AI LAW RADAR · Daily Last verified 22 Aug 2026

Topic dossier

Prohibited & banned AI practices

The AI uses that are forbidden outright — manipulative systems, social scoring, non-consensual intimate imagery and algorithmic price coordination — regardless of safeguards. 25 obligations across 10 jurisdictions — 18 in force, 2 proposed. Next dated deadline: 1 Dec 2026.

Above the risk tiers sits a smaller set of outright bans. The EU AI Act’s Article 5 is the broadest: it prohibits social scoring, manipulative and exploitative systems, untargeted facial-image scraping and more. Texas, Peru and the US TAKE IT DOWN Act add their own prohibitions. A second, newer family bans a specific commercial use of algorithms rather than a technique: New Jersey and Illinois forbid software that coordinates residential rents between competing landlords, and Maryland forbids setting retail food prices from an individual shopper’s personal data. These are the lines that hold regardless of safeguards or consent.

The Register

25 obligations · 10 jurisdictions

Argentina 1

Argentina Binding

Ley 25.326 Art. 20 — judicial and administrative decisions may not rest solely on automated profiling

Binds Courts issuing judicial decisions and public bodies issuing administrative acts in Argentina where the decision appraises or evaluates human conduct, whatever the underlying data file (Art. 20 sits in Chapter III, on the rights of data subjects, and applies alongside the general scope in Art. 1). Impact tier: all entities in the sense that any public or private data file feeding such a decision is exposed to the nullity, but the duty itself falls on the public decision-maker.. Art. 20 of the Ley de Protección de los Datos Personales (Ley 25.326), headed 'Impugnación de valoraciones personales', provides that judicial decisions and administrative acts which involve the appraisal or evaluation of human conduct may not have as their sole basis the result of automated processing of personal data that yields a definition of the data subject's profile or personality, and that acts contrary to that rule are incurably void ('insanablemente nulos'). It is Argentina's only in-force statutory constraint on automated decision-making: unlike LGPD Art. 20 in Brazil or PIPA Art. 37-2 in Korea it confers no request-for-review procedure and does not reach private-sector recommender systems or algorithmic work dispatch, and its remedy is nullity of the act rather than a right exercised against a controller. The related access right in Art. 15 requires information held about the subject to be supplied in clear form, and Art. 43 of the Constitution supplies the habeas data action used to enforce Chapter VII.

Ley 25.326 was sanctioned 4 October 2000 and partially promulgated by Decreto 995/2000, published in the Boletín Oficial on 2 November 2000. The law contains no commencement clause, so the residual rule of the Código Civil then in force (Art. 2, Ley 340) applied — laws bind after the eight days following official publication — giving 11 November 2000. Art. 20 was not among the provisions vetoed by Decreto 995/2000, which struck only points 2 and 3 of Art. 29 inc. 1 and Art. 47; the text was read in the Ministerio de Justicia InfoLeg consolidated version, which records the veto history in its Antecedentes Normativos. The commencement date is a derivation from the residual civil-law rule rather than a date stated in the instrument; the substance of the article, and the fact that it binds today, are not in doubt. Added in the AIL-211 LATAM coverage-symmetry sweep as Argentina's nearest peer of cn-pipl-art24 and br-lgpd-art20; no Argentine in-force peer of the recommendation off-switch (CAC Art. 17) or algorithmic work dispatch (CAC Art. 20) was found.

Stated maximum penalty — The sanction attached to Art. 20 itself is civil: an act founded solely on automated profiling is incurably void (Art. 20.2), which the data subject may pursue through the habeas data action of Arts. 33-43. Separately, Art. 31 empowers the supervisory authority (now the Agencia de Acceso a la Información Pública) to impose a warning, suspension, a fine of ARS 1,000 to ARS 100,000, or closure or cancellation of the data file, without prejudice to civil damages and to the criminal offences in Arts. 117 bis and 157 bis of the Código Penal; the peso figures are the un-indexed statutory amounts as enacted in 2000.

In force · 11 Nov 2000 checked 15 Aug 2026 Ley 25.326 Art. 20 ↗ high confidence

Chile 1

Chile Binding

Ley 19.628 Art. 8° bis (inserted by Ley 21.719) — right to object to solely-automated decisions and profiling

