Kyrgyzstan
◆Binding
Binds Owners and users of AI systems that interact with natural persons as consumers (part 1); users of emotion-recognition and biometric-classification systems (part 2); users of AI systems for deepfakes (part 4). Danger tier is irrelevant here - a minimal-danger chatbot owes part 1 - and there is no size, sector or nationality threshold. Part 1's register limb additionally reaches the sectoral regulator of the national ecosystem, which must publish the same information on its own site.. Art. 197 is Kyrgyzstan's transparency article and, unlike the rest of Chapter 23, it applies to AI systems at any danger level. Part 1 obliges owners and users who design, develop or apply AI systems in order to interact with natural persons as consumers to inform those consumers of the fact that they are interacting with an AI system, except where it is obvious from the circumstances; it further declares information about the use of AI systems within digital-environment legal relations to be publicly accessible information, which must be posted in accessible and intelligible form both on the sites of the users of those systems and on the site of the sectoral regulator of the national ecosystem - a disclosure register duty that goes beyond the EU AI Act art. 50 equivalent. Part 2 requires users of systems intended for emotion recognition or for the classification of natural persons by biometric characteristics to inform the persons concerned that such a system is being applied to them; Kyrgyzstan regulates these by notification rather than banning them in workplaces and education as the EU does. Part 4 requires users of AI systems for deepfakes to disclose the artificial origin or alteration of the material. Part 3 disapplies parts 1 and 2 - not part 4 - for functions where informing would frustrate lawful use for defence, national security, or public order in the detection, prevention and investigation of crime and criminal prosecution; part 5 disapplies part 4 for lawful use protecting those same goods or in exercise of the freedom of scientific, technical and artistic creativity, teaching and learning, which is a notably wide carve-out from deepfake labelling. Part 6 conditions every one of those exceptions on necessary measures having been taken to protect the affected human and civil rights and freedoms.
In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. Art. 197 needs no implementing act and none has been issued: the duties are self-executing on the text, and neither Resolution No. 770 nor Order No. 1181-т touches transparency. What has NOT been located is any published register on the site of the sectoral regulator of the national ecosystem under part 1, which the article requires; that is recorded as an open follow-up rather than asserted either way.
Stated maximum penalty — Nothing. There is no administrative offence for failing to disclose AI interaction, for applying emotion recognition or biometric classification without notifying the person, or for publishing an unlabelled deepfake. Art. 228-10 of the Code of Offences, the only AI-specific offence, covers the art. 192(2) targeted-unlawful-harm prohibition alone (200 расчетных показателей for natural persons, 650 for legal persons, at 100 som per показатель). Kyrgyzstan therefore sits at the opposite end from Kazakhstan on this one point: Kazakhstan's KoAP art. 641-1 does penalise failure to inform users about misleading synthetic outputs, at 15 to 100 MRP, while Kyrgyzstan's identical duty carries no fine at all.
US · TN
◆Binding
Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.
Effective 2026-05-22, the date carried in the "Effective date(s)" field of the Tennessee General Assembly bill-status record; Section 4 of Public Chapter 1082 reads "This act takes effect upon becoming a law, the public welfare requiring it" (publications.tnsosfiles.com/acts/114/pub/pc1082.pdf), so there is no deferred application. The same record lists the governor's signature action on 2026-05-27; the enrolled chapter's approval stamp is a handwritten scan and is not machine-readable, so the 05/22 effective date is taken from the legislature's own field rather than reconstructed from the signature. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.
Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators
US · IA
◆Binding
Binds Operators of conversational AI services serving Iowa consumers. Disclosure and safeguard obligations for conversational AI operators serving Iowa users; compliance applicable 2027-07-01.
Law in force 2026-07-01; compliance obligations applicable from July 1, 2027.
Stated maximum penalty — Civil enforcement by Iowa AG (amount TBD)
US · TN
◆Binding
Binds Any person creating or deploying AI systems available in Tennessee. Prohibits AI systems from claiming to function as qualified mental health professionals.
Stated maximum penalty — $5,000 per violation (Consumer Protection Act)
US · HI
◆Binding
Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.
Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.
Stated maximum penalty — $1,000/violation up to $1,000,000/operator
US · CT
◆Binding
Binds Operators who provide or operate an artificial intelligence companion for users in Connecticut, with heightened duties where the user is under 18. Operators of AI companions have until 1 Jan 2027 before disclosure, crisis-referral and minor-protection duties bite.
Public Act No. 26-15 ss 4-6, each expressly '(Effective January 1, 2027)'. s 5 sets baseline operator duties; s 6 adds under-18 duties, including a clear and conspicuous statement at the start of each interaction that the companion is not a licensed mental health professional, bars on romantic/erotic interaction with minors, bars on discouraging a minor from seeking mental health services or adult help, and bars on manipulative engagement-extension techniques. Violations of ss 5 and 6 are unfair or deceptive trade practices enforced solely by the Attorney General.
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)
US · WA
◆Binding
Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.
Disclosures every 3 hours (all users) or 1 hour (minor users).
Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)
US · OR
◆Binding
Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.
Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees
US · CO
◆Binding
Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.
Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01.
Stated maximum penalty — CO AG enforcement
US · RI
◆Binding
Binds Chatbot and companion AI operators serving Rhode Island users. Chatbot/companion AI operators must include suicidal-ideation protocols and crisis referrals; annual reporting to AG from 2027-07-01.
Signed 2026-06-22 by Governor McKee; general effective date 2027-01-01. Annual reports to RI AG beginning July 1, 2027.
Stated maximum penalty — RI AG enforcement
US · GA
◆Binding
Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.
Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)
US · ID
◆Binding
Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.
Modeled on Nebraska LB 525. Signed 2026-04-01.
Stated maximum penalty — Idaho AG enforcement (amount TBD)
US · NE
◆Binding
Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.
Signed April 14, 2026; operative July 1, 2027 (sections 12–18).
Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only