Federal
US · Federal
◆Binding
Binds Anyone publishing non-consensual intimate imagery; covered online platforms (notice-and-removal). Bans non-consensual intimate imagery incl. AI deepfakes; covered platforms must remove within 48h (notice-and-removal duty live 19 May 2026).
Stated maximum penalty — FTC enforcement; criminal penalties
US · Federal
▲Proposed
Binds AI system developers meeting both: $100M+ training compute and $500M+ annual gross AI revenue. Frontier AI developers meeting dual thresholds ($100M dev compute, $500M annual AI revenue) must implement kill-switch capability; 15-day DHS incident reporting; DHS/CISA authority to compel emergency shutdown.
Introduced Jul 23, 2026 by Reps. Lieu (D) and Moran (R) as H.R. 9917; referred to the House Committee on Homeland Security same day; triggered by OpenAI/Hugging Face hack incident. 119th Congress.
Stated maximum penalty — Up to $2M/day (general); up to $20M/day (defying shutdown order)
State — AL
US · AL
◆Binding
Binds Health insurers using AI in coverage determinations in Alabama. AI may not be sole basis for coverage denial; health insurers must disclose AI use and file annual certification with Alabama DOI.
Annual certification to Alabama DOI required.
Stated maximum penalty — Alabama DOI disciplinary action (license revocation/suspension)
State — CA
US · CA
◆Binding
Binds Operators of companion-chatbot platforms available in California. AI-status disclosure + self-harm protocols.
Stated maximum penalty — Private right of action
US · CA
◆Binding
Binds Frontier AI developers (>1e26 training ops); large frontier developers (>$500M revenue). Safety frameworks + critical-incident reporting to Cal OES for frontier developers.
Stated maximum penalty — Up to $1M per violation
US · CA
◆Binding
Binds Developers of generative AI systems made available to Californians. Public dataset-summary disclosure for generative AI offered to Californians.
Stated maximum penalty — Civil enforcement
US · CA
◆Binding
Binds Any person or entity that develops or deploys AI/GenAI systems using health-profession-protected terms, letters, or phrases (broader than nursing — covers all licensed healing-arts professions, e.g. medicine, dentistry, psychology). Adds Bus. & Prof. Code §§ 4999.8-4999.9: makes existing law that bars falsely indicating or implying possession of a health-care license (e.g., under the Medical Practice Act, Dental Practice Act) enforceable against any person or entity that develops or deploys an AI or GenAI system using protected terms, letters, or phrases in its advertising or functionality. Separately prohibits AI/GenAI use of terms implying that care, advice, reports, or assessments are provided by a licensed natural person. Each prohibited use is a separate violation.
AB 489 (Bonta), approved by Governor and filed with Secretary of State Oct. 11, 2025; no urgency clause, so it took effect Jan. 1, 2026 under the default California statutory effective-date rule (Cal. Const. art. IV, §8(c)).
Stated maximum penalty — Enforced via the applicable health-care licensing board's injunctive authority (Bus. & Prof. Code §125.5) plus the penalty already attached to the underlying title-protection provision being invoked (e.g., unauthorized practice of medicine under §2052 is a public offense punishable by up to 1 year in county jail and/or a $10,000 fine)
US · CA
◆Binding
Binds Covered GenAI providers with >1M monthly users accessible in California. AI-detection tool + content provenance for >1M-user providers.
Operative 2 August 2026 under Bus. & Prof. Code s 22757.6 as amended by AB 853, which pushed the original 1 January 2026 start date back. Covers the s 22757.3 covered-provider duties: a free public AI-detection tool, latent disclosures in AI-generated image, video and audio output, and an optional manifest disclosure. A covered provider is one whose GenAI system has over 1,000,000 monthly visitors or users and is publicly accessible within California (s 22757.1(d)). AB 853's later tranches are tracked as us-ca-ab853 (1 January 2027) and us-ca-ab853-capture-device (1 January 2028).
Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)
US · CA
◆Binding
Binds Large online platforms (public-facing social media, file-sharing, mass messaging or stand-alone search) exceeding 2,000,000 unique monthly users over the preceding 12 months; and GenAI hosting platforms offering model weights or source code for download. Large online platforms must detect, display and preserve content provenance data; GenAI hosting platforms may not offer models that omit AI disclosures.
AB 853 (approved by the Governor 13 October 2025) adds three tranches to the California AI Transparency Act. The covered-provider regime under Bus. & Prof. Code s 22757.3 became operative 2 August 2026 and is tracked separately as us-ca-sb942. This entry covers the second tranche: s 22757.3.1 (large online platform provenance detection, a provenance user interface, user inspection/download, and a bar on knowingly stripping provenance data or digital signatures) and s 22757.3.2 (GenAI hosting platforms may not knowingly make available a GenAI system that omits s 22757.3 disclosures). Both carry an express operative date of 1 January 2027 (s 22757.3.1(c), s 22757.3.2(b)). The capture-device manufacturer tranche starts 1 January 2028 and is tracked as us-ca-ab853-capture-device. Threshold correction 2026-08-12: the large online platform test is 2,000,000 unique monthly users (s 22757.1(h)(1)), not the 1,000,000 figure that governs covered providers; broadband internet access service and telecommunications service are excluded. Note a drafting inconsistency in the enacted text: s 22757.3.2 uses 'GenAI system hosting platform' while the defined term at s 22757.1(g) is 'GenAI hosting platform'.
Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)
US · CA
◆Binding
Binds California K-12 public school districts, county offices of education, and charter schools engaging employees or contractors. Requires that all K-12 public school employees and independent contractors performing employee-equivalent functions be natural persons; prohibits schools from contracting with AI systems to fill legally recognized employee or contractor roles. Does NOT ban AI tools in classrooms — lesson planning, grading support, translation, tutoring/student practice tools, and other AI-assisted instruction remain permitted.
Chaptered June 30 2026 as Ch. 45, Stats. 2026; adds Education Code §98; effective 2027-01-01.
Stated maximum penalty — Not specified in bill text; subject to existing Education Code enforcement mechanisms
US · CA
◆Binding
Binds Capture device manufacturers, for any capture device first produced for sale in California on or after 1 January 2028 (cameras, mobile phones with built-in cameras or microphones, voice recorders); no user threshold applies. Camera, phone and recorder makers must offer, and switch on by default, latent provenance disclosures in captured content.
Bus. & Prof. Code s 22757.3.3, added by AB 853 (approved 13 October 2025). A capture device manufacturer must (1) give the user the option to include a latent disclosure in content captured by the device and (2) embed latent disclosures by default, in each case only to the extent technically feasible and consistent with widely adopted specifications from an established standards-setting body. The duty attaches to devices first produced for sale in the state on or after 1 January 2028, and s 22757.3.3(c) sets the same operative date. Unlike the covered-provider (1,000,000 monthly users) and large online platform (2,000,000 unique monthly users) tranches, this one has no size threshold: s 22757.1(c)(1) defines a capture device manufacturer simply as a person who produces a capture device for sale in the state. Added 2026-08-12 to close a coverage gap; the 2028 date previously appeared in no entry.
Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)
State — CO
US · CO
◆Binding
Binds Regulated psychotherapy professionals in Colorado using AI; any entity misrepresenting AI as professional-equivalent. AI cannot deliver psychotherapy without licensed professional's real-time involvement; disclosure and written consent required.
Signed 3 Jun 2026 by Gov. Polis; enacted without a safety clause, so the general post-session effective date applies. IN FORCE since 12 Aug 2026 — the Colorado General Assembly bill record (leg.colorado.gov/bills/hb26-1195) lists the session law as Chapter 358 with Effective Date 08/12/2026, re-confirmed on the day of entry into force. No amendments or delays. Unaffected by the federal court injunction pausing CO SB 26-189 (the broader Colorado AI Act). AG holds exclusive enforcement; $20,000 per violation; 60-day cure period.