Binds Controllers of personal data ('responsables de datos'), public and private, within the scope of Ley 19.628 as amended, including controllers not established in Chile whose processing is aimed at offering goods or services to data subjects in Chile or at monitoring their behaviour, expressly including its analysis, tracking, profiling or prediction. Impact tier: all entities.. Ley 21.719, which overhauls Chilean data-protection law and creates the Agencia de Protección de Datos Personales, inserts a new Art. 8° bis into Ley 19.628 headed 'Decisiones individuales automatizadas, incluida la elaboración de perfiles'. The data subject has the right to object to, and not to be subject to, decisions based on the automated processing of their personal data, including profiling, that produce legal effects on them or significantly affect them. The right does not apply where the decision is necessary to conclude or perform a contract between the subject and the controller, where the subject has given prior express consent in the form prescribed by Art. 12, or where a law so provides and lays down safeguards. In all cases of automated decision-making, including those three exceptions, the controller must adopt the measures needed to secure the subject's rights and freedoms, their right to information and transparency, and their right to obtain an explanation, to human intervention, to express their point of view and to request review of the decision. 'Elaboración de perfiles' is defined in the new Art. 2 w) as any automated processing used to evaluate, analyse or predict a person's professional performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements. Two related duties attach: Art. 14 ter l) requires the controller to disclose the existence of automated decisions and profiling together with meaningful information on the logic applied and the expected consequences, and Art. 15 bis makes a data-protection impact assessment mandatory where there is systematic and exhaustive evaluation of personal aspects based on automated processing or decisions, such as profiling, producing significant legal effects.

Ley 21.719 was published in the Diario Oficial on 13 December 2024. Artículo primero transitorio provides that the amendments to Ley 19.628, Ley 20.285 and Ley 19.496 contained in the first, second and third permanent articles enter into force on the first day of the twenty-fourth month after publication, i.e. 1 December 2026 — the same date carried in the BCN norm metadata (fecha_vigencia 2026-12-01, idNorma 1209272). Artículo segundo transitorio required the implementing regulations within six months of publication and Artículo cuarto transitorio required the first Agency board to be appointed six months before entry into force; implementation instruments already published include Decreto 12 of 17 June 2025 creating the ministerial implementation commission, Resolución Exenta 202503748 of 19 December 2025 approving the model contractual clauses for international transfers, and Resolución Exenta 1400 of 24 June 2026 on the procedures for Arts. 54 and 55, the last two of which themselves take effect on 1 December 2026. Text read in the Biblioteca del Congreso Nacional LeyChile XML for idNorma 1209272 via the backend host servicios-leychile.bcn.cl after the public www.bcn.cl endpoint returned HTTP 429. Chile's peer of br-lgpd-art20, cn-pipl-art24, kr-pipa-art37-2-adm and ar-ley25326-art20; unlike Argentina's Art. 20 it is a full GDPR-style right with explanation, human intervention and review, and unlike Brazil's Art. 20 it is not yet in force. Postponement risk (as of 2026-08-17): 1 December 2026 remains the legally operative date on the face of the law — no decree or amending law has changed it — but on 4 August 2026 co-Minister of Economy Daniel Mas publicly confirmed the government is evaluating postponing entry into force, because the Agencia de Protección de Datos Personales still has no seated Consejo Directivo: the Senate rejected the President's first slate of three nominees in May 2026 for lack of the required two-thirds quorum, and the June 2026 statutory deadline to appoint the board has lapsed. No amending bill has yet been introduced. Source: https://www.emol.com/noticias/Economia/2026/08/04/1207539/gobierno-postergar-ley-datos-personales.html

Stated maximum penalty — Enforced by the Agencia de Protección de Datos Personales under the new sanction regime of Ley 19.628. Art. 35: minor infringements draw a written warning or a fine of up to 5,000 UTM, serious infringements up to 10,000 UTM and very serious infringements up to 20,000 UTM. Obstructing or impeding the legitimate exercise of the right to object is a serious infringement under Art. 34 ter e); any other breach of the rights and duties of the law that is not classified as serious or very serious is a minor infringement under Art. 34 bis f). Repeat infringement allows a fine of up to three times the amount for the infringement committed, and for an infringer that is not a smaller enterprise under Art. segundo of Ley 20.416 repeating a serious or very serious infringement, up to 2% or 4% of annual turnover from sales, services and other business activities in the last calendar year. Repeated very serious fines within twenty-four months allow suspension of processing operations for up to thirty days (Art. 38). For public bodies the fine is 20% to 50% of the monthly salary of the head of the infringing body.

Applies 1 Dec 2026 checked 22 Aug 2026 Ley 19.628 Art. 8° bis (Ley 21.719) ↗ high confidence

China 1

China Binding

Anthropomorphic AI Interactive Services Measures

Binds Providers of anthropomorphic AI interactive services (virtual companions, emotional chatbots, human-like AI) publicly available in mainland China. Dedicated compliance regime for AI companion services, virtual chatbots and emotionally interactive AI; mandates AI-identity disclosure, minor protections, usage-time warnings, and prohibits inducing emotional dependence.

