Home › Topics › consumer protection
U.S. AI Laws: consumer protection
As of 2026-08-12, AI Laws USA tracks 358 U.S. AI rules on consumer protection across federal, state, county, and city government. Each entry links to its official source.
Federal consumer protection rules (95)
-
In effect
Benavides v. Tesla (Autopilot)
S.D. Fla. · Effective 2025-08-01 · Benavides v. Tesla, Inc., No. 1:21-cv-21940 (S.D. Fla. Aug. 1, 2025)
A Florida federal jury found Tesla 33% liable in August 2025 for the 2019 death of Naibel Benavides Leon, in a crash involving Autopilot. The jury awarded $243M ($129M compensatory + $200M punitive); in February 2026 the court denied Tesla's post-trial motions and upheld the verdict in full — the first Autopilot wrongful-death verdict against Tesla.
-
In effect
COPPA + 2025 Rule (childrens data)
United States · Effective 2025-06-23 · 15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312
COPPA requires online services aimed at children under 13 to get verifiable parental consent before collecting kids' personal data. The 2025 rule update — fully in effect since April 22, 2026 — adds biometric identifiers (like face templates and voiceprints, which matter for AI tools), requires separate parental consent before sharing children's data for targeted advertising, and tightens data retention limits.
-
In effect
TAKE IT DOWN Act
United States · Effective 2025-05-19 · Pub. L. No. 119-12 (S. 146)
Makes it a federal crime to knowingly publish intimate images of someone without consent, including AI-generated deepfakes. Social media and similar platforms must give victims a way to request removal and must take the content (and known copies) down within 48 hours. The platform removal requirement became enforceable May 19, 2026, and the FTC has already begun enforcement.
-
In effect
Louis v. SafeRent
D. Mass. · Effective 2024-11-20 · Louis v. SafeRent Solutions, LLC, No. 1:22-cv-10800 (D. Mass.)
SafeRent agreed in November 2024 to a $2.275M settlement and a five-year ban on using its 'SafeRent Score' for housing-voucher applicants, after a class action alleged its AI tenant-screening tool systematically denied housing to Black and Hispanic Section 8 voucher holders. The first major AI tenant-screening Fair Housing Act settlement.
-
In effect
FTC Impersonation Rule (AI)
United States · Effective 2024-04-01 · 16 C.F.R. Part 461; 89 Fed. Reg. 15017
The FTC's Impersonation Rule lets the agency directly sue scammers who pretend to be a government agency or a real business — including those who use AI-cloned voices or generated images to do so. Civil penalties can reach $53,088 per violation. The FTC also issued a supplemental notice in February 2024 proposing to extend the rule to all individual impersonation.
-
In effect
TCPA (AI voice calls)
United States · Effective 2024-02-08 · 47 U.S.C. § 227; FCC 24-17
Robocalls using AI-cloned or AI-generated voices are treated like other 'artificial voice' calls: callers need your prior express consent, must identify themselves, and must offer opt-outs for telemarketing. You can personally sue violators for $500 to $1,500 per illegal call.
-
In effect
FTC v. Rite Aid
FTC · Effective 2023-12-19 · FTC v. Rite Aid Corp., No. 2:23-cv-05023 (E.D. Pa. Dec. 19, 2023)
The FTC banned Rite Aid from using facial-recognition technology in its stores for five years after finding the pharmacy chain's FRT system falsely tagged customers — disproportionately women and people of color — as shoplifters, leading to wrongful detentions and humiliations.
-
In effect
FAA Part 107 (drones)
United States · Effective 2016-08-29 · 14 C.F.R. Part 107
The core federal rulebook for commercial and recreational small drones (under 55 lb). Operators need a Remote Pilot Certificate, must keep the drone within visual line of sight, fly below 400 ft, avoid most airspace without authorization, and follow operations-over-people limits. Waivers and Beyond-Visual-Line-of-Sight (BVLOS) approvals exist for advanced operators.
-
In effect
ECOA / Regulation B (AI credit discrimination)
United States · Effective 1975-10-28 · 15 U.S.C. § 1691; 12 C.F.R. Part 1002
Lenders cannot discriminate in credit decisions and must give you specific, accurate reasons when they deny or worsen your credit — even if the decision was made by an AI model. Earlier CFPB guidance said lenders can't hide behind 'black box' algorithms; that guidance was withdrawn in May 2025, but the underlying statute and regulation still require accurate adverse-action notices.
-
In effect
FCRA (AI in credit & background checks)
United States · Effective 1971-04-25 · 15 U.S.C. § 1681 et seq.
When a company uses a consumer report or score — including AI-generated risk scores from background-check and tenant/employment screening firms — to deny you credit, insurance, housing, or a job, it must tell you and identify the agency that supplied the report. You have the right to a free copy of your file and to dispute inaccurate information, no matter how algorithmic the scoring was.
-
In effect
FTC Act Section 5 (unfair/deceptive AI)
United States · Effective 1914-09-26 · 15 U.S.C. § 45
The FTC's basic consumer-protection law bans unfair or deceptive business practices, and the agency applies it directly to AI. Companies cannot lie about what their AI can do, use AI to deceive people, or sell AI tools designed for fraud. The FTC's 'Operation AI Comply' sweep has brought numerous cases since 2024.
-
Enacted (not yet in effect)
DOJ ADA Title II Web Rule
United States · Effective 2027-04-24 · 89 Fed. Reg. 31320 (Apr. 24, 2024)
DOJ final rule requiring state and local government web content and mobile apps (including AI-driven services) to meet WCAG 2.1 AA. Compliance dates extended to 2027/2028.
-
In effect
FERC Large-Load Interconnection Orders (RM26-4)
United States · Effective 2026-06-18 · FPA § 206 show-cause orders, FERC Docket Nos. EL26-67 through EL26-72 (June 18, 2026), advancing ANOPR Docket No. RM26-4-000
On June 18, 2026, FERC issued tailored show-cause orders under Section 206 of the Federal Power Act to the six major U.S. regional grid operators (PJM, MISO, SPP, CAISO, ISO-NE, and NYISO), directing each to either justify its existing large-load interconnection tariff as just and reasonable or file tariff revisions within 60 days. The orders target the surge in demand from AI data centers and large industrial loads, requiring reforms to study processes, cost transparency to prevent cost-shifting onto ordinary ratepayers, co-location and behind-the-meter accommodation, and new services for flexible large loads. FERC left retail cost-shifting protection to state regulators; reforms apply prospectively and do not disrupt existing deals.
-
In effect
DOJ-RealPage Consent Decree (algorithmic rent)
United States · Effective 2026-05-01 · United States v. RealPage, Inc. et al., No. 1:24-cv-00710 (M.D.N.C.); 15 U.S.C. §§ 1–2
In November 2025, the DOJ settled with RealPage — the dominant algorithmic rent-pricing software company — requiring it to stop using competitors' real-time pricing data to coordinate rents. The settlement received preliminary court approval in May 2026 and places RealPage under a court-appointed compliance monitor for seven years. Thousands of property managers used RealPage's software; the DOJ alleged it enabled competing landlords to align rental prices, harming renters across the country.
-
In effect
Doe v. X.AI (Grok NCII deepfakes class action)
United States · Effective 2026-01-23 · Doe v. X.AI Corp., No. 5:26-cv-00772 (N.D. Cal., filed Jan. 23, 2026); amended complaint July 7, 2026
A class action filed January 23, 2026 in the Northern District of California (Case No. 5:26-cv-00772) alleges that X.AI's Grok AI model generated over three million sexualized deepfake images in an 11-day period, including images of minors. An amended complaint filed July 7, 2026 added Stability AI as a co-defendant and two new plaintiffs, including one who alleges approximately 7,000 child sexual abuse material (CSAM) images were generated of them. Claims include product liability, negligence, public nuisance, and privacy violations. A companion case (Doe 1 v. X.AI Corp., No. 5:26-cv-02246) was filed March 16, 2026. Note: X.AI Corp. has rebranded to SpaceXAI following its merger with SpaceX.
-
In effect
FTC v. IntelliVision
FTC · Effective 2024-12-19 · In re IntelliVision Techs. Corp., FTC No. C-4813 (Dec. 19, 2024)
The FTC settled with IntelliVision in December 2024, alleging the company falsely claimed its facial-recognition product had 'zero gender or racial bias' without testing-data to support that — and that its accuracy claims were unsubstantiated. Builds on the FTC's Rite Aid theory.
-
In effect
FTC v. Evolv
FTC · Effective 2024-11-26 · Federal Trade Commission v. Evolv Technologies Holdings, Inc., No. 1:24-cv-12940 (D. Mass. Nov. 26, 2024)
The FTC settled with Evolv Technology in November 2024 over claims it falsely marketed its AI-powered scanners as accurately detecting weapons in schools and venues, when in fact the systems missed weapons (including the knife in the Utica, NY school stabbing) and flagged everyday objects. Customers can cancel contracts.
-
In effect
FinCEN deepfake-fraud BSA alert
United States · Effective 2024-11-13 · FinCEN Alert FIN-2024-Alert004 (Nov. 13, 2024)
FinCEN issued an alert telling banks and other financial institutions how to spot — and report — fraud schemes that use generative-AI deepfakes to defeat identity verification. Suspicious activity reports must use the SAR keyword 'FIN-2024-DEEPFAKEFRAUD' so FinCEN can track the trend in synthetic identity and account-takeover fraud.
-
In effect
CFPB AI chatbot circular
United States · Effective 2024-10-23 · CFPB Issue Spotlight (June 2023); CFPB UDAAP / ECOA / TILA enforcement posture (2024)
Building on its 2023 chatbot report, the CFPB has warned that banks and lenders using generative-AI chatbots that mislead consumers — about fees, account terms, or credit denials — face liability under the Consumer Financial Protection Act, the Equal Credit Opportunity Act, and the Truth in Lending Act. Hallucinating chatbots are not a regulatory loophole.
-
Blocked / in litigation
Character.AI Companion Chatbot Suits
M.D. Fla. + E.D. Tex. · Effective 2024-10-22 · Garcia v. Character Techs., Inc., No. 6:24-cv-01903 (M.D. Fla.); A.F. v. Character Techs., Inc., No. 2:24-cv-01014 (E.D. Tex.)
Five plaintiffs across two jurisdictions sued Character.AI in 2024 alleging the companion chatbot service caused minors' suicide, self-harm, sexual abuse, and severe mental injury. Garcia v. Character.AI in Florida was the first AI companion wrongful-death suit; in Texas a federal court issued a landmark May 2025 ruling that AI chatbot outputs are not protected First Amendment speech.
-
In effect
FTC Operation AI Comply
United States · Effective 2024-09-25 · FTC Operation AI Comply (Sept. 25, 2024)
FTC enforcement sweep announcing five settlements against firms using AI to enable deceptive or unfair conduct. Establishes a baseline of cases for ongoing AI deception enforcement.