Stated maximum penalty — Unfair trade practice (CO Consumer Protection Act; AG enforcement); $20,000 per violation
US · CO
◆Binding
Binds Developers & deployers of automated decision-making tech in consequential decisions. ADMT documentation, consumer notice & appeal rights.
ENFORCEMENT STAYED — xAI v. Weiser, No. 1:26-cv-01515 (D. Colo.): On approx. April 27, 2026, a joint consent-based enforcement stay was entered (agreed by xAI LLC, the U.S. DOJ, and the Colorado AG). The original SB 24-205 was repealed and replaced by SB 26-189 (signed May 14, 2026); the stay was extended to SB 26-189. AG cannot initiate enforcement until 14 days after any PI ruling. xAI must file a formal PI motion within 28 days of Colorado finalizing rulemaking under SB 26-189. Law is valid and on the books (effective date unchanged: 2027-01-01), but practical enforcement is suspended pending PI disposition. FEDERAL PREEMPTION PRESSURE (separate from the litigation stay): on 7 July 2026 the FTC published for comment a proposed 'Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems' (docket FTC-2026-0859), asserting that steering AI outputs contrary to consumers' reasonable expectations — in the FTC's words 'including attempted compliance with a State law, such as Colorado's recently revised Artificial Intelligence Act' — may be deceptive under Section 5 of the FTC Act. The comment period closed 31 July 2026 and drew opposing comments, including from a multistate attorney-general coalition. The FTC has not finalised the policy statement and no court has ruled on preemption, so the text, scope and 1 January 2027 effective date of SB 26-189 are unchanged by it.
Stated maximum penalty — AG enforcement; per violation
US · CO
◆Binding
Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.
Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01.
Stated maximum penalty — CO AG enforcement
US · CO
◆Binding
Binds Health insurers, pharmacy benefit managers, and managed care entities using AI for utilization review in Colorado. Health insurers and managed care entities using AI for coverage determinations must require human clinician review before denying coverage; AI decisions must be individualized and non-discriminatory; periodic audits required.
Signed June 2, 2026; effective January 1, 2027.
Stated maximum penalty — State insurance enforcement; penalty amount not specified in primary source
State — CT
US · CT
◆Binding
Binds Subscription-based AI providers, frontier developers, generative AI providers with >1,000,000 monthly users publicly accessible for personal use, and CT state agencies. Subscription-based AI providers give consumer disclosures; frontier developers publish safety frameworks; large generative providers embed provenance data; state agencies gated on OPM/DAS AI policies.
Public Act No. 26-15, signed by the Governor 27 May 2026. This row carries the 1 Oct 2026 tranche: s 1 (subscription-based provider disclosures), s 2 (frontier developer duties), s 15 (covered provider provenance/detectability of synthetic digital content, >1,000,000 monthly users), s 38 (state agency AI use and procurement). The Act's later tranches are carried as separate rows: AI companions 1 Jan 2027 (us-ct-sb5-companion), automated employment-related decision technology 1 Oct 2027 (us-ct-sb5-aedt), covered-platform minors 1 Jan 2028 (us-ct-sb5-minors). Sections 17, 18, 31 (AI Academy, working group, higher-education alliance) took effect 1 Jul 2026 but create state-programme duties only, not private-sector obligations. Bill status page: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&bill_num=SB5&which_year=2026
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)
US · CT
◆Binding
Binds Operators who provide or operate an artificial intelligence companion for users in Connecticut, with heightened duties where the user is under 18. Operators of AI companions have until 1 Jan 2027 before disclosure, crisis-referral and minor-protection duties bite.
Public Act No. 26-15 ss 4-6, each expressly '(Effective January 1, 2027)'. s 5 sets baseline operator duties; s 6 adds under-18 duties, including a clear and conspicuous statement at the start of each interaction that the companion is not a licensed mental health professional, bars on romantic/erotic interaction with minors, bars on discouraging a minor from seeking mental health services or adult help, and bars on manipulative engagement-extension techniques. Violations of ss 5 and 6 are unfair or deceptive trade practices enforced solely by the Attorney General.