In force 15 Jul 2026. No confirmed enforcement actions as of 2026-08-08: exhaustive cross-check (Bird & Bird, IAPP, Covington, CAC official news/enforcement index, DigitalPolicyAlert) found no penalty decisions or enforcement notices. CAC does not publish a searchable administrative-penalty registry. A claim of 12 fines / RMB 4.2M circulates in AI-generated blog content (Cubbbix, Aug 2026; republished by Ethicore Substack verbatim) — not independently verifiable and treated as unconfirmed.

Stated maximum penalty — CAC administrative penalties; service suspension

In force · 15 Jul 2026 checked 17 Aug 2026 CAC Anthropomorphic AI Interim Measures (2026) ↗ high confidence

European Union 2

EU Comprehensive

Prohibited AI practices (Art. 5)

Binds All providers & deployers of AI systems in the EU. Bans on social scoring, manipulative AI, untargeted scraping.

Stated maximum penalty — Up to 7% global turnover or €35M

In force · 2 Feb 2025 checked 17 Aug 2026 EU AI Act ↗ high confidence
EU Comprehensive

New prohibitions — AI CSAM / intimate imagery

Binds All providers / deployers of such AI systems. New Art. 5 prohibition added by Digital Omnibus (Reg. EU 2026/1744, OJ L 2026/1744 published 24 Jul 2026); prohibits AI generation of CSAM and non-consensual intimate imagery. Applies from 2 Dec 2026.

Prohibition introduced by Regulation (EU) 2026/1744; the new Article 5 prohibition applies from 2 December 2026.

Stated maximum penalty — Up to 7% turnover or €35M

Applies 2 Dec 2026 checked 22 Aug 2026 EU AI Act (Digital Omnibus) ↗ high confidence

Kyrgyzstan 1

Kyrgyzstan Binding

Digital Code arts. 191-193 - every AI system used in the country must be danger-assessed, and both the method and the result must be published

Binds Владельцы систем искусственного интеллекта - the owners of AI systems applied in the Kyrgyz Republic, with the art. 192(3) risk-minimisation duty extending to users as well. Resolution No. 770 para. 2 spells the scope out: owners of AI systems applied in Kyrgyzstan 'irrespective of organisational-legal form, departmental (sectoral) affiliation and form of ownership'. There is no turnover, headcount, sector or nationality threshold anywhere in Chapter 23, so a sole trader running one model and a state body running a national platform owe the same assessment and the same publication.. Chapter 23 of the Digital Code of the Kyrgyz Republic (Code No. 178 of 31 July 2025), arts. 191 to 193, is the base layer of Kyrgyzstan's AI regime and it is unusual in applying to every AI system without a risk gate. Art. 191(1) starts from permission: AI systems are designed, developed and applied without restriction except where this Code says otherwise. Art. 191(2) then fixes seven sectoral principles that owners must build to - risk reduction, openness, explainability, human controllability, accuracy, reliability and security - and art. 191(3) makes them the basis on which every requirement for AI systems is set and read. Art. 192(1) limits what those requirements may protect to six enumerated goods (life and health, human and civil rights and freedoms, the environment, defence capability, national security, public order), art. 192(2) prohibits outright the design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to those goods, and art. 192(3) puts a general duty on owners and users of AI systems irrespective of danger level to take all reasonable and necessary measures to minimise the risk of such harm. Art. 193 is the operative obligation: ALL AI systems applied in Kyrgyzstan are subject to a danger assessment, carried out by the system's owner at the design stage, again on completion of development and before application, and again on any unplanned change to the system or its environment of use that could alter the result. The owner writes the methodology itself, but under requirements set by the Cabinet of Ministers, and art. 193(4) requires BOTH the assessment result AND the methodology to be posted on the owner's website in a form simple and intelligible to natural persons and additionally as open data, state secrets excepted. Those Cabinet requirements exist: Resolution No. 770 of 2 December 2025 approved a Requirements-for-the-danger-assessment-methodology annex, so this is a filled slot and not a deferred one.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The implementing act is Cabinet of Ministers Resolution No. 770 of 2 December 2025, published in «Эркин-Тоо» No. 96 (3753) of 5 December 2025, which approves five annexes under arts. 193 and 194 - the danger-assessment methodology requirements, and requirements for risk management, for system characteristics, for digital data quality and for technical documentation. Its para. 4 commences it 'fifteen days after the entry into force of the Digital Code', which computed from 6 February 2026 puts it at 21 February 2026; the ЦБД record card carries no dateOfEntry for the Resolution, so that single date is arithmetic from the Resolution's own text rather than a stated date. The Resolution's status in ЦБД is «Действует».