-
In effect
FTC v. DoNotPay
FTC · Effective 2024-09-25 · In re DoNotPay, Inc., FTC No. C-4796 (Sept. 25, 2024)
The FTC settled with 'AI lawyer' DoNotPay in September 2024 over claims the company falsely marketed an AI chatbot as a substitute for a human lawyer, without ever testing whether its outputs matched a competent attorney's work. Part of the FTC's 'Operation AI Comply' sweep.
-
In effect
FTC v. Rytr
FTC · Effective 2024-09-25 · In re Rytr LLC, FTC No. C-4795 (Sept. 25, 2024)
Part of Operation AI Comply: the FTC ordered AI writing service Rytr to stop offering a 'testimonial and review' generator that produced fake consumer reviews on demand. The first FTC action against an AI product specifically designed to generate deceptive content.
-
In effect
FTC Operation AI Comply (Sept. 2024)
FTC · Effective 2024-09-25 · FTC Press Release, Operation AI Comply (Sept. 25, 2024)
On September 25, 2024 the FTC announced 'Operation AI Comply' — a coordinated sweep against five companies (DoNotPay, Rytr, Ascend Ecom, Ecommerce Empire Builders, FBA Machine) accused of using AI claims to defraud consumers. Marked the FTC's first systemic AI enforcement sweep.
-
In effect
DOJ AI-fraud sentencing guidance
United States · Effective 2024-09-23 · DOJ Criminal Division ECCP (Sept. 23, 2024); Deputy AG Lisa Monaco, ABA White Collar Conf. (Mar. 5, 2024)
The Justice Department updated its corporate compliance guidance in September 2024 to require companies to assess and mitigate AI-related risks, and Deputy AG Lisa Monaco announced in March 2024 that DOJ will seek stiffer sentences when AI is used to commit fraud — treating AI as an aggravating factor.
-
In effect
FCC Lingo Telecom Biden deepfake fine
United States · Effective 2024-08-21 · FCC Consent Decree, DA 24-823 (Aug. 21, 2024)
The FCC fined voice provider Lingo Telecom $1 million for carrying AI-generated robocalls that used a cloned voice of President Biden to suppress votes in the January 2024 New Hampshire primary. It was the first FCC enforcement action against a carrier for transmitting AI deepfake robocalls.
-
In effect
FTC HBNR Rule (AI health apps)
United States · Effective 2024-07-29 · 16 C.F.R. Part 318; 89 Fed. Reg. 47028
Health apps and connected devices — including AI-powered mental health and fitness tools — must notify users, the FTC, and (in some cases) the media within 60 days of a breach of identifiable health information. The 2024 amendments confirm that AI-generated inferences about health are covered.
-
In effect
FTC v. NGL Labs
FTC · Effective 2024-07-09 · United States v. NGL Labs, LLC, No. 2:24-cv-05753 (C.D. Cal. July 9, 2024)
The FTC and the Los Angeles DA settled with anonymous-messaging app NGL Labs for $5M in July 2024, alleging the company used fake AI-generated 'anonymous' messages to manipulate teen users into paying for premium features that wouldn't actually reveal sender identities. NGL is banned from marketing to under-18 users.
-
In effect
HHS § 1557 Rule (AI clinical tools)
United States · Effective 2024-07-05 · 45 C.F.R. § 92.210; 89 Fed. Reg. 37522
HHS's Section 1557 rule bans discrimination in 'patient care decision-support tools,' which includes AI and algorithmic clinical tools. Covered health programs and providers must identify when a tool relies on patient race, age, disability, or other protected traits and take steps to mitigate the risk of discrimination.
-
Blocked / in litigation
Lehrman v. Lovo
S.D.N.Y. · Effective 2024-05-16 · Lehrman v. Lovo, Inc., No. 1:24-cv-03770 (S.D.N.Y.)
Voice actors Paul Lehrman and Linnea Sage sued AI voice-cloning startup Lovo, alleging Lovo cloned their voices through deceptive Fiverr commissions and resold the clones without consent. The case is the highest-profile U.S. voice-cloning right-of-publicity action and was certified in part in 2025.
-
In effect
FAA Reauthorization Act 2024 (drones)
United States · Effective 2024-05-16 · Pub. L. No. 118-63
The five-year FAA reauthorization sets the agenda for U.S. drone integration through 2028: it directs the FAA to finalize a Beyond-Visual-Line-of-Sight rule, expands counter-drone authority for federal and (in pilot programs) state and local agencies, advances Advanced Air Mobility (passenger drones / eVTOLs), and tightens rules on drones produced by countries of concern.
-
In effect
HUD FHEO Tenant Screening AI
United States · Effective 2024-05-02 · HUD FHEO, Guidance on Application of the Fair Housing Act to the Screening of Applicants for Rental Housing (May 2, 2024)
HUD guidance applying the Fair Housing Act to algorithmic tenant screening — landlords and screening vendors share liability for discriminatory outcomes.
-
In effect
HUD FHEO Digital Advertising AI
United States · Effective 2024-05-02 · HUD FHEO, Guidance on Application of the Fair Housing Act to the Advertising of Housing, Credit, and Other Real Estate-Related Transactions through Digital Platforms (May 2, 2024)
HUD guidance making clear that algorithmic ad-targeting causing discriminatory exposure violates the Fair Housing Act.
-
In effect
SEC AI-washing settlement
United States · Effective 2024-03-18 · In re Delphia (USA) Inc., Securities Act Rel. No. 11264 (Mar. 18, 2024); In re Global Predictions Inc., Securities Act Rel. No. 11265 (Mar. 18, 2024)
The SEC charged two investment advisers — Delphia (USA) and Global Predictions — with making false and misleading statements about using AI and machine learning. The firms paid $400,000 combined in civil penalties. It was the SEC's first 'AI-washing' enforcement action and signals scrutiny of overstated AI capability claims in financial services.
-
In effect
CMS MA Rule (AI prior auth)
United States · Effective 2024-01-01 · 42 C.F.R. § 422.101(c); 88 Fed. Reg. 22120 (Apr. 12, 2023)
Medicare Advantage plans cannot use algorithms or AI to deny medically necessary care. Any algorithm-driven coverage decision must comply with traditional Medicare coverage criteria and consider the individual patient's circumstances — not just generic model output.
-
Blocked / in litigation
DOJ / Multistate v. Yardi
W.D. Wash. · Effective 2023-12-29 · Duffy v. Yardi Systems, Inc., No. 2:23-cv-01391 (W.D. Wash.)
Renters brought a parallel class action against Yardi Systems — RealPage's main competitor in algorithmic rent-pricing — alleging it likewise coordinated multifamily rents across competing landlords. State AGs joined as enforcement actors; the case is moving in parallel with the DOJ-RealPage proceeding.
-
In effect
CFPB Circ. 2023-03 (AI credit)
United States · Effective 2023-09-19 · CFPB Circular 2023-03 (Sept. 19, 2023)
CFPB Circular 2023-03 clarifies that lenders using AI or other complex credit models for credit denial cannot rely on checklist adverse-action notices. They must provide specific, accurate reasons under ECOA — even if the AI's decision is hard to explain.
-
In effect
CFPB § 1071 Rule (small-biz AI lending)
United States · Effective 2023-08-29 · 12 C.F.R. Part 1002 Subpart B; 88 Fed. Reg. 35150
Lenders covered by the rule must collect and report demographic and transactional data on small-business credit applications — including data needed to detect algorithmic discrimination by AI underwriting models.
-
In effect
FTC v. Amazon (Ring)
FTC · Effective 2023-07-31 · Federal Trade Commission v. Ring LLC, No. 1:23-cv-01549 (D.D.C. 2023)
The FTC settled with Amazon's Ring subsidiary for $5.8M in 2023 over privacy and security failures — including allowing employees and contractors to view customer videos without consent and failing to prevent stalkers from compromising accounts. The settlement restricts Ring's use of customer videos for product / AI development.
-
In effect
FTC v. Amazon (Alexa)
FTC · Effective 2023-07-25 · United States v. Amazon.com, Inc., No. 2:23-cv-00811 (W.D. Wash. July 25, 2023)
Companion FTC action settled with Amazon's Alexa division for $25M in 2023, alleging Amazon retained children's voice recordings indefinitely despite COPPA, deleted records when parents requested but kept transcripts and the underlying voice models, and used the data to train Alexa's voice-recognition AI.
-
Blocked / in litigation
Cigna PXDX AI Denial Class Action
E.D. Cal. · Effective 2023-07-24 · Kisting-Leung v. Cigna Corp., No. 2:23-cv-01477 (E.D. Cal.)
Patients sued Cigna in 2023 alleging its 'PxDx' algorithm reviewed and denied roughly 300,000 claims in two months — averaging 1.2 seconds per denial — without genuine physician review, violating California and federal law. Triggered a wave of similar AI healthcare-denial suits against UnitedHealth (NaviHealth) and Humana.
-
In effect
Mata v. Avianca (ChatGPT fake cites)
S.D.N.Y. · Effective 2023-06-22 · Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023)
Two New York attorneys submitted a brief containing six fictitious case citations generated by ChatGPT. In June 2023 Judge P. Kevin Castel sanctioned them $5,000 each — the first formal federal sanction for AI-hallucinated legal citations, and the most-cited case in subsequent bar opinions on attorney AI use.
-
In effect
NHTSA SGO 2021-01 (AV/ADAS reporting)
United States · Effective 2021-06-29 · NHTSA SGO 2021-01
Manufacturers and operators of vehicles equipped with SAE Level 2 driver-assistance (Tesla Autopilot, GM Super Cruise) or Level 3-5 automated driving systems must report crashes to NHTSA on a strict timeline — within one day for serious crashes. The data drives recall actions including Tesla's Dec. 2023 over-the-air Autopilot recall.
-
In effect
NHTSA AV federal framework
United States · Effective 2021-06-29 · NHTSA Standing General Order 2021-01; 49 U.S.C. § 30166
NHTSA's Standing General Order requires automakers and operators of Level 2 driver-assistance and Level 3–5 automated driving systems to report crashes involving those systems. Federal Motor Vehicle Safety Standards regulate vehicle design; NHTSA's voluntary safety guidance (AV 4.0) and the Automated Vehicle Comprehensive Plan provide non-binding policy direction.
-
In effect
Robles v. Domino's
9th Cir. · Effective 2019-10-07 · Robles v. Domino's Pizza, LLC, 913 F.3d 898 (9th Cir. 2019), cert. denied, 140 S. Ct. 122
While predating modern generative AI, the Ninth Circuit's 2019 Robles v. Domino's ruling — followed by Supreme Court cert. denial — established that ADA Title III applies to web and mobile apps that interact with brick-and-mortar services. The decision is now the doctrinal anchor for AI chatbot and voice-assistant accessibility claims.