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)
US · CT
◆Binding
Binds Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 1 Oct 2027. Developers and deployers have until 1 Oct 2027, when the duties attach to any automated employment-related decision technology deployed in Connecticut on or after that date.
Public Act No. 26-15 ss 7-12. Date nuance: the sections themselves are '(Effective October 1, 2026)', but the operative duties in ss 8, 9 and 10 each attach only to technology 'deployed in the state on or after October 1, 2027', so 1 Oct 2027 is the date on which the obligations bite. s 8 is the developer-to-deployer disclosure; ss 9-10 are the deployer notice duties; s 11 carries the trade-secret carve-out; s 12 makes violations of ss 8-11 unfair or deceptive trade practices enforced solely by the Attorney General.
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)
US · CT
◆Binding
Binds Covered operators of covered platforms serving Connecticut users who are under eighteen. Covered platform operators have until 1 Jan 2028 before personalised feed and related restrictions apply to users under 18.
Public Act No. 26-15 s 39, expressly '(Effective January 1, 2028)'. Bars a covered operator from serving a covered minor a personalised recommendation feed based on information associated with the user or the user's device unless one of the listed conditions is met, including commercially reasonable and technically feasible age determination or verifiable parental consent. s 39(g) deems violations of subsections (b)-(e) unfair or deceptive trade practices under Conn. Gen. Stat. s 42-110b(a).
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)
State — DE
US · DE
◆Binding
Binds Any person or entity deploying or offering an AI agent in Delaware that would be licensed as, or presented under the title of, a nurse, physician, or physician assistant. A nonhuman entity, including an agent powered by artificial intelligence, may not be licensed or certified to practice professional nursing, advanced practice registered nursing, practical nursing, medicine, or as a physician assistant in Delaware, and may not use the associated protected titles — "Nurse", "RN", "LPN", "APRN", "CRNA", "CNS", "CNP", "CNM", "Doctor"/"Dr.", "Physician", "Surgeon", "MD", "DO", "Physician Assistant"/"PA". Amends 24 Del. C. §§ 1920, 1720, 1773. Does not restrict AI clinical decision-support or documentation tools that do not hold themselves out under a licensed title.
Signed by Gov. Meyer and approved April 23, 2026 as 85 Del. Laws ch. 250; no delayed-effective-date clause, so effective on enactment.
Stated maximum penalty — Medicine: class F felony, $1,000–$5,000 fine and/or up to 3 years (24 Del. C. § 1766(a)); other Ch. 17 violations class B misdemeanor (§ 1766(c)). Nursing/title misuse: up to $1,000 and/or 1 year (24 Del. C. § 1925)
State — GA
US · GA
◆Binding
Binds Health insurers and utilization review entities in Georgia. AI prohibited from issuing adverse prior-authorization determinations without licensed clinical peer review.
Stated maximum penalty — Georgia Insurance Commissioner enforcement
US · GA
◆Binding
Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.
Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)
State — HI
US · HI
◆Binding
Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.
Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.
Stated maximum penalty — $1,000/violation up to $1,000,000/operator
US · HI
◆Binding
Binds Anyone who knowingly publishes realistic AI-generated imitations of identifiable persons without consent; advertisers using synthetic performers in a materially deceptive manner. Two-part law: (1) prohibits publishing unauthorized AI-generated realistic imitations of identifiable persons for use in advertising, fraud, harassment, defamation, or election interference — victims may sue for up to $25,000 per piece or actual damages; (2) requires conspicuous disclosure when synthetic performers (AI-fabricated human assets not recognizable as any real individual) appear in advertising in a materially deceptive manner.
Stated maximum penalty — Up to $25,000 per piece of content or actual damages, plus punitive damages and attorneys fees (Part I — private civil action + AG); $1,000 first violation / $5,000 subsequent violations (Part II — AG enforcement)
State — IA
US · IA
◆Binding
Binds Operators of conversational AI services serving Iowa consumers. Disclosure and safeguard obligations for conversational AI operators serving Iowa users; compliance applicable 2027-07-01.