Stated maximum penalty — Nothing. There is no administrative offence for failing to run the danger assessment, for using a methodology that does not meet the Resolution No. 770 requirements, or for not publishing the result and the methodology. The only AI-specific offence Kyrgyzstan created is art. 228-10 of the Code of Offences (Code No. 128 of 28 October 2021, article inserted by Law No. 180 of 31 July 2025), and it reaches only the art. 192(2) prohibition: design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to the protected goods, fined at 200 расчетных показателей for natural persons and 650 for legal persons. The расчетный показатель has been 100 som since 1 January 2006 (Law No. 13 of 27 January 2006 art. 2; Jogorku Kenesh Resolution No. 1115-III of 15 June 2006, still «Действует»), so the ceiling is 20,000 som for a natural person and 65,000 som for a legal person - roughly 230 and 745 US dollars. This is the same enforcement gap Kazakhstan has: a fully drafted duty layer sitting on a single narrow offence.

In force · 6 Feb 2026 checked 22 Aug 2026 KG Digital Code arts. 191-193 ↗ high confidence

Kazakhstan 1

Kazakhstan Binding

AI Law art. 17(3) — seven AI capabilities banned outright, and the owner classifies its own risk tier

Binds Собственники и владельцы систем искусственного интеллекта — the owners and holders of AI systems. The Law states no size, sector, turnover or nationality threshold, so enterprise, SME, sole trader and public body are all covered on the same terms; the administrative fines in KoAP art. 641-1 are the place where size enters, and they are graded across natural persons, small business and non-commercial organisations, medium business and large business.. Law of the Republic of Kazakhstan No. 230-VIII ЗРК of 17 November 2025 «Об искусственном интеллекте» is Kazakhstan's first standalone AI statute and the first in Central Asia, and art. 17 is its structural core. Art. 17(3) forbids, on the territory of Kazakhstan, the creation and operation of AI systems possessing any one of seven functional capabilities: (1) use of subconscious, manipulative or other methods that distort a natural person's behaviour and limit their capacity to take informed decisions, or that push them into decisions capable of causing or threatening harm; (2) exploitation of a person's moral or physical vulnerability arising from age, disability, social position or any other circumstance, with the aim of causing or threatening harm; (3) evaluation and classification of natural persons or groups over a period of time on the basis of their social behaviour or known, assumed or predicted personal characteristics — a social-scoring ban, subject to cases provided by law; (4) collection and processing of personal data in breach of the personal-data legislation; (5) classification of natural persons on the basis of biometric data to infer race, political views, religious affiliation or any other criterion for the purpose of discriminating against them; (6) determination of a person's emotions without their consent, save in cases provided by law; and (7) creation and dissemination of results of AI activity that the laws prohibit. The list is close enough to EU AI Act art. 5 to be read against it, but it is a prohibition on creation and operation rather than on placing on the market, it has no law-enforcement-carve-out architecture, and the emotion-recognition limb is a consent rule rather than a workplace-and-education ban. Art. 17(1) then sets the three risk tiers — minimal, medium and high — and, unlike the EU's annex-driven scheme, assigns the classification to the owner and (or) holder of the system itself, applying the rules on classification of informatisation objects. High-risk systems that are also critically important information-and-communication infrastructure, or that are intended to form state electronic information resources, are treated as state systems for information-security purposes. Art. 17(2) adds a second, orthogonal axis of autonomy — low (a human always makes the final choice), medium (human correction or reversal remains possible) and high (human correction or reversal is wholly excluded or technically impossible) — and defers the rules on creating and operating high-autonomy systems to other laws, which is a real gap rather than a filled slot.

In force since 18 January 2026. Art. 31 commences the Law «по истечении шестидесяти календарных дней после дня его первого официального опубликования», with no article carved out. The А́ділет record card gives first official publication as the newspapers «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both of 18 November 2025, with the Reference Control Bank of NPA in electronic form following on 20 November 2025. The sixty days run from 19 November 2025 and expire at the end of 17 January 2026, so the Law entered into force on 18 January 2026. А́ділет serves the text as «Обновленный» (consolidated and current), database state 19 August 2026, and flags the only pending change — Law No. 326-VIII of 24 June 2026 — as a future «Примечание ИЗПИ» note rather than as applied text.

Stated maximum penalty — The Law itself sets no figure: art. 30 is a bare referral to responsibility «в соответствии с законами Республики Казахстан». The companion Law No. 232-VIII of 17 November 2025 inserted KoAP art. 641-1, but its part one reaches only two things — failure to inform users about misleading synthetic outputs, and failure to manage the risks of a high-risk system where that failure caused harm — so breach of the art. 17(3) prohibitions is NOT itself an enumerated administrative offence. In practice an art. 17(3) capability is reached indirectly: through art. 18(2), which obliges immediate suspension or termination once such a risk is identified and whose breach is penalised by art. 641-1, through art. 20(2)(2), which makes the presence of prohibited capabilities an express object of AI system audit, through the personal-data offences in KoAP art. 79-1 and following where limb (4) is engaged, and through the criminal law, since art. 641-1 applies only «если это действие (бездействие) не содержит признаков уголовно наказуемого деяния». This entry states no figure for art. 17(3) itself rather than importing the art. 641-1 band, which on its face does not cover it.