-
In effect
FDA 510(k) — surgical robots
United States · Effective 1976-05-28 · 21 U.S.C. § 360(k); 21 C.F.R. Part 807
Robotically-assisted surgical devices (RASD) — like Intuitive's da Vinci or Stryker's Mako — are FDA-regulated medical devices. Most clear the market through the 510(k) pathway by showing substantial equivalence to a predicate device. The FDA issued a 2019 safety communication and continues to police off-label robotic mastectomy and AI-software updates under its evolving 'Predetermined Change Control Plan' authority.
-
In effect
OSHA industrial robots
United States · Effective 1971-04-28 · 29 U.S.C. § 654(a)(1); 29 C.F.R. § 1910.212
OSHA does not have a robot-specific standard, but uses its general machine-guarding rule and the General Duty Clause to require employers to protect workers from industrial robots. Its Technical Manual Chapter 4 incorporates the ANSI/RIA R15.06 robot safety standard as the de facto benchmark for guarding, presence-sensing, and lockout/tagout around robotic cells and collaborative robots ('cobots').
-
Blocked / in litigation
xAI v. Harwood (Grok NCII Counter-Suit 2026)
United States · Effective 2026-07-14 · xAI Corp. v. Terry Harwood, N.D. Tex. (Dallas Div.), filed July 14, 2026
xAI Corp. (the company behind the Grok AI chatbot, formerly operating as 'X.AI') filed a civil lawsuit on July 14, 2026 in the Northern District of Texas against Terry Harwood, a South Carolina man. The lawsuit alleges Harwood opened two Grok accounts between December 8, 2025 and February 18, 2026, uploading non-sexual photos of adults and minors and manipulating Grok into generating sexually explicit deepfake images — bypassing the system's safety guardrails. xAI seeks unspecified monetary damages and a permanent ban on Harwood from all xAI products. Harwood was separately arrested on February 26, 2026 on criminal charges of sexual exploitation of a minor. The case is notable as one of the first civil lawsuits filed by an AI company against a user for misusing the AI system to generate harmful content, rather than the more common pattern of a victim suing the AI company. xAI disclosed it suspended 52,222 accounts and filed 73,604 NCMEC reports related to Grok deepfake abuse in 2026, leading to at least 244 arrests.
-
Blocked / in litigation
Florida AG v. OpenAI (AI safety, minors)
United States · Effective 2026-06-01 · State of Florida ex rel. Uthmeier v. OpenAI LLC et al. (Highlands County 10th Jud. Cir., June 1, 2026; removed to S.D. Fla. July 2, 2026)
Florida Attorney General James Uthmeier filed the first-in-nation state-led lawsuit against OpenAI on June 1, 2026, in Highlands County Circuit Court, alleging ChatGPT was deceptively marketed to minors despite known safety risks. The 10-count complaint cites specific harms including the death of 16-year-old Adam Raine, who died by suicide following extensive ChatGPT conversations, and the alleged use of ChatGPT by the accused Florida State University mass shooter. OpenAI LLC and CEO Sam Altman (named personally) removed the case to federal court before Judge Aileen Cannon in Fort Pierce on July 2, 2026. Florida has moved to remand; the jurisdictional battle is ongoing.
-
Blocked / in litigation
NAACP v. xAI (Colossus 2 Air Pollution)
N.D. Miss. · Effective 2026-04-14 · NAACP et al. v. xAI Corp. et al., No. 3:26-cv-00074-MPM-JMV (N.D. Miss., filed April 14, 2026)
The NAACP and local organizations sued xAI and its affiliate MZX Tech in April 2026, alleging 27 natural gas turbines at xAI's Colossus 2 data center in Southaven, Mississippi were operated without required air permits, harming predominantly Black residents near the facility. In June 2026, the Trump DOJ moved to intervene and dismiss the case, arguing the lawsuit would 'hamper America's AI innovation' — marking the first time DOJ used a motion to dismiss a citizen Clean Air Act suit on AI-policy grounds.
-
Proposed / pending
NAIC AI Evaluation Tool Pilot (12 states, 2026)
United States · Effective 2026-03-02 · NAIC Big Data and AI (H) Working Group — AI Systems Evaluation Tool Pilot (launched March 2, 2026)
The National Association of Insurance Commissioners launched a 12-state pilot program in March 2026 to test a new 'AI Systems Evaluation Tool' — a standardized framework giving insurance examiners a structured method to assess how insurance companies govern their AI systems during market conduct and financial examinations. The 12 participating states are California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. The tool requires insurers to complete four exhibits: one quantifying AI usage, one assessing governance risk, one detailing high-risk AI systems, and one documenting AI data practices. The pilot runs through September 2026, with tool updates through October 2026 and formal NAIC adoption expected at the Fall National Meeting in November 2026.
-
In effect
ACA § 1557 (AI in patient care)
United States · Effective 2025-05-01 · 42 U.S.C. § 18116; 45 C.F.R. § 92.210
A 2024 HHS rule says hospitals, insurers, and other covered health entities may not discriminate through clinical algorithms and AI decision-support tools, and must make reasonable efforts to find and fix bias in those tools. The requirement took effect May 1, 2025, but HHS has stayed quiet on enforcement, so its practical protection is uncertain while it stays on the books.
-
In effect
FBI 2024 Elder Fraud Report
United States · Effective 2025-04-29 · FBI IC3 2024 Elder Fraud Report (Apr. 29, 2025)
The FBI's annual Elder Fraud Report — published April 2025 for calendar year 2024 — documented $4.885 billion in losses by Americans 60+, with AI voice cloning, AI-driven romance and pig-butchering scams, and tech-support fraud identified as fastest-growing vectors. The report is the principal federal basis for AI elder-fraud policy and enforcement priorities.
-
In effect
Federal AI Executive Orders
United States · Effective 2025-01-23 · Exec. Order 14179 (Jan. 23, 2025); Exec. Order of Dec. 11, 2025
The current federal posture is deregulatory: EO 14179 (January 2025) revoked the prior AI safety order and directed agencies to remove AI rules seen as barriers to innovation, leading agencies like the EEOC and CFPB to pull AI guidance. A December 11, 2025 executive order directs the DOJ to challenge state AI laws and pushes for a uniform federal framework — but it does not itself preempt state laws, which remain in force absent congressional action or court rulings.
-
In effect
FBI IC3 AI fraud PSA
United States · Effective 2024-12-03 · FBI IC3 PSA I-120324-PSA (Dec. 3, 2024)
The FBI's Internet Crime Complaint Center warned that criminals are using generative AI for phishing, impersonation, romance scams, investment fraud, and synthetic identity creation — and gave concrete defenses, like asking a 'secret word' on suspicious family calls. The PSA underpins FBI investigative priority and informs federal AI-fraud charging decisions.
-
In effect
DHS AI Critical Infra Framework
United States · Effective 2024-11-14 · DHS Framework (Nov. 14, 2024)
DHS released a voluntary framework that lays out the responsibilities of cloud providers, AI developers, AI deployers, critical-infrastructure owners, and civil society for the safe and secure use of AI in U.S. critical infrastructure sectors — including grid, water, financial services, and healthcare.
-
In effect
USDA AI Strategy
United States · Effective 2024-09-30 · USDA AI Strategy (Sept. 30, 2024)
USDA's AI Strategy governs how the department deploys AI across food safety inspection, SNAP eligibility processing, agricultural research, and farm-loan adjudication — with use-case inventory disclosure required by OMB.
-
Repealed / replaced
Battle v. Microsoft
D. Md. · Effective 2024-08-22 · Battle v. Microsoft Corp., No. 1:23-cv-01822 (D. Md.)
Aerospace consultant Jeffery Battle sued Microsoft alleging Bing/Copilot conflated him with a convicted terrorist of the same name. The case was dismissed in 2024 — among the early dismissals signaling that AI hallucination defamation suits face uphill battles on actual malice and statement-of-fact grounds.
-
In effect
SSA AI Disability Adjudication
United States · Effective 2024-07-30 · SSA AI Governance Framework (July 30, 2024)
Social Security Administration governance for AI used to help adjudicate disability claims — including the Insight tool and Quick Disability Determinations. Human adjudicators must review every AI-assisted determination; AI cannot deny benefits without ALJ or examiner review.
-
In effect
NIST GenAI Profile (AI 600-1)
United States · Effective 2024-07-26 · NIST AI 600-1
NIST's voluntary GenAI Profile is the leading federal playbook for managing risks unique to generative AI: hallucinations, harmful content, intellectual property leakage, data poisoning, and CBRN misuse. Federal contractors and many enterprises adopt it as the de facto AI risk-management baseline.
-
In effect
FINRA AI Notice 24-09
United States · Effective 2024-06-27 · FINRA Reg. Notice 24-09 (June 27, 2024)
FINRA reminded broker-dealers that existing rules — supervision, recordkeeping, advertising, and anti-fraud — apply fully to AI tools, including generative AI used for customer communications, surveillance, and trading. Firms misrepresenting AI capabilities or failing to supervise AI outputs face enforcement.
-
In effect
FSMB AI Guidance
United States · Effective 2024-04-26 · FSMB Policy (Apr. 26, 2024)
FSMB adopted a national framework guiding all U.S. state medical boards on what physicians must do when using AI: maintain transparency with patients, ensure AI tools are appropriate to use, supervise AI outputs, and protect patient privacy. States are adopting it as the model framework.
-
In effect
Treasury AI Cyber Report (Fin. Services)
United States · Effective 2024-03-27 · Treasury Report (March 2024)
Treasury released a sector-wide report outlining AI-specific cybersecurity risks facing banks and financial institutions, the gap between large and small firms in AI-fraud defense, and supervisory expectations for AI-driven fraud, deepfakes, and prompt-injection attacks.
-
In effect
NTIA AI Accountability Report
United States · Effective 2024-03-27 · NTIA AI Accountability Report (Mar. 27, 2024)
The Commerce Department's NTIA released the federal government's flagship policy report on AI accountability — concluding that independent AI audits, evaluations, and disclosure mechanisms are essential and recommending federal investment in the AI accountability ecosystem.
-
In effect
CFTC AI trading-scam advisory
United States · Effective 2024-01-25 · CFTC OCEO Customer Advisory (Jan. 25, 2024)
The Commodity Futures Trading Commission warned consumers about AI-related investment scams — fraudsters promising guaranteed returns from AI trading bots, AI-generated celebrity endorsements, and AI-themed pump-and-dump schemes in crypto and forex markets. The advisory laid the groundwork for CFTC enforcement against AI-touted commodity fraud.
-
In effect
CISA AI Roadmap
United States · Effective 2023-11-14 · CISA AI Roadmap (Nov. 14, 2023)
CISA's AI Roadmap outlines how the U.S. cybersecurity agency will use AI to defend networks, secure AI systems against attacks, and protect critical infrastructure from AI-enabled threats — including deepfakes and AI-driven cyberattacks on the 16 critical-infrastructure sectors.