Law in force 2026-07-01; compliance obligations applicable from July 1, 2027.
Stated maximum penalty — Civil enforcement by Iowa AG (amount TBD)
US · IA
◆Binding
Binds Health carriers and utilization review organizations operating in Iowa. AI cannot be sole basis for denying medically necessary services; human clinical review required for adverse determinations.
Electronic prior authorization required from 2027-07-01.
Stated maximum penalty — Iowa Insurance Division enforcement
State — ID
US · ID
◆Binding
Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.
Modeled on Nebraska LB 525. Signed 2026-04-01.
Stated maximum penalty — Idaho AG enforcement (amount TBD)
State — IL
US · IL
◆Binding
Binds Employers & employment agencies using AI in employment decisions. Bars discriminatory AI use in hiring; notice required.
Stated maximum penalty — IDHR enforcement
US · IL
◆Binding
Binds Large frontier AI developers (>$500M revenue, trained on massive compute) operating in Illinois. Large frontier AI developers must publish safety frameworks, annual third-party audits, and report critical incidents within 72 hours.
Signed 2026-07-06.
Stated maximum penalty — Up to $1M first offense; up to $3M subsequent violations
US · IL
◆Binding
Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.
Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.
Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified
US · IL
◆Binding
Binds Health insurance issuers and managed care organizations in Illinois (excludes self-insured ERISA plans and workers' compensation). Prohibits health insurers and managed care organizations from using algorithms or automated tools to downcode medical claims without comprehensive human review; requires AMA CPT coding guideline-compliant physician review of all downcoding determinations; bans discriminatory targeting of providers treating complex/chronic patients.
Signed 2026-07-10 by Governor Pritzker; effective 2028-01-01.
Stated maximum penalty — Fines, restitution, or license suspension (IL Department of Insurance enforcement)
US · IL
▲Proposed
Binds Landlords of residential units in Illinois and third-party algorithmic pricing service providers who facilitate rental price coordination. Amends the Illinois Antitrust Act to prohibit landlords and third-party services from using AI algorithms to coordinate residential rental pricing; specifically targets algorithmic platforms (e.g., RealPage) used by competing landlords to fix or stabilize rents.
The AI rental-pricing language no longer exists in this bill vehicle. Senate Floor Amendment No. 1 (adopted 2026-05-21) had added the algorithmic rental-price-coordination ban described above, but House Committee Amendment No. 1 (filed 2026-05-28, adopted 2026-05-29) replaced that content entirely with unrelated Cook County / Calumet City eminent-domain (quick-take) provisions for economic development. Governor Pritzker signed the bill on 2026-08-07 as Public Act 104-0805; the enacted text contains no AI or algorithmic-pricing provisions.
Stated maximum penalty — Illinois Antitrust Act — civil penalties (enforcement by Illinois AG)
State — IN
US · IN
◆Binding
Binds Health insurers and health benefit providers in Indiana. AI cannot be sole basis for claim downcoding; insurers must disclose AI use in adverse determinations.
Stated maximum penalty — Indiana DOI enforcement
State — MD
US · MD
◆Binding
Binds Health insurance carriers, PBMs, and private review agents conducting utilization review in Maryland. AI tools in health-care utilization review must base decisions on individual clinical information; AI subject to quarterly MIA audit.
Quarterly review of AI utilization tools for effectiveness, accuracy, and fairness required.
Stated maximum penalty — Maryland Insurance Administration (MIA) enforcement
US · MD
◆Binding
Binds Any person who uses AI or deepfake representations with fraudulent intent to harm, harass, intimidate, or threaten individuals in Maryland. Criminalises creation and distribution of AI/deepfake representations used for identity fraud; expands existing identity-fraud statute.
Signed May 12, 2026 by Governor Wes Moore; effective October 1, 2026.