In force · 18 Jan 2026 checked 21 Aug 2026 KZ AI Law art. 17 ↗ high confidence

Peru 1

Peru Comprehensive

AI Law 31814 + Reglamento — risk-based regime

Binds Public and private AI developers / deployers. Prohibited / high-risk / acceptable tiers; high-risk AI needs prior evaluation, human oversight and transparency.

Stated maximum penalty — Referral to data-protection / Indecopi

In force · 22 Jan 2026 checked 20 Aug 2026 Ley 31814 + DS 115-2025-PCM ↗ high confidence

United Kingdom 2

UK Binding

UK DUAA 2025 s.138 — Non-consensual deepfake creation/request offences

Binds Any person in the UK who creates or requests creation of a non-consensual intimate deepfake image. Section 138 of the Data (Use and Access) Act 2025 inserts ss.66E–66H into the Sexual Offences Act 2003, criminalising the creation of non-consensual 'purported intimate images' (deepfakes) and the act of requesting such creation, even if the image is never distributed.

In force February 6, 2026 per SI 2026/31 (Commencement No. 5 Regulations 2026). Distinct from Crime and Policing Act 2026 (ss.66I–66L) which targets tool suppliers; this section targets end-users who create or request deepfakes.

Stated maximum penalty — Unlimited fine and/or summary imprisonment (Sexual Offences Act 2003)

In force · 6 Feb 2026 checked 21 Aug 2026 DUAA 2025, s.138 / Sexual Offences Act 2003 ss.66E–66H ↗ high confidence
UK Binding

Crime and Policing Act 2026 — AI-generated CSAM and deepfake offences

Binds Individual developers, distributors, and corporate bodies (criminal offences); Ofcom-regulated platforms (OSA priority-content duty). Criminalises making, adapting, possessing, supplying, or offering to supply AI models optimised to generate CSAM (up to 5 years imprisonment). Separately criminalises AI “nudification” tools/deepfake intimate image generators. Upgrades AI-generated intimate image creation to priority offences under the Online Safety Act; Ofcom-regulated platforms must prevent and remove such content (up to £3M penalty for non-compliance).

Royal Assent: 29 April 2026 (2026 c.20). Section 99 (purported intimate image generators) and related provisions commenced 29 June 2026 via UKSI 2026/689 (Commencement No. 1). CSAM generator offences (Pt.3 Ch.3) commenced on same SI.

Stated maximum penalty — 5 years imprisonment (CSA/deepfake AI generator offences); £3M Ofcom fine (platform intimate image duty)

In force · 29 Jun 2026 checked 21 Aug 2026 Crime and Policing Act 2026 ↗ high confidence

United States 14

US · Federal Binding

TAKE IT DOWN Act

Binds Anyone publishing non-consensual intimate imagery; covered online platforms (notice-and-removal). Bans non-consensual intimate imagery incl. AI deepfakes; covered platforms must remove within 48h (notice-and-removal duty live 19 May 2026).

Stated maximum penalty — FTC enforcement; criminal penalties

In force · 19 May 2025 checked 13 Aug 2026 TAKE IT DOWN Act (PL 119-12) ↗ high confidence
US · TX Binding

Texas Responsible AI Governance Act (TRAIGA)

Binds Persons developing/deploying AI in Texas or serving Texas residents; state agencies. Bans manipulative/discriminatory AI; AG-enforced.

Stated maximum penalty — Up to $200k/violation; $40k/day

In force · 1 Jan 2026 checked 13 Aug 2026 HB 149 ↗ high confidence
US · OR Binding

Oregon Bars Nonhuman Entities from Nursing Titles (HB 2748)

Binds Any nonhuman entity, including AI systems, using a protected nursing title or abbreviation in Oregon. Codified as ORS 678.027: a nonhuman entity, including but not limited to an agent powered by artificial intelligence, may not use the titles or abbreviations Advanced Practice Registered Nurse (APRN), Certified Registered Nurse Anesthetist (CRNA), Clinical Nurse Specialist (CNS), Licensed Practical Nurse (LPN), Registered Nurse (RN), Nurse Practitioner (NP), Certified Medication Aide (CMA), or Certified Nursing Assistant (CNA).

Enrolled House Bill 2748 (HB 2748-A), 83rd Oregon Legislative Assembly — 2025 Regular Session; passed House June 13, 2025, Senate June 11, 2025, signed by Gov. Kotek; codified 2025 c.378 §2 (ORS 678.027). The enrolled act contains only Sections 1 and 2 and no effective-date clause, so ORS 171.022 controls: "Except as otherwise provided in the Act, an Act of the Legislative Assembly takes effect on January 1 of the year after passage of the Act" — passed 2025, therefore in force Jan. 1, 2026.