-
In effect
EEOC SEP FY24-28 (AI priority)
United States · Effective 2023-09-21 · 88 Fed. Reg. 65042
EEOC's Strategic Enforcement Plan elevates algorithmic and AI hiring discrimination to one of the agency's top investigation priorities through FY 2028 — even after the agency removed its 2023 AI technical assistance documents in January 2025.
-
In effect
DOJ Civil Rights AI Statement
United States · Effective 2023-04-25 · DOJ-CFPB-EEOC-FTC Joint Statement (Apr. 25, 2023)
DOJ joined three other federal agencies in an interagency statement confirming that existing civil rights laws — Fair Housing Act, ECOA, Title VII, ADA — apply fully to AI and algorithmic systems. AI does not create a 'liability shield' for discrimination.
-
Blocked / in litigation
Young v. NeoCortext (Reface)
C.D. Cal. · Effective 2023-04-03 · Young v. NeoCortext, Inc., No. 2:23-cv-02496 (C.D. Cal.); 9th Cir. Dec. 2024
Reality TV personality Kyland Young sued NeoCortext (developer of the Reface face-swap app) under California's right-of-publicity statute, alleging Reface used his image in its in-app catalog without consent. In 2024 the Ninth Circuit affirmed denial of NeoCortext's anti-SLAPP motion, allowing the case to proceed.
-
In effect
NIST AI RMF (voluntary AI risk framework)
United States · Effective 2023-01-26 · NIST AI 100-1 (AI RMF 1.0); NIST AI 600-1
A voluntary federal framework that helps organizations identify, measure, and manage risks from AI systems — including bias, safety, and security issues. It creates no legal rights for individuals, but it has become the de facto standard referenced by regulators, several state AI laws, and federal contractors.
-
In effect
OSTP AI Bill of Rights Blueprint
United States · Effective 2022-10-04 · OSTP Blueprint (October 2022)
The Blueprint laid out five non-binding principles for protecting Americans from automated systems: safe and effective systems, algorithmic discrimination protections, data privacy, notice and explanation, and human alternatives. It remains the most widely cited federal articulation of AI rights and is referenced by state AI laws.
-
In effect
FTC AI Guidance (2021)
United States · Effective 2021-04-19 · FTC Business Guidance (Apr. 19, 2021)
FTC's foundational AI compliance blog warning that biased algorithms can violate FTC Act Sec. 5, FCRA, and ECOA. Sets the agency's enforcement posture on deceptive and unfair AI practices.
-
In effect
Interagency AI/ML Risk Mgmt (OCC/Fed/FDIC)
United States · Effective 2021-03-31 · 86 Fed. Reg. 16837; SR 11-7; OCC Bulletin 2011-12
Banking regulators issued a joint request for information setting their supervisory expectations for banks using AI and machine learning — covering model risk, fair lending, third-party AI vendors, and consumer-protection compliance. The 2011 model-risk-management guidance (SR 11-7) governs AI underwriting models.
-
Enacted (not yet in effect)
FERC order directing PJM and other grid operators to reform
United States · FERC order directing PJM and other grid operators to reform tariffs on large-load (data center) transmission cost allocation (Docket RM26-4-000)
FERC ordered PJM and other regional grid operators to revise or defend their tariffs within 60 days to prevent existing ratepayers from being unlawfully charged for transmission upgrades required to serve large new loads such as AI data centers.
-
Proposed / pending
Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757)
United States · Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757)
The U.S. House passed H.R. 7757 (267-117), imposing obligations on AI chatbot providers and online platforms to protect minors, including AI disclosure, crisis resources, use-break prompts, and policies against sexual exploitation and age-restricted content.
-
Proposed / pending
FTC Proposed Policy Statement — AI Accuracy (July 2026)
United States · FTC Proposed Policy Statement on Suppression of Accuracy in AI Systems, 91 Fed. Reg. ___ (July 7, 2026) (Docket 2026-13628)
The Federal Trade Commission published a proposed policy statement in the Federal Register on July 7, 2026 warning that AI companies that steer outputs toward undisclosed ideological objectives (rather than user-requested accuracy) may be engaging in deceptive practices under Section 5 of the FTC Act. The statement was issued pursuant to a Trump Executive Order directing the FTC to clarify how Section 5 applies to AI. Notably, the proposed statement also suggests that state laws requiring AI systems to alter outputs — including some state AI bias and accuracy mandates — may conflict with federal consumer protection law, raising preemption concerns. Public comments are due July 31, 2026. The statement is proposed, not final, and does not itself impose any legal obligations.
-
Proposed / pending
FTC CARS Rule (AI auto)
United States · 16 C.F.R. Part 463; 89 Fed. Reg. 590
The FTC rule targets deceptive auto-dealer practices, including AI-powered tools used in financing offers and add-on sales. The rule's compliance date is stayed pending Fifth Circuit litigation, but core deception standards still apply under FTC Act Section 5.
-
Proposed / pending
FTC Commercial Surveillance ANPR
United States · 87 Fed. Reg. 51273
The FTC's advance notice of proposed rulemaking on 'commercial surveillance and data security' asked whether to write rules limiting how companies collect data, train AI models on consumers, and use automated decision-making. The proceeding is technically open but has not advanced to a notice of proposed rulemaking.
-
Proposed / pending
FCC AI robocall disclosure NPRM
United States · FCC 24-84, NPRM, CG Docket 23-362 (Aug. 8, 2024)
The FCC's August 2024 proposed rule would require callers using AI-generated voices or AI-written texts to disclose that fact at the start of the call or in the text, and would let consumers refuse AI calls even when prerecorded consent was given. The proposal is pending as of June 2026 — track its status before relying on it.
-
Proposed / pending
H.R. 9340 Ratepayer Protection Act (proposed)
United States · H.R. 9340, 119th Cong. (2026)
H.R. 9340 would amend section 111(d) of the Public Utility Regulatory Policies Act of 1978 (16 U.S.C. 2621(d)) to add a federal ratemaking standard for 'large-load customers', requiring that rates charged to such a customer be designed to recover from that customer the full incremental cost of any generation, transmission or distribution upgrade necessary to serve its load, including where the customer terminates its contract or ceases purchasing energy. Before making such an upgrade the utility would have to require the customer to provide financial assurances or contributions covering its cost. A 'large-load customer' is defined as a non-residential electric consumer requesting or contracting for electric energy for one or more facilities with an aggregate peak demand of 100 megawatts or more at a single site or campus.
-
Proposed / pending
QUIET Act
United States · H.R.1027, 119th Congress (2025–2026)
Requires any robocall that uses artificial intelligence to emulate a human voice to include a clear disclosure at the start of the message stating that AI is being used. Also doubles the maximum forfeiture penalty and criminal fines under the TCPA for violations involving AI voice or text impersonation. Seniors are not specifically named but are a primary intended beneficiary — AARP surveys show 95% of adults 50+ received a scam or illegal robocall in 2025.
-
Proposed / pending
QUIET Act (Senate)
United States · S.3354, 119th Congress (2025–2026)
Senate companion to H.R.1027; requires AI-generated robocalls to disclose AI use at the start of the call and enhances TCPA penalties for AI voice or text impersonation violations. Directly addresses a primary vector for elder fraud — AI voice robocalls. Bipartisan press materials cited protection of older Americans from scam calls as a key goal.
-
Proposed / pending
Preventing Deep Fake Scams Act (House)
United States · H.R.1734, 119th Congress (2025–2026)
Establishes a congressional Task Force on Artificial Intelligence in the Financial Services Sector to assess how deepfakes and voice-cloning tools are used to commit financial fraud and to report best-practice recommendations to Congress within one year of enactment. Fraudsters stole more than $12.5 billion from consumers in 2024; older adults represent the largest victim group. Seniors are not explicitly named but protection of older adults is a stated motivation in the companion Senate press materials.
-
Proposed / pending
Preventing Deep Fake Scams Act (Senate)
United States · S.2117, 119th Congress (2025–2026)
Senate companion to H.R.1734; establishes the Task Force on Artificial Intelligence in the Financial Services Sector to study AI-enabled financial scams — including deepfakes and voice-cloning grandparent scams — and to produce congressional recommendations within one year. FBI data cited by sponsors shows 201,266 complaints from Americans 60+ in 2025 with $7.748 billion in losses. Seniors are not specifically enumerated in the bill text but are the primary demographic motivating the legislation.
-
Proposed / pending
NO FAKES Act of 2025
United States · S.1367, 119th Congress (2025–2026)
Creates the first federal individual right against unauthorized AI-generated digital replicas of a person's image, likeness, or voice. Provides a right to subpoena online platforms for data about unauthorized deepfakes and establishes a DMCA-style notice-and-takedown procedure. Seniors and others whose voices are cloned without consent for use in grandparent or impersonation scams would have a direct cause of action against the parties responsible.
-
Proposed / pending
AI Scam Prevention Act
United States · S.3495, 119th Congress (2025–2026)
Prohibits using artificial intelligence to impersonate any person — family member, government official, or business — with intent to defraud. Codifies and expands the FTC's existing rule against impersonating government or business officials and updates definitions to include text messages, video conference calls, and AI-generated or prerecorded voice. Sen. Klobuchar's press release explicitly cited grandparent scams where criminals clone a grandchild's voice to defraud elderly relatives as a primary motivation.
-
Proposed / pending
AI Fraud Accountability Act
United States · S.3982, 119th Congress (2025–2026)
Amends the Communications Act of 1934 to create a new criminal offense for using a realistic digital impersonation in interstate or foreign communications with intent to defraud a person of money or things of value. Establishes extraterritorial jurisdiction — critical because many AI scam operations targeting American seniors originate overseas. Empowers the FTC with civil enforcement authority and directs NIST to develop best practices. Explicitly endorsed by AARP and the 60 Plus Association because of the devastating toll on seniors.
-
Proposed / pending
AI Fraud Accountability Act (House)
United States · H.R.7786, 119th Congress (2025–2026)
House companion to S.3982; criminalizes the use of realistic digital impersonation tools in interstate or foreign communications with fraudulent intent. Includes extraterritorial jurisdiction to reach foreign-based AI scam operations that frequently target American seniors. Buchanan's press release explicitly stated that the bill responds to 'a disturbing rise in AI-generated voice clones' used to defraud families including older adults.
-
Proposed / pending
AI Fraud Deterrence Act
United States · H.R.6306, 119th Congress (2025–2026)
Amends federal mail fraud, wire fraud, bank fraud, and money laundering statutes to impose significantly higher maximum penalties when AI tools are used to commit those offenses. Proposed fines range from $1–2 million and maximum prison terms of 20–30 years for AI-assisted fraud. Rep. Lieu's press release specifically cited scammers using AI voice cloning to target seniors as the primary motivation. Seniors are not individually named in the bill text but are the explicit focus of the sponsors' public advocacy.