Stated maximum penalty — Up to 5 years imprisonment and/or $10,000 fine (single victim); up to 10 years and/or $15,000 (two or more victims)
US · MD
▲Proposed
Binds Food retail stores ≥15,000 sq ft selling tax-exempt food, and third-party delivery service providers arranging delivery from such stores, operating in Maryland. First US state law banning AI-driven personalised (surveillance) pricing in food retail and delivery; prohibits setting prices based on individual consumer personal data.
EXCLUDED FROM ACTIVE COVERAGE — CEO ruling AIL-136 (2026-08-03): all AI/algorithm language was deliberately struck from HB 895 before enactment. The enacted Ch. 154 prohibits personalized data-driven pricing for tax-exempt food (retailers ≥15,000 sq ft + food delivery); no AI definition, no near-real-time AI dynamic-pricing clause, no §13-322 algorithmic-pricing disclosure. Enacted operative line is personal data, not AI. Narrow food scope, regulatory-only, no private right of action. Fails coverage prong (a): AI is not load-bearing in enacted text. REVERSAL TRIGGER: re-escalate to CEO if AI/algorithm language is re-introduced in a future MD legislative session, or if personalized/surveillance pricing becomes an AI-governance flashpoint with AI-specific statutory language.
Stated maximum penalty — Up to $10,000 per violation; up to $25,000 per violation for repeat offenders (Maryland AG enforcement)
State — NE
US · NE
◆Binding
Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.
Signed April 14, 2026; operative July 1, 2027 (sections 12–18).
Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only
State — NJ
US · NJ
◆Binding
Binds Residential rental property owners and algorithmic revenue management software coordinators operating in New Jersey. Prohibits residential landlords and algorithmic revenue-management software coordinators from using algorithms that share competing landlords' nonpublic pricing data to recommend rents; bans parallel pricing coordination via software.
Signed 2026-07-20 by Gov. Mikie Sherrill; effective first day of the twelfth month following enactment (2027-07-01).
Stated maximum penalty — NJ Antitrust Act enforcement (P.L.1970, c.73); AG complaint portal required; penalty as provided under NJ Antitrust Act
State — NY
US · NY
◆Binding
Binds Operators of AI companion models serving New York users (excludes customer-service / internal-productivity-only systems). AI-identity disclosure at session start + every 3h and suicide/self-harm crisis referral (988) for AI companion operators; NY AG enforces.
Stated maximum penalty — Up to $15,000/day per violation (AG only; no private right of action)
US · NY
◆Binding
Binds Any person or entity using a deceased NY-domiciled performer's AI-generated digital replica in covered audiovisual, recorded, or live musical works without written consent from rights holders. Requires prior written consent from heirs, executors, or assigns before using a deceased New York-domiciled performer's or personality's AI-generated digital replica in audiovisual works, sound recordings, or live musical performances. Amends NY Civil Rights Law §50-f to introduce an AI-specific 'digital replica' definition (highly realistic, readily identifiable, computer-generated representation) and removes the prior 'likely to deceive' threshold. Covers 40 years post-mortem. Private right of action: statutory damages ≥$2,000 or actual damages plus profits and punitive damages.
Stated maximum penalty — ≥$2,000 statutory damages or actual damages + profits + punitive damages (private right of action)
US · NY
◆Binding
Binds Persons, firms, or corporations engaged in commerce who produce or create advertisements using synthetic performers with actual knowledge of their use in New York. Requires conspicuous disclosure when AI-generated synthetic performers (digitally created human assets not recognizable as any identifiable real person) appear in advertisements in any medium — newspapers, magazines, radio, TV, streaming, billboards, and transit. Advertisers must have actual knowledge of synthetic performer use. Exempts expressive works, audio-only ads, and language-translation uses.
Stated maximum penalty — $1,000 first violation; $5,000 subsequent violations (civil penalties)
US · NY
◆Binding
Binds Large frontier developers (>1e26 ops, >$500M revenue) operating in New York. Safety/security protocols + 72h critical-incident reporting to NYDFS; AG enforces civil penalties.
The RAISE Act as originally signed 19 December 2025 (Ch. 699) was superseded by a chapter amendment, S8828 (Ch. 96), introduced 6 Jan 2026 and signed by Governor Hochul 27 March 2026. The amendment shifted rulemaking and incident-report oversight from the Division of Homeland Security and Emergency Services to a new office within the NY Department of Financial Services (DFS), and set the effective date at 1 January 2027.
Stated maximum penalty — Up to $1M / $3M
State — NYC
US · NYC
◆Binding
Binds NYC employers & agencies using automated employment decision tools (AEDTs). Annual bias audit + published summary + candidate notice.
Stated maximum penalty — $500–$1,500 per violation/day
State — OR
US · OR
◆Binding
Binds Any nonhuman entity, including AI systems, using a protected nursing title or abbreviation in Oregon. Codified as ORS 678.027: a nonhuman entity, including but not limited to an agent powered by artificial intelligence, may not use the titles or abbreviations Advanced Practice Registered Nurse (APRN), Certified Registered Nurse Anesthetist (CRNA), Clinical Nurse Specialist (CNS), Licensed Practical Nurse (LPN), Registered Nurse (RN), Nurse Practitioner (NP), Certified Medication Aide (CMA), or Certified Nursing Assistant (CNA).
Enrolled House Bill 2748 (HB 2748-A), 83rd Oregon Legislative Assembly — 2025 Regular Session; passed House June 13, 2025, Senate June 11, 2025, signed by Gov. Kotek; codified 2025 c.378 §2 (ORS 678.027). The enrolled act contains only Sections 1 and 2 and no effective-date clause, so ORS 171.022 controls: "Except as otherwise provided in the Act, an Act of the Legislative Assembly takes effect on January 1 of the year after passage of the Act" — passed 2025, therefore in force Jan. 1, 2026.
Stated maximum penalty — Violation of ORS 678.010 to 678.415 (which includes 678.027) is a Class C misdemeanor — ORS 678.990(1)
US · OR
◆Binding
Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.
Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees
State — RI
US · RI
◆Binding
Binds Any individual, corporation or entity offering therapy/psychotherapy services in Rhode Island, and RI-licensed mental health professionals using AI. R.I. Gen. Laws ch. 40.1-5.5. No individual, corporation or entity may provide, advertise or offer therapy/psychotherapy services to the public in RI — including via Internet-based AI — unless conducted by a licensed professional (§ 40.1-5.5-3(b)). Licensed professionals may use emotional-attachment/companion AI in recorded or transcribed sessions only with prior written informed consent (§ 40.1-5.5-3(a)), and may not let AI make independent therapeutic decisions, conduct therapeutic communication without an established relationship, or set treatment plans (§ 40.1-5.5-3(c)). Carve-outs: religious counseling, peer support, public self-help materials, and FDA-cleared AI tools.
Enacted as Substitute A (LC004589/SUB A/2); signed by Governor McKee June 22, 2026; effective upon passage. Verified against the enacted Sub A text 2026-08-10.
Stated maximum penalty — Confidentiality violations: penalties under R.I. Gen. Laws § 5-37.3-9; EOHHS investigative authority; RI licensing enforcement
US · RI
◆Binding
Binds Healthcare providers (physicians, PAs, dentists, RNs, LPNs, APRNs, nursing assistants, other DOH-licensed professionals) and healthcare facilities (§ 23-17-2) in Rhode Island. R.I. Gen. Laws ch. 23-106. Healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits must notify patients of that use and must review the AI-generated documentation for accuracy after the visit (§ 23-106-3).
Enacted as Substitute A (LC004720/SUB A) creating R.I. Gen. Laws ch. 23-106; signed 22 June 2026; effective upon passage. Verified against the enacted Sub A text 2026-08-10.
Stated maximum penalty — RI healthcare licensing enforcement
US · RI
◆Binding
Binds Chatbot and companion AI operators serving Rhode Island users. Chatbot/companion AI operators must include suicidal-ideation protocols and crisis referrals; annual reporting to AG from 2027-07-01.
Signed 2026-06-22 by Governor McKee; general effective date 2027-01-01. Annual reports to RI AG beginning July 1, 2027.
Stated maximum penalty — RI AG enforcement
State — TN
US · TN
◆Binding
Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.
Effective 2026-05-22, the date carried in the "Effective date(s)" field of the Tennessee General Assembly bill-status record; Section 4 of Public Chapter 1082 reads "This act takes effect upon becoming a law, the public welfare requiring it" (publications.tnsosfiles.com/acts/114/pub/pc1082.pdf), so there is no deferred application. The same record lists the governor's signature action on 2026-05-27; the enrolled chapter's approval stamp is a handwritten scan and is not machine-readable, so the 05/22 effective date is taken from the legislature's own field rather than reconstructed from the signature. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.
Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators
US · TN
◆Binding
Binds Any person creating or deploying AI systems available in Tennessee. Prohibits AI systems from claiming to function as qualified mental health professionals.
Stated maximum penalty — $5,000 per violation (Consumer Protection Act)
State — TX
US · TX
◆Binding
Binds Persons developing/deploying AI in Texas or serving Texas residents; state agencies. Bans manipulative/discriminatory AI; AG-enforced.
Stated maximum penalty — Up to $200k/violation; $40k/day
State — UT
US · UT
◆Binding
Binds Health insurers operating in Utah for prior authorization processes. Insurers must disclose AI use in prior authorization reviews; adverse determinations must reflect independent medical judgment.
Stated maximum penalty — Disclosure to Utah Insurance Department required
State — WA
US · WA
◆Binding
Binds Private health carriers and public employee health plans using AI in prior authorization in Washington. AI cannot be sole basis for denying health care services; human clinical review required for AI-generated denials.
Annual reporting to OIC on AI-generated prior auth statistics required.
Stated maximum penalty — OIC enforcement (civil penalties; license actions)
US · WA
◆Binding
Binds Any person creating, distributing, or facilitating AI-generated/manipulated likenesses of Washington residents. Prohibits creating or using AI-generated forged digital likenesses without consent; amends WA Personality Rights Act.
Stated maximum penalty — $3,000/violation + noneconomic damages; private right of action
US · WA
◆Binding
Binds Any person or nonhuman entity (including AI systems, chatbots, and automated triage/care tools) presenting itself under a protected nursing title or abbreviation in Washington. Amends RCW 18.79.030: only a human person licensed under ch. 18.79 RCW may practice as, or use the titles of, a registered nurse ("RN"), advanced practice registered nurse/nurse practitioner ("APRN"/"NP"), or licensed practical nurse ("LPN"). No other person or any nonhuman entity may assume those titles or abbreviations, or use other words, letters, signs, or figures indicating it is a nurse.
House Bill 2155, 2026 Regular Session, passed House Feb. 11, 2026 (87-8) and Senate Feb. 26, 2026 (46-2); delivered to Governor Mar. 3 and signed Mar. 9, 2026 as Chapter 6, 2026 Laws. The enrolled act contains no effective-date section; the Legislature's own bill record states "Effective date 6/11/2026" (Washington's default general effective date, 90 days after sine die). Sec. 1 (in force) expires June 30, 2027, when Sec. 2 (an equivalent re-enactment) takes over.
Stated maximum penalty — Enforced as unlicensed practice under RCW 18.130.190: civil fine up to $1,000/day (18.130.190(3)); first violation is a gross misdemeanor, subsequent violations a class C felony (18.130.190(7))
US · WA
◆Binding
Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.
Disclosures every 3 hours (all users) or 1 hour (minor users).
Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)
US · WA
◆Binding
Binds AI content creators and operators serving Washington users. Operators/creators must inform users when content is developed or modified through AI.
Signed 2026-03-24; codified as Chapter 167, Laws of 2026. Enforced exclusively by the WA Attorney General under the Consumer Protection Act (ch. 19.86 RCW).
Stated maximum penalty — Civil penalty up to $100,000 per covered provider (WA Consumer Protection Act, ch. 19.86 RCW; AG enforcement only)