Stated maximum penalty — Violation of ORS 678.010 to 678.415 (which includes 678.027) is a Class C misdemeanor — ORS 678.990(1)

In force · 1 Jan 2026 checked 14 Aug 2026 OR HB 2748 (2025 c.378 §2; ORS 678.027) ↗ high confidence
US · CA Binding

California Extends Health-Profession Title-Protection Law to AI (AB 489)

Binds Any person or entity that develops or deploys AI/GenAI systems using health-profession-protected terms, letters, or phrases (broader than nursing — covers all licensed healing-arts professions, e.g. medicine, dentistry, psychology). Adds Bus. & Prof. Code §§ 4999.8-4999.9: makes existing law that bars falsely indicating or implying possession of a health-care license (e.g., under the Medical Practice Act, Dental Practice Act) enforceable against any person or entity that develops or deploys an AI or GenAI system using protected terms, letters, or phrases in its advertising or functionality. Separately prohibits AI/GenAI use of terms implying that care, advice, reports, or assessments are provided by a licensed natural person. Each prohibited use is a separate violation.

AB 489 (Bonta), approved by Governor and filed with Secretary of State Oct. 11, 2025; no urgency clause, so it took effect Jan. 1, 2026 under the default California statutory effective-date rule (Cal. Const. art. IV, §8(c)).

Stated maximum penalty — Enforced via the applicable health-care licensing board's injunctive authority (Bus. & Prof. Code §125.5) plus the penalty already attached to the underlying title-protection provision being invoked (e.g., unauthorized practice of medicine under §2052 is a public offense punishable by up to 1 year in county jail and/or a $10,000 fine)

In force · 1 Jan 2026 checked 14 Aug 2026 CA AB 489 (Bus. & Prof. Code §§ 4999.8-4999.9) ↗ high confidence
US · DE Binding

Delaware AI Agents Barred from Medical/Nursing Licensure and Titles (HB 191)

Binds Any person or entity deploying or offering an AI agent in Delaware that would be licensed as, or presented under the title of, a nurse, physician, or physician assistant. A nonhuman entity, including an agent powered by artificial intelligence, may not be licensed or certified to practice professional nursing, advanced practice registered nursing, practical nursing, medicine, or as a physician assistant in Delaware, and may not use the associated protected titles — "Nurse", "RN", "LPN", "APRN", "CRNA", "CNS", "CNP", "CNM", "Doctor"/"Dr.", "Physician", "Surgeon", "MD", "DO", "Physician Assistant"/"PA". Amends 24 Del. C. §§ 1920, 1720, 1773. Does not restrict AI clinical decision-support or documentation tools that do not hold themselves out under a licensed title.

Signed by Gov. Meyer and approved April 23, 2026 as 85 Del. Laws ch. 250; no delayed-effective-date clause, so effective on enactment.

Stated maximum penalty — Medicine: class F felony, $1,000–$5,000 fine and/or up to 3 years (24 Del. C. § 1766(a)); other Ch. 17 violations class B misdemeanor (§ 1766(c)). Nursing/title misuse: up to $1,000 and/or 1 year (24 Del. C. § 1925)

In force · 23 Apr 2026 checked 14 Aug 2026 DE HB 191 (85 Del. Laws ch. 250) ↗ high confidence
US · WA Binding

Washington Forged Digital Likeness Protection Act (SB 5886 / Ch.69)

Binds Any person creating, distributing, or facilitating AI-generated/manipulated likenesses of Washington residents. Prohibits creating or using AI-generated forged digital likenesses without consent; amends WA Personality Rights Act.

Stated maximum penalty — $3,000/violation + noneconomic damages; private right of action

In force · 11 Jun 2026 checked 13 Aug 2026 SB 5886 / Ch.69 ↗ high confidence
US · WA Binding

Washington Bars Nonhuman Entities from Nursing Titles (HB 2155)

Binds Any person or nonhuman entity (including AI systems, chatbots, and automated triage/care tools) presenting itself under a protected nursing title or abbreviation in Washington. Amends RCW 18.79.030: only a human person licensed under ch. 18.79 RCW may practice as, or use the titles of, a registered nurse ("RN"), advanced practice registered nurse/nurse practitioner ("APRN"/"NP"), or licensed practical nurse ("LPN"). No other person or any nonhuman entity may assume those titles or abbreviations, or use other words, letters, signs, or figures indicating it is a nurse.

House Bill 2155, 2026 Regular Session, passed House Feb. 11, 2026 (87-8) and Senate Feb. 26, 2026 (46-2); delivered to Governor Mar. 3 and signed Mar. 9, 2026 as Chapter 6, 2026 Laws. The enrolled act contains no effective-date section; the Legislature's own bill record states "Effective date 6/11/2026" (Washington's default general effective date, 90 days after sine die). Sec. 1 (in force) expires June 30, 2027, when Sec. 2 (an equivalent re-enactment) takes over.

Stated maximum penalty — Enforced as unlicensed practice under RCW 18.130.190: civil fine up to $1,000/day (18.130.190(3)); first violation is a gross misdemeanor, subsequent violations a class C felony (18.130.190(7))

In force · 11 Jun 2026 checked 14 Aug 2026 WA HB 2155 (amending RCW 18.79.030) ↗ high confidence
US · RI Binding

Rhode Island Oversight of AI in Mental Health Care Act (H 7349 Sub A)

Binds Any individual, corporation or entity offering therapy/psychotherapy services in Rhode Island, and RI-licensed mental health professionals using AI. R.I. Gen. Laws ch. 40.1-5.5. No individual, corporation or entity may provide, advertise or offer therapy/psychotherapy services to the public in RI — including via Internet-based AI — unless conducted by a licensed professional (§ 40.1-5.5-3(b)). Licensed professionals may use emotional-attachment/companion AI in recorded or transcribed sessions only with prior written informed consent (§ 40.1-5.5-3(a)), and may not let AI make independent therapeutic decisions, conduct therapeutic communication without an established relationship, or set treatment plans (§ 40.1-5.5-3(c)). Carve-outs: religious counseling, peer support, public self-help materials, and FDA-cleared AI tools.

Enacted as Substitute A (LC004589/SUB A/2); signed by Governor McKee June 22, 2026; effective upon passage. Verified against the enacted Sub A text 2026-08-10.

Stated maximum penalty — Confidentiality violations: penalties under R.I. Gen. Laws § 5-37.3-9; EOHHS investigative authority; RI licensing enforcement

In force · 22 Jun 2026 checked 13 Aug 2026 H 7349 ↗ high confidence
US · IL Binding

Illinois AI Teacher Evaluation Restrictions (SB 2909 / PA 104-0565)

Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.

Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.

Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified

Applies 1 Jan 2027 checked 20 Aug 2026 SB 2909 / PA 104-0565 ↗ high confidence
US · NJ Binding

NJ FAIR Act — Algorithmic Rent-Setting Ban (A3497/S451)

Binds Residential rental property owners and algorithmic revenue management software coordinators operating in New Jersey. Prohibits residential landlords and algorithmic revenue-management software coordinators from using algorithms that share competing landlords' nonpublic pricing data to recommend rents; bans parallel pricing coordination via software.

Signed 2026-07-20 by Gov. Mikie Sherrill; effective first day of the twelfth month following enactment (2027-07-01).

Stated maximum penalty — NJ Antitrust Act enforcement (P.L.1970, c.73); AG complaint portal required; penalty as provided under NJ Antitrust Act

Applies 1 Jul 2027 checked 13 Aug 2026 FAIR Act (A3497/S451) ↗ high confidence
US · IL Binding

Illinois Transparency in Downcoding Act (SB 3114 / PA 104-0568)

Binds Health insurance issuers and managed care organizations in Illinois (excludes self-insured ERISA plans and workers' compensation). Prohibits health insurers and managed care organizations from using algorithms or automated tools to downcode medical claims without comprehensive human review; requires AMA CPT coding guideline-compliant physician review of all downcoding determinations; bans discriminatory targeting of providers treating complex/chronic patients.

Signed 2026-07-10 by Governor Pritzker; effective 2028-01-01.

Stated maximum penalty — Fines, restitution, or license suspension (IL Department of Insurance enforcement)

Applies 1 Jan 2028 checked 13 Aug 2026 SB 3114 / PA 104-0568 ↗ high confidence
US · MD Proposed

Maryland Protection From Predatory Pricing Act (HB 895 / Ch. 154)

Binds Food retail stores ≥15,000 sq ft selling tax-exempt food, and third-party delivery service providers arranging delivery from such stores, operating in Maryland. First US state law banning AI-driven personalised (surveillance) pricing in food retail and delivery; prohibits setting prices based on individual consumer personal data.

EXCLUDED FROM ACTIVE COVERAGE — CEO ruling AIL-136 (2026-08-03): all AI/algorithm language was deliberately struck from HB 895 before enactment. The enacted Ch. 154 prohibits personalized data-driven pricing for tax-exempt food (retailers ≥15,000 sq ft + food delivery); no AI definition, no near-real-time AI dynamic-pricing clause, no §13-322 algorithmic-pricing disclosure. Enacted operative line is personal data, not AI. Narrow food scope, regulatory-only, no private right of action. Fails coverage prong (a): AI is not load-bearing in enacted text. REVERSAL TRIGGER: re-escalate to CEO if AI/algorithm language is re-introduced in a future MD legislative session, or if personalized/surveillance pricing becomes an AI-governance flashpoint with AI-specific statutory language.

Stated maximum penalty — Up to $10,000 per violation; up to $25,000 per violation for repeat offenders (Maryland AG enforcement)

Proposed · target 1 Oct 2026 checked 22 Aug 2026 MD HB 895 / Ch. 154 ↗ high confidence
US · IL Proposed

Illinois AI Rental Price Coordination Ban (SB 343)

Binds Landlords of residential units in Illinois and third-party algorithmic pricing service providers who facilitate rental price coordination. Amends the Illinois Antitrust Act to prohibit landlords and third-party services from using AI algorithms to coordinate residential rental pricing; specifically targets algorithmic platforms (e.g., RealPage) used by competing landlords to fix or stabilize rents.

The AI rental-pricing language no longer exists in this bill vehicle. Senate Floor Amendment No. 1 (adopted 2026-05-21) had added the algorithmic rental-price-coordination ban described above, but House Committee Amendment No. 1 (filed 2026-05-28, adopted 2026-05-29) replaced that content entirely with unrelated Cook County / Calumet City eminent-domain (quick-take) provisions for economic development. Governor Pritzker signed the bill on 2026-08-07 as Public Act 104-0805; the enacted text contains no AI or algorithmic-pricing provisions.

Stated maximum penalty — Illinois Antitrust Act — civil penalties (enforcement by Illinois AG)

Proposed checked 13 Aug 2026 SB 343 (IL 104th GA) ↗ high confidence

Uzbekistan 1

Uzbekistan Binding

Administrative Liability Code art. 46² part 2 — unlawful AI processing of personal data

Binds Any person who unlawfully processes personal data using AI technologies and disseminates it in mass media, telecommunications networks or the Internet. Unlawfully processing personal data with AI technologies and disseminating it in the media, telecom networks or the Internet is an administrative offence carrying a fine and confiscation.

Part two was added to art. 46² of the Code on Administrative Liability (Law No. 2015-XII of 22 Sept 1994) by art. 2 of Law No. ЎРҚ-1115 of 21 January 2026, in force on publication (National Database of Legislation, 21.01.2026, No. 03/26/1115/0063). It reads: unlawful processing of personal data using artificial intelligence technologies, and their dissemination in mass media, telecommunications networks or the worldwide information network Internet, entails a fine of fifty to one hundred base calculation units (базовая расчетная величина, BRV — an index re-set periodically by presidential decree, so the soum figure moves) with confiscation of the objects of the offence. Note the cumulative structure: the text couples unlawful processing WITH dissemination, so AI processing that stays internal is charged under part one (7 BRV for citizens, 50 BRV for officials) rather than part two. ЎРҚ-1115 also added a matching ground to art. 12¹ of the Law on Informatization, which is the access-restriction route for the same conduct. This is the only penalty the 2026 AI amendment act created — art. 7¹ of the Law on Informatization has none.

Stated maximum penalty — Fine 50–100 BRV + confiscation of the objects of the offence

In force · 21 Jan 2026 checked 21 Aug 2026 KoAO art. 46²(2) ↗ high confidence

Questions & answers

From the data

What AI practices does the EU AI Act ban?

Article 5 prohibits, among others, harmful manipulation, exploitation of vulnerabilities, social scoring by public authorities, certain predictive policing, untargeted scraping of facial images and most real-time remote biometric identification in public spaces. The bans have applied since 2 February 2025.

Is non-consensual deepfake imagery banned?

Increasingly, yes. The US TAKE IT DOWN Act bans non-consensual intimate imagery, including AI deepfakes, and requires covered platforms to remove it; the EU has added a new Article 5 prohibition targeting AI-generated CSAM and intimate imagery.

Do the prohibitions apply to small companies?

Article 5-style bans generally apply to anyone placing such a system on the market or putting it into service in the jurisdiction, regardless of size. Scope and exemptions differ by instrument — check the linked source.

Is algorithmic rent-setting or personalised pricing banned?

In a growing number of US states. New Jersey’s FAIR Act and Illinois’ SB 343 prohibit landlords and revenue-management vendors from using algorithms fed with competitors’ nonpublic pricing data to set or coordinate residential rents; Maryland’s Protection From Predatory Pricing Act bans pricing food-retail and delivery items from an individual consumer’s personal data. Illinois’ bill had passed the legislature but was not yet signed as of 28 July 2026 — each row above carries its own status.

Which jurisdictions does AI Law Radar track for prohibited ai practices?

We currently track prohibited ai practices obligations across 10 jurisdictions: Argentina, Chile, China, European Union, Kyrgyzstan, Kazakhstan, Peru, United Kingdom, United States and Uzbekistan. Each is dated and linked to its primary source on this page.