-
Status unknown
Sky / Scarlett Johansson voice-likeness threat
(threatened — no filed case) · Effective 2024-05-20 · Public legal threat by Scarlett Johansson re: OpenAI 'Sky' voice (May 2024)
Scarlett Johansson publicly threatened legal action against OpenAI in May 2024 after the company released a 'Sky' voice for GPT-4o that closely resembled hers — after she had declined to license her voice. OpenAI withdrew the voice. No lawsuit was filed, but the episode became a touchstone for voice-likeness AI right-of-publicity policy debates and shaped the NO FAKES Act.
-
Expired
SEC PDA Rule (proposed)
United States · SEC Release Nos. 34-97990 / IA-6353 (proposed July 26, 2023); withdrawn via Release No. 33-11377 (June 12, 2025)
This SEC proposal (July 2023) would have required broker-dealers and investment advisers to eliminate or neutralize conflicts of interest from AI/predictive-analytics technologies used in investor interactions. It DID NOT take effect: on June 12, 2025 the SEC formally withdrew it (one of 14 Biden/Gensler-era proposals withdrawn), so no rule is in force — any future rulemaking would have to start over with a new proposal.
-
Expired
Algorithmic Accountability Act (2019, died)
United States · H.R. 2231 / S. 1108, 116th Cong. (2019) — died in committee
Sens. Wyden and Booker and Rep. Clarke introduced the first federal Algorithmic Accountability Act on April 10, 2019. It would have empowered the FTC to require large companies to assess and address bias, discrimination, and privacy risks in 'automated decision systems.' Never received a committee vote — but it set the template for every subsequent federal and state algorithmic-accountability bill.
-
Expired
Algorithmic Accountability Act (2022, died)
United States · S. 3572 / H.R. 6580, 117th Cong. (2022) — died in committee
Sens. Wyden and Booker and Rep. Clarke reintroduced an expanded Algorithmic Accountability Act on Feb. 3, 2022. It would have required impact assessments for 'augmented critical decision processes' across employment, housing, credit, education, and healthcare. Died in committee but became the most-cited federal AI bill of the 117th Congress.
-
Expired
Algorithmic Accountability Act (2023, died)
United States · S. 2892 / H.R. 5628, 118th Cong. (2023) — died in committee
The third iteration of the Algorithmic Accountability Act, reintroduced on Sept. 21, 2023 with refined definitions and FTC rulemaking authority. Like its predecessors it never received committee action — but it remains the leading federal ADS-impact-assessment template.
-
Expired
Algorithmic Justice Act (Markey/Matsui, died)
United States · S. 1896 / H.R. 3611, 117th Cong. (2021) — died in committee
Sen. Markey and Rep. Matsui's May 2021 bill would have banned discriminatory algorithmic processes on online platforms, required plain-language algorithm disclosure to users, and created a cross-agency task force on algorithmic discrimination. Died in committee but became a citation anchor for later FTC trade-rule petitions.
State consumer protection rules (235)
-
In effect
CA CPPA ADMT Regs
CA · Effective 2026-01-01 · 11 Cal. Code Regs. §§ 7200-7232
California's privacy agency finalized binding regulations governing automated decision-making and AI used to make significant decisions about Californians — including hiring, housing, education, healthcare, financial services, and ads to minors. Consumers gain rights to pre-use notice, opt-out, and access to information about how AI made the decision.
-
In effect
CCPA/CPRA + ADMT Regulations
California · Effective 2026-01-01 · Cal. Civ. Code § 1798.100 et seq.; Cal. Code Regs. tit. 11, div. 6
California's main privacy law gives consumers rights to know, delete, correct, and opt out of the sale or sharing of their personal information. New regulations finalized in 2025 add rights around automated decision-making technology (ADMT): businesses using ADMT for significant decisions (jobs, housing, credit, healthcare) must give pre-use notice, let people opt out, and provide access to how decisions were made.
-
In effect
HB 3773 (AI Employment Discrimination)
Illinois · Effective 2026-01-01 · P.A. 103-0804, amending 775 ILCS 5
Illinois employers may not use AI in ways that discriminate against protected classes in recruitment, hiring, promotion, discipline, discharge, or other employment terms, and may not use zip codes as a proxy for protected characteristics. Employers must notify workers and applicants when AI is used in employment decisions.
-
In effect
IL BIPA (2008, first-in-nation biometric law)
IL · Effective 2008-10-03 · 740 ILCS 14/1 et seq. (P.A. 95-994, 2008; amended P.A. 103-0769, 2024)
Signed October 3, 2008, the Illinois Biometric Information Privacy Act (BIPA) was the first state biometric privacy law in the United States — and remains the most powerful. Its private right of action and statutory damages ($1,000 negligent / $5,000 intentional per violation) have driven over $1.5B in class-action settlements, including the $650M Facebook face-tagging settlement (2021) and the $725M TikTok settlement (2021). 2024 amendment (P.A. 103-0769) limited claims to one accrual per person per collection method. Still in effect 2026.
-
Vetoed
Arizona HB 2311 AI chatbot safety for minors — vetoed 2026
Arizona · Ariz. H.B. 2311, 57th Leg., 2d Reg. Sess. (2026) — vetoed June 19, 2026
Arizona HB 2311 would have required AI chatbot operators to disclose to minor users that they are interacting with artificial intelligence, connect minor users displaying crisis signals to mental health resources, and prohibit gamification techniques designed to maximize time-on-platform for minors. The bill also barred sexual content generation when the AI knew or should have known the user was a minor. The Arizona House passed the bill 35-20 and the Senate passed it 16-12. Governor Katie Hobbs vetoed HB 2311 on June 19, 2026, as part of her veto of all three AI bills that reached her desk in the 2026 legislative session.
-
Enacted (not yet in effect)
Illinois Children's Social Media Safety Act — algorithmic recommendations ban for minors
Illinois · Effective 2028-01-01 · Illinois HB5511, Children's Social Media Safety Act (signed July 31, 2026; effective January 1, 2028)
Illinois's Children's Social Media Safety Act, signed by Governor Pritzker on July 31, 2026, bans social media platforms from using algorithmic content recommendations for users they know to be minors — restricting feeds to only content the user searched for or from accounts the user chose to follow. It requires operating system providers to verify user age at account setup and share an age-category signal with platforms. It mandates default privacy settings for minors that limit location sharing, nighttime notifications (banned 10 pm – 7 am), and digital currency features. The Illinois Attorney General may enforce violations with civil penalties up to $50,000 per violation. The law takes effect January 1, 2028.
-
Enacted (not yet in effect)
NJ Fair Pricing and Transparency Act S3952 (2026)
NJ · Effective 2027-07-23 · N.J. S3952 / A3929 (222nd Legislature, 2026) — signed July 23, 2026; effective July 23, 2027
Governor Meredith Sherrill signed New Jersey S3952/A3929, the Fair Pricing and Transparency Act, on July 23, 2026, making New Jersey the third state to ban surveillance-based grocery pricing, following Maryland and Connecticut. The law prohibits retail food stores from setting individualized prices based on a customer's personal data, purchasing history, or tracked attributes. It also imposes a one-year moratorium on electronic shelf labels (ESLs). Effective July 23, 2027. Notably, the law includes a private right of action for injured consumers — the first state surveillance-pricing law to do so.
-
Enacted (not yet in effect)
NJ Forbidding the Algorithmic Inflation of Rent (FAIR) Act
New Jersey · Effective 2027-07-20 · Forbidding the Algorithmic Inflation of Rent (FAIR) Act, N.J. P.L.2026, c.43 (A3497/S451), signed July 20, 2026
New Jersey Governor Sherrrill signed the Forbidding the Algorithmic Inflation of Rent (FAIR) Act on July 20, 2026, making New Jersey the first state to ban landlords from using algorithmic revenue-management software that coordinates rent-setting using nonpublic competitor pricing and occupancy data. The law, effective July 20, 2027, prohibits residential landlords from using or paying for such software and from receiving pricing recommendations derived from competitors' nonpublic data. RealPage and similar tools are directly targeted.
-
Enacted (not yet in effect)
Washington HB 2225 (AI chatbot disclosure, minor protections, crisis protocols)
Washington · Effective 2027-01-01 · Washington HB 2225 (2026), effective January 1, 2027
Washington's AI Companion Chatbot Safety Act (HB 2225), signed March 24, 2026, requires operators of AI companion chatbots to clearly disclose to all users that they are interacting with AI, not a human. The disclosure must be repeated every three hours for adult users and every one hour for minor users. Operators must implement suicide and self-harm crisis protocols for all users, protect minors from manipulative engagement mechanics, and restrict access to adult content. The law includes a private right of action, allowing affected individuals to sue operators. It takes effect January 1, 2027.
-
Enacted (not yet in effect)
Oregon SB 1546 (AI companion chatbot disclosure + private right of action)
Oregon · Effective 2027-01-01 · Or. SB 1546 (2026 Reg. Sess.), effective January 1, 2027
Oregon's AI Companion Chatbot Safety Act (SB 1546), signed March 31, 2026 and effective January 1, 2027, is the first U.S. chatbot law to include a direct private right of action. It regulates operators of 'AI companions' — defined as AI systems designed to simulate a sustained human-like relationship and retain contextual information across interactions. Operators must: clearly and repeatedly disclose that the system is AI, not a human (recurring disclosure every three hours for adults and every hour for minors); implement protocols to detect suicidal ideation or self-harm and direct users to crisis resources; protect minors from manipulative engagement mechanics (variable-ratio reinforcement, unpredictable rewards). Any person harmed by a violation may sue directly for $1,000 per violation, any greater actual damages, injunctive relief, and attorney fees. The law was passed near-unanimously by the Oregon legislature on March 5, 2026.
-
Enacted (not yet in effect)
SC H 4591 Stop HARM from Addictive Social Media Act (2026)
SC · Effective 2027-01-01 · S.C. H 4591 (126th G.A., 2026) — signed May 19, 2026; eff. Jan. 1, 2027
South Carolina H 4591, the Stop HARM from Addictive Social Media Act, prohibits social media platforms from deploying addictive algorithmic design features to users under 18. Covered platforms must disable infinite scroll, autoplay, and similar compulsive-engagement features for minor users without parental consent; must not push notifications to minors during school hours (7 AM–3 PM) or late night (10 PM–6 AM) without parental authorization; and may not use algorithmic recommendation systems that exploit minors' psychological vulnerabilities to drive engagement. Platforms must implement age verification. Signed May 19, 2026; effective January 1, 2027.
-
Enacted (not yet in effect)
CO AI Act (SB 24-205)
CO · Effective 2027-01-01 · Colo. Rev. Stat. §§ 6-1-1701 to 6-1-1707; SB 24-205 (2024)
Colorado was the first state to enact a comprehensive AI law regulating high-risk AI used to make consequential decisions about Coloradans — including credit, insurance, employment, housing, healthcare, and government services. It requires risk management, bias audits, and consumer disclosure; deceptive AI practices are deemed unfair under the Colorado Consumer Protection Act.
-
Enacted (not yet in effect)
Maryland SB 8 (AI/deepfake impersonation)
Maryland · Effective 2026-10-01 · 2026 Md. Laws ch. 445 (SB 8)
This law makes it a crime to intentionally use artificial intelligence or a deepfake representation to impersonate, falsely depict, or claim to represent another person, or to create or distribute false records, with intent to cause harm, to induce someone to hand over personal identifying information, or to obtain a benefit, credit, good, service, or other thing of value. 'Deepfake representation' means synthetic media indistinguishable from an actual, identifiable human being, and a victim may bring a civil action.
-
Enacted (not yet in effect)
Missouri AI Therapy Chatbot Ban (SB 1019)
Missouri · Effective 2026-08-28 · Mo. SB 1019 (2026 Reg. Sess.); MMPA enforcement; effective Aug 28, 2026
Missouri's 2026 health-care law bans companies and individuals from advertising or claiming that an AI chatbot can act as a mental-health professional or provide therapy services. Marketing an AI 'therapist' is treated as an unlawful business practice the state Attorney General can pursue, with fines of $10,000 for a first violation and $20,000 for each later violation.
-
In effect
Maine mental-health AI limits (2026)
Maine · Effective 2026-07-29 · Maine LD 2082 / HP 1397 (P.L. 2026, Ch. 687, 132nd Leg.); signed April 13, 2026; eff. July 29, 2026
Maine enacted LD 2082 (signed April 13, 2026 by Governor Janet Mills; effective July 29, 2026) limiting how licensed mental health professionals can use AI: only for administrative and limited supplementary tasks. AI may not make therapeutic communications, treatment decisions, or independently interact with patients. Professionals must get patient consent before using ambient-listening or other AI-powered recording tools.
-
In effect
AZ HB 2175 (AI Insurance Denial — Physician Review)
Arizona · Effective 2026-07-01 · Ariz. HB 2175 (57th Leg., 1st R.S. 2025), signed May 12, 2025, eff. July 1, 2026
Arizona HB 2175 requires health insurers and managed-care organizations to have a licensed physician or medical director individually review each case before denying a health insurance claim or prior-authorization request based on medical necessity or experimental status. Insurers may not rely solely on AI algorithms, automated decision-support tools, or algorithmic recommendations to deny coverage. The law directly targets automated prior-authorization systems that issue denials without physician involvement. Signed May 12, 2025, effective July 1, 2026. Arizona is among the first states to specifically prohibit AI-only health insurance denials by statute.
-
Blocked / in litigation
Ostergaard v. Microsoft — data center noise class action (2026)
Wisconsin · Effective 2026-07-01 · Ostergaard v. Microsoft Corp., No. 2:26-cv-01169-JPS (E.D. Wis. filed July 1, 2026)
Three homeowners — Garret Ostergaard, David Wade and Joy Wade — filed a putative class action against Microsoft Corporation on 2026-07-01 in the U.S. District Court for the Eastern District of Wisconsin over noise from Microsoft's 'Fairwater' AI data center on Braun Road in the Village of Mount Pleasant. The complaint alleges the facility, a multi-building campus of roughly 1.2 million square feet requiring hundreds of megawatts, emits unreasonable and excessive noise onto surrounding residential properties through its cooling systems and backup generators, causing loss of use and enjoyment and diminished property value. The pleaded counts are Count I private nuisance — substantial and unreasonable interference alleged to be intentional, knowing, reckless and/or negligent, recurring, ongoing and abatable with ordinary care — and Count II negligence, for negligently constructing, maintaining and operating the facility including inadequate soundproofing.
-
In effect
RI Therapy Chatbot Ban (2026)
Rhode Island · Effective 2026-06-22 · Rhode Island H 7349 / S 2197 (2026), signed June 22, 2026
Rhode Island Governor Dan McKee signed H 7349 / S 2197 on June 22, 2026, prohibiting any person or business from providing therapy or psychotherapy services using artificial intelligence. Only licensed mental health professionals may conduct such sessions. The law targets AI companion chatbots and virtual therapy products that may lead users to believe they are receiving licensed mental health care from a human professional.
-
In effect
RI AI Companion Self-Harm Safety (2026)
Rhode Island · Effective 2026-06-22 · Rhode Island S 2195 / H 7350 (2026), signed June 22, 2026
Rhode Island Governor Dan McKee signed S 2195 / H 7350 on June 22, 2026, requiring operators of AI companion chatbots to implement protocols for identifying and responding to suicidal ideation. Chatbot operators must provide users experiencing suicidal ideation with crisis resources and may not discourage users from seeking professional help. Civil penalties reach $15,000 per day per violation, with proceeds directed to Rhode Island suicide prevention programs.
-
In effect
TX TDI Bulletin B-0003-26 (AI in insurance)
Texas · Effective 2026-06-12 · Texas Department of Insurance, Commissioner's Bulletin B-0003-26 (June 12, 2026)
The Texas Department of Insurance issued Commissioner's Bulletin B-0003-26 on June 12, 2026, telling insurers that decisions made with artificial intelligence must comply with Texas insurance law: AI-driven decisions may not be inaccurate, arbitrary, capricious, or unfairly discriminatory. Insurers must have a human review and approve consequential AI decisions before they take effect, maintain governance, risk-management, and audit programs for their AI systems, and keep documentation they can produce to TDI on request. TDI will police compliance through examinations and complaint monitoring.
-
Blocked / in litigation
PA v. Character.AI (Fake Psychiatrist Chatbot)
Pennsylvania · Effective 2026-05-01 · Commonwealth v. Character Technologies, Inc. (Pa. Commonwealth Ct., filed May 1, 2026)
Pennsylvania Attorney General Josh Shapiro filed suit in Commonwealth Court on May 1, 2026, alleging that Character.AI's companion chatbot 'Emilie' impersonated a licensed Pennsylvania psychiatrist and provided ongoing psychiatric advice and treatment to users without a license. The Shapiro administration seeks a preliminary injunction requiring Character.AI to clearly disclose that its chatbots are not licensed mental health professionals and cannot provide medical treatment.
-
In effect
SC H 3431 Age-Appropriate Design Code Act (2026)
SC · Effective 2026-03-01 · S.C. H 3431 (126th G.A., 2026) — signed Feb. 5, 2026; eff. March 1, 2026
South Carolina H 3431, the Age-Appropriate Design Code Act, requires online platforms and services likely to be accessed by children under 18 to prioritize children's best interests. Covered companies must conduct data protection impact assessments before launching features accessible to minors, set privacy controls to their highest protective level by default for child users, minimize data collection, prohibit profiling children for commercial purposes without verifiable parental consent, and disclose how algorithms affect what content children see. Signed by Governor McMaster February 5, 2026; operational March 1, 2026.
-
In effect
California AB 489 (AI healthcare chatbot misrepresentation ban)
California · Effective 2026-01-01 · Cal. AB 489 (2025-2026 Reg. Sess.), effective January 1, 2026
California AB 489, signed October 11, 2025 and in effect since January 1, 2026, prohibits AI systems from using post-nominal letters (M.D., R.N., etc.), icons, phrases, or other design elements that imply a user is receiving care from a licensed health care professional unless actual licensed professional oversight exists. It also bars marketing language suggesting clinical expertise — such as 'doctor-level,' 'clinician-guided,' or 'expert-backed' — unless the product is genuinely supported by licensed professionals. The law expands California professional licensing boards' authority to investigate and enforce violations, with each misleading representation treated as a separate offense.
-
Blocked / in litigation
X.AI v. Bonta (AB 2013 training-data disclosure)
California · Effective 2025-12-29 · X.AI LLC v. Bonta, No. 2:25-cv-12295 (C.D. Cal., filed Dec. 29, 2025), appeal pending, No. 26-1591 (9th Cir.); oral argument July 16, 2026
X.AI LLC (Elon Musk's AI company) sued California Attorney General Rob Bonta to strike down AB 2013, California's law requiring developers of generative AI systems to publicly disclose documentation about the data used to train them. The suit was filed December 29, 2025 in the Central District of California, arguing the disclosure mandate violates the First, Fifth, and Fourteenth Amendments. Judge Bernal denied X.AI's request for a preliminary injunction on March 4, 2026, and X.AI appealed to the Ninth Circuit, where the case is pending. AB 2013 took effect January 1, 2026 and remains enforceable while the appeal proceeds. The Attorney General defends the law as a regulation of commercial speech.
-
In effect
New York S7882 (felony to use algorithms to coordinate residential rents)
New York · Effective 2025-12-15 · N.Y. Gen. Bus. Law 340-b (S7882, 2025)
This law makes it a crime to help residential landlords coordinate the rents they charge instead of competing with one another, including by operating or licensing software, a data-analytics service, or an algorithmic tool that performs a rent-setting coordination function across two or more landlords. The conduct must be done knowingly or recklessly. Violations are a Class E felony, with fines up to $1 million for a corporation and up to $100,000 or up to four years in prison for an individual.
-
Blocked / in litigation
Raine v. OpenAI
CA · Effective 2025-08-26 · Raine v. OpenAI, Inc., No. CGC-25-628528 (Cal. Super. Ct., S.F. Cty.)
The parents of 16-year-old Adam Raine sued OpenAI and CEO Sam Altman in August 2025, alleging ChatGPT provided their son with detailed information on suicide methods and encouraged him in conversations preceding his death. The first wrongful-death suit against a general-purpose LLM developer.
-
In effect
IL WOPR (AI therapy ban)
IL · Effective 2025-08-01 · P.A. 104-0054; 225 ILCS 8/
Illinois banned AI-only therapy and made it unlawful for AI products to claim or imply they can provide mental-health treatment without a licensed clinician supervising. Aimed at consumer-protection harms from companion/therapy chatbots that misrepresent clinical credentials.
-
In effect
NV SB 199 (AI mental-health misrepresentation)
NV · Effective 2025-07-01 · 2025 Nev. Stat. Ch. 283 (AB 406); amends NRS Chs. 391, 433, 629
Nevada made it a deceptive trade practice for AI chatbots and companion apps to falsely claim — or imply — that they are licensed mental-health professionals. Aimed squarely at the growing class of GenAI 'therapy' apps that mislead vulnerable users about clinical credentials.
-
In effect
CPPA Honda ADMT settlement
CA · Effective 2025-03-12 · CPPA, In re American Honda Motor Co. (Mar. 12, 2025)
California's privacy agency fined American Honda $632,500 — its first public enforcement action — for making consumers go through hoops to exercise opt-out and access rights, including against automated decision-making and data-broker sharing. The agency signaled that ADMT (automated decision-making technology) compliance is now a top enforcement priority for AI-driven consumer profiling.
-
In effect
CA SB 1120 (AI prior auth)
CA · Effective 2025-01-01 · Cal. Stats. 2024 Ch. 879; Cal. Health & Safety Code § 1367.01
California prohibits health insurers from using AI or algorithms to deny, delay, or modify medical care — only a qualified physician can make a coverage denial. The law applies to all California-regulated health plans, including commercial, Medi-Cal managed care, and Knox-Keene plans.
-
In effect
IL Digital Voice/Likeness Act
IL · Effective 2025-01-01 · 765 ILCS 1075/; P.A. 103-1014
Illinois created a private right of action against anyone who distributes an unauthorized AI 'digital replica' of a person's voice or likeness, with damages up to $150,000 plus attorneys' fees. Aimed at AI voice-clone fraud, fake celebrity endorsements, and unauthorized digital replicas of performers.
-
In effect
CA AB 1008 (CCPA + AI)
CA · Effective 2025-01-01 · Cal. Civ. Code § 1798.140; AB 1008 (Stats. 2024, ch. 853)
California clarified that personal information remains protected by the CCPA even when it is embedded in or generated by AI systems — including model weights and AI-generated synthetic content about a person. Closes a loophole AI developers had used to argue training data and model outputs fell outside privacy law.
-
In effect
OR PUC Data Center Rate Class
OR · Effective 2024-12-04 · Or. PUC Order No. 24-447
Oregon's Public Utility Commission established a separate large-load rate class — covering data centers, crypto, and AI compute customers — to protect residential customers from cost-shifting and require minimum-take obligations. PacifiCorp and Portland General Electric must apply the new tariffs to incoming AI data centers.
-
In effect
VA SCC Data Center Rate Case
VA · Effective 2024-11-13 · Va. SCC Case No. PUR-2024-00144
Virginia's State Corporation Commission opened a formal investigation into how data center load growth — driven by AI compute demand — should be allocated across electricity rate classes, to keep residential customers from subsidizing AI data centers. Includes minimum-billing demands and special tariffs.
-
In effect
NY AI digital replica law
NY · Effective 2024-08-13 · N.Y. Civil Rights Law §§ 50-f, 50-g; Ch. 219 and 220 of 2024
New York governor signed laws making vague AI digital-replica clauses in personal-services contracts unenforceable and reinforcing the state's right-of-publicity protections for AI-generated voice and likeness fraud. Builds on NY's existing Civil Rights Law §§ 50-f and 50-g.
-
In effect
NYDFS CL 7 (2024) — Insurance AI Anti-Discrimination
New York · Effective 2024-07-11 · NYDFS Insurance Circular Letter No. 7 (2024) (July 11, 2024)
New York's Department of Financial Services issued Insurance Circular Letter No. 7 on July 11, 2024, establishing the most substantive state insurance AI rule in the country. Going beyond the NAIC Model Bulletin adopted by 24+ states, NYDFS CL No. 7 requires insurers to conduct a comprehensive 'proxy assessment' before using any AI system (AIS) or external consumer data source (ECDIS) in underwriting or pricing — and prohibits any such use unless the insurer can demonstrate the system does not produce unfair or unlawful discrimination against protected classes. When an AI-influenced adverse underwriting decision is made, the insurer must provide written notice within 15 days of the decision. Governance, documentation, and DFS market-conduct examination requirements apply immediately.
-
In effect
FL HB 919 AI political/commercial disclosure
FL · Effective 2024-07-01 · Ch. 2024-126, Laws of Fla.; Fla. Stat. § 106.143
Florida requires any political ad using AI-generated content to carry a clear disclaimer; failing to disclose AI use in a political or paid ad — or using AI to materially deceive — is a first-degree misdemeanor. Enforcement is via the Florida Elections Commission and the Department of State.
-
In effect
ELVIS Act
Tennessee · Effective 2024-07-01 · Tenn. Code Ann. §§ 47-25-1101 to -1108 (ELVIS Act, 2024)
The first US law protecting voices from AI cloning: Tennessee added 'voice' to its right-of-publicity law, so using AI to mimic someone's voice or likeness without permission is both a civil violation and a crime. It also allows lawsuits against those who distribute tools whose primary purpose is producing unauthorized voice or likeness replicas.
-
In effect
UT AI Policy Act (SB 149)
UT · Effective 2024-05-01 · Utah Code §§ 13-2-12, 13-72-101 et seq.; SB 149 (2024)
Utah was the first state to require regulated professionals (e.g., doctors, lawyers, accountants) to clearly disclose when consumers are interacting with generative AI, and to make companies liable under existing consumer-protection law for any deception their GenAI commits. It also created the Office of AI Policy and a regulatory sandbox.
-
In effect
NY S5959-D (2020, digital replicas + deepfake porn)
NY · Effective 2021-05-29 · Ch. 304 of 2020 (S5959-D); N.Y. Civ. Rights Law §§ 50-f, 52-c
Signed by Governor Cuomo on November 30, 2020, NY S5959-D was the first state law to (1) extend right of publicity to digital replicas of deceased personalities for 40 years, and (2) create a private right of action against unlawful publication of sexually explicit deepfakes. Landmark precedent — direct ancestor of CA AB 1836 (2024) and NY's 2023-2025 digital-replica laws.
-
In effect
VA HB 2678 (2019, first deepfake-NCII criminal law)
VA · Effective 2019-07-01 · Va. Code § 18.2-386.2 (as amended by HB 2678, 2019 Reg. Sess.)
Virginia HB 2678 (2019) was the first U.S. state law to criminalize AI-generated nonconsensual intimate imagery (deepfake porn). It amended Va. Code § 18.2-386.2 (revenge-porn statute) to cover 'falsely created videographic or still image' depictions. Class 1 misdemeanor. Still in effect 2026 and remains the foundational state deepfake-NCII statute.
-
In effect
MI UIA MIDAS Reform Rules
MI · Effective 2017-12-13 · MCL § 421.62a; 2017 Mich. Pub. Acts 224-228
After Michigan's MIDAS automated fraud-detection system wrongly accused tens of thousands of unemployment claimants of fraud and seized their tax refunds, Michigan adopted statutory and regulatory reforms requiring human review before fraud determinations, restitution for wrongful determinations, and prohibition on fully automated fraud findings.
-
In effect
VA PDD Act (2017 — first)
Virginia · Effective 2017-07-01 · Va. Code §§ 46.2-100, 46.2-908.1:1
Virginia was the first U.S. state to legalize sidewalk delivery robots. PDDs may operate on sidewalks and crosswalks (10 mph cap, 50 lb cargo limit), must carry $100,000 liability insurance and a visible operator ID, and localities may further regulate them. Starship Technologies' deployment at George Mason in 2019 traces back to this law.
-
In effect
UT drone-wildfire law
Utah · Effective 2017-05-09 · Utah Code §§ 65A-3-2.5, 76-6-2410
Utah responded to repeated incidents of hobby drones grounding aerial firefighting by criminalizing drone operation that interferes with manned aircraft fighting wildfires, conducting search-and-rescue, or supporting law enforcement, and authorizing public-safety agencies to disable or neutralize an intruding drone.
-
In effect
TX HB 912 (2013 drone privacy)
Texas · Effective 2013-09-01 · Tex. Gov't Code Ch. 423
One of the broadest state drone-privacy laws: it is illegal in Texas to use a drone to capture images of a person or private real property without consent, subject to 19 enumerated exceptions (newsgathering, mapping, etc.). Texas's drone-privacy chapter was partially struck down in NPPA v. McCraw (2022) on First Amendment grounds, but most provisions remain in force.
-
In effect
OR weaponized-drone ban
Oregon · Effective 2013-07-29 · Or. Rev. Stat. §§ 837.300–837.380
Oregon prohibits anyone from operating a weaponized drone, requires law-enforcement drones to be authorized for specific missions, and provides a civil action for property owners whose airspace is repeatedly invaded by drones flying below 400 feet.
-
In effect
FL drone surveillance act
Florida · Effective 2013-07-01 · Fla. Stat. §§ 934.50, 330.41
Florida bars law enforcement from using drones for surveillance without a warrant or specific exception, and (after SB 92/2015 and SB 44/2021 amendments) prohibits anyone from using a drone to capture images of private property or people on private property in violation of reasonable expectations of privacy. SB 44 (2021) also tightened state preemption over local drone ordinances.
-
Enacted (not yet in effect)
Vermont Data Broker Law (H.211)
Vermont · Vt. H.211 (2025-2026 biennium); signed June 16, 2026
Vermont enacted a law tightening rules on data brokers — companies that buy and sell people's personal information, the same data that feeds profiling and AI systems. Signed by Gov. Phil Scott on June 16, 2026, it strengthens Vermont's existing data-broker regulation and personal-information protections.
-
Enacted (not yet in effect)
Delaware HB 191 (AI clinician licensure ban)
Delaware · Del. HB 191 (2026), signed April 23, 2026
Delaware's HB 191, signed April 23, 2026, prohibits any non-human entity — including an AI-powered agent — from being licensed or certified to practice as a professional nurse, advanced practice registered nurse, practical nurse, physician, or physician assistant. It also bars non-human entities from using protected professional titles or abbreviations tied to those professions.
-
Enacted (not yet in effect)
Hawaii AI Companion Safety Act (Act 248)
Hawaii · HI SB 3001 CD1 (2026)
Hawaii enacted a law (Act 248, signed July 14, 2026) requiring AI companion chatbot operators to clearly disclose users are talking to AI, implement self-harm and suicidal-ideation protocols, protect minors from manipulative engagement techniques and sexually explicit content, provide parental tools, and file annual reports with the state Behavioral Health Administration.
-
Enacted (not yet in effect)
Idaho Conversational AI Safety Act (chatbot disclosure + crisis protocol)
Idaho · Effective 2027-07-01 · Idaho SB 1297 (2026), ch. 249
Idaho's Conversational AI Safety Act requires operators of conversational AI services to clearly disclose that a user is interacting with AI whenever a reasonable person could be misled into thinking it is human. Operators must adopt a protocol to respond to users who express suicidal ideation, including making reasonable efforts to refer them to crisis resources, and may not claim to provide professional mental or behavioral health care. There are added protections for minor users, including persistent AI disclosures and parental controls for younger children.
-
Enacted (not yet in effect)
Iowa SF 2417 (Conversational AI Safety Act)
Iowa · Effective 2027-07-01 · Iowa S.F. 2417, 91st Gen. Assemb. (2026), applies July 1, 2027
Iowa requires operators of conversational AI services to clearly disclose that a user is interacting with artificial intelligence — through a persistent disclaimer or a notice repeated at least every three hours of continuous use — whenever a reasonable person might otherwise believe they are talking to a human. Operators must adopt protocols to respond to user messages about suicidal ideation or self-harm, including referring the user to crisis resources, and may not represent that the service provides professional psychological or behavioral health care, with extra safeguards for minors.
-
Enacted (not yet in effect)
Nebraska LB 525 (AI chatbot disclosure & crisis protocol)
Nebraska · Effective 2027-07-01 · Neb. Laws 2026, LB 525, Secs. 12-18 (Conversational Artificial Intelligence Safety Act)
Nebraska's Conversational Artificial Intelligence Safety Act regulates publicly available AI chatbots that simulate human conversation. When a reasonable person would be misled into thinking they are talking to a human, the operator must clearly disclose that they are interacting with AI, and minors must always be told they are interacting with AI. Operators must adopt a protocol for responding to messages about suicidal thoughts or self-harm by referring users to crisis services, and must not program the service to claim it provides professional mental or behavioral health care.
-
Enacted (not yet in effect)
SB 540 (GA Chatbot Safety)
Georgia · Effective 2027-07-01 · Ga. SB 540 (2025-2026 Reg. Sess.), signed May 15, 2026; effective July 1, 2027
Georgia — the first Republican-led state to do so — enacted a chatbot safety law. Operators must tell users they're talking to AI, verify ages, give parents controls, and follow crisis protocols (like referring to the 988 lifeline) when users express suicidal thoughts. Chatbots talking to minors can't claim to be sentient, produce sexual content, simulate romance, encourage secrets from adults, or fake distress when a child ends the chat. No carve-out for chatbots inside big platforms. Effective July 1, 2027.
-
Enacted (not yet in effect)
Utah SB 298 (bars AI/algorithmic transaction denials by protected traits)
Utah · Effective 2027-05-05 · Utah Code 70A-9a-902, 70A-9a-903 (S.B. 298, 2026)
Utah bars issuers of 'programmable money' from blocking or failing transactions based on a person's protected traits and lawful conduct — including political opinions or speech, religious beliefs, sex, skin color, ethnicity, sexual orientation, medical history, location, purchase or browsing history, residence, business sector, or any social-credit-style score. The prohibition explicitly reaches denials carried out through automation, computer code, algorithms, or AI. A harmed person can sue for statutory and declaratory relief plus actual and punitive damages, and a court can revoke the issuer's authorization to do business in Utah.
-
Enacted (not yet in effect)
HB 1170 (WA AI Content Disclosure)
Washington · Effective 2027-02-01 · Wash. E2SHB 1170 (2026); Ch. 167, 2026 Laws
Large AI image, video, and audio generators must embed hard-to-remove provenance data — watermarks or tamper-resistant metadata — in every piece of synthetic content they create. This lets journalists, courts, and the public identify AI-generated media. Applies to services with over 1 million monthly users. Enforced by the Washington Attorney General under the Consumer Protection Act. Effective February 1, 2027.
-
Enacted (not yet in effect)
CO ADMT Act (SB 26-189, 2026)
Colorado · Effective 2027-01-01 · Colo. SB 26-189 (2026), signed May 14, 2026, eff. January 1, 2027
Colorado Governor Jared Polis signed SB 26-189 on May 14, 2026, repealing and replacing the original Colorado AI Act (SB 24-205) before it could take effect. The replacement law creates a disclosure-focused framework for 'Automated Decision-Making Technology' (ADMT) — a narrower category than the prior law's 'high-risk AI' — applicable to consequential decisions in employment, housing, healthcare, credit, education, insurance, and government services. The original Colorado AI Act had been blocked by a federal court on constitutional grounds days before the replacement was passed. The new ADMT Act takes effect January 1, 2027.
-
Enacted (not yet in effect)
Wisconsin 452.136(1m) (real estate ads must disclose AI-altered property images)
Wisconsin · Effective 2027-01-01 · Wis. Stat. 452.136(1m); 2025 Wis. Act 69
Wisconsin will require licensed real estate professionals to disclose in their advertising whenever an ad has been altered or modified using technology, including AI, to add, remove, or change elements of a property in a way that creates a false or misleading impression. The rule targets AI-edited listing photos that could mislead buyers or renters. It takes effect January 1, 2027.
-
Enacted (not yet in effect)
SB 26-189 (Colorado ADMT Law)
Colorado · Effective 2027-01-01 · SB 26-189 (Colo. 2026)
Colorado's replacement AI law focuses on transparency rather than broad anti-discrimination duties. Starting January 1, 2027, companies using automated decision-making technology to materially influence consequential decisions (employment, housing, lending, insurance, healthcare) must notify consumers before use and provide post-decision disclosures; developers must give deployers technical documentation.
-
Enacted (not yet in effect)
RAISE Act
New York · Effective 2027-01-01 · RAISE Act, S6953B/A6453B (N.Y. 2025), as amended 2026
New York's frontier AI safety law requires the largest AI developers to publish safety protocols and report serious safety incidents to the state within 72 hours. It creates a new AI oversight office and carries penalties up to $3 million for repeat violations, starting January 1, 2027.
-
Enacted (not yet in effect)
SB 1546 (OR Chatbot Safety)
Oregon · Effective 2027-01-01 · Or. SB 1546 (2026), sponsored by Sen. Lisa Reynolds
Oregon's chatbot safety law — the first major chatbot measure passed in 2026 — requires AI chatbot operators to tell users they're talking to AI, prevent outputs that could cause suicidal thoughts, and refer users expressing suicidal ideation to mental-health resources. Kids get extra protections: hourly AI reminders and break reminders, no sexual content, no addictive reward loops, and no emotional manipulation when a child tries to log off. Users harmed by violations can sue. Effective January 1, 2027.
-
Enacted (not yet in effect)
HB 2225 (WA Chatbot Safety)
Washington · Effective 2027-01-01 · Wash. HB 2225, Ch. 168, 2026 Laws; RCW 19.86.093
Washington requires AI companion chatbots to clearly tell users they are talking to an AI, not a person. Operators must have crisis protocols — connecting distressed users to the 988 Suicide and Crisis Lifeline — and additional safeguards for minors. If a company violates the law, consumers can sue under Washington's Consumer Protection Act and recover actual damages, an injunction, and attorney's fees. Effective January 1, 2027.
-
Enacted (not yet in effect)
Maryland Predatory Pricing Act (surveillance pricing)
Maryland · Effective 2026-10-01 · 2026 Md. Laws ch. 154 (HB 895)
This law bars food retailers and third-party delivery service providers from using a consumer's personal data or dynamic (surveillance) pricing to set a higher price for tax-exempt food for a specific consumer. It also prohibits using protected-class data to offer, advertise, or sell goods in a way that withholds an accommodation or advantage from the consumer the data pertains to. Violations are treated as unfair, abusive, or deceptive trade practices under the Maryland Consumer Protection Act.
-
Enacted (not yet in effect)
CT SB 5 (2026 AI Act)
Connecticut · Effective 2026-10-01 · Conn. Public Act 26-15 (SB 5, 2026)
After years of failed attempts, Connecticut enacted a comprehensive AI law in 2026. It requires employers to disclose AI used in employment decisions, mandates disclosure when layoffs relate to AI, imposes some of the nation's strictest AI companion-chatbot rules (especially for children), and codifies that automated decision-making is no defense to discrimination claims. Most provisions start October 1, 2026.
-
In effect
SB 942 (AI Transparency Act)
California · Effective 2026-08-02 · Cal. Bus. & Prof. Code § 22757 et seq. (SB 942, as amended by AB 853)
Large generative AI providers (over 1 million monthly users) must offer a free AI-detection tool and embed disclosures in AI-generated images, video, and audio, including hidden watermark-style disclosures. A 2025 amendment delayed the start to August 2, 2026 and extended duties to large online platforms and capture-device makers (2027).
-
In effect
Maine AI-in-Therapy Law (licensed pros only)
Maine · Effective 2026-07-28 · P.L. 2026, ch. 687 (L.D. 2082 / H.P. 1397); 10 M.R.S. Sec. 1500-EE
Maine bars anyone from providing, advertising, or offering therapy or psychotherapy to the public — including through internet-based AI — unless the services are delivered by a licensed professional. Licensed professionals may use AI only for administrative or supplementary support, and only if they retain full responsibility for its outputs; using AI for supplementary support requires written client notice and consent. AI may not make independent therapeutic decisions, engage in therapeutic communication with clients, or generate treatment plans without the licensee's review and approval.
-
In effect
TN HB 1847 data center ratepayer protection (2026)
TN · Effective 2026-07-01 · Tenn. HB 1847/SB 2128 (114th G.A., 2026) — signed May 7, 2026; eff. July 1, 2026
Tennessee HB 1847/SB 2128, signed May 7, 2026 and effective July 1, 2026, requires data centers drawing 50 megawatts or more of electricity to pay their proportionate share of transmission and distribution infrastructure costs, rather than spreading those costs across all utility ratepayers. The law prevents large hyperscale data centers from being cross-subsidized by ordinary residential and small commercial customers.
-
In effect
VA Data Center Cost-Allocation Law
Virginia · Effective 2026-07-01 · Va. SB 253 (2026) (Sen. Lucas); companion Va. HB 1393 (2026); related Va. HB 507 (2026, generator air permits). Signed with gubernatorial amendments, May 2026; effective July 1, 2026.
Virginia's 2026 data-center cost-allocation law (SB 253, by Sen. L. Louise Lucas, with companion HB 1393). As amended by Gov. Spanberger and signed in May 2026, it lets the State Corporation Commission (SCC) shift certain electricity costs — PJM capacity-auction purchases and the financing of distribution lines and substations that mainly serve data centers — onto data centers and other very large (25 MW+) customers in their rate class, instead of spreading them across residential bills. The governor's amendments made the cost-shift SCC-discretionary rather than automatic, so the real-world savings depend on future SCC rate cases. The bill also extends Dominion and Appalachian Power low-income weatherization programs.
-
In effect
Mississippi HB 1723 (defines AI)
Mississippi · Effective 2026-07-01 · Miss. HB 1723, 2026 Regular Session
Mississippi adopted a single, uniform definition of 'artificial intelligence' to be used across state law. AI is defined as a machine-based system that, for a set of human-defined objectives, can make predictions, recommendations, or decisions that influence real or virtual environments. The measure is definitional and does not itself impose obligations or penalties.
-
In effect
Tennessee SB 1580 (AI can't claim to be a mental health professional)
Tennessee · Effective 2026-07-01 · 2026 Tenn. Pub. Ch. 647 (SB 1580); enforced under Tenn. Code Ann. 47-18-101 et seq. (TCPA)
Tennessee makes it unlawful for anyone who develops or deploys an artificial intelligence system to advertise or represent to the public that the system is, or can act as, a qualified mental health professional. Violations are treated as unfair or deceptive acts under the Tennessee Consumer Protection Act. The law authorizes a civil penalty of up to $5,000 per violation, along with injunctive relief and damages, and includes a private right of action for affected individuals.
-
In effect
Wyo. Stat. 1-1-143 (AI developers shielded from civil liability for others' misuse)
Wyoming · Effective 2026-07-01 · Wyo. Stat. Ann. 1-1-143; 2026 Wyo. Sess. Laws (HB0102 / HEA 32)
This Wyoming provision shields the developer of an AI system from civil damages when a different person uses that system to commit illegal acts or cause harm. The protection does not apply if the system was built knowing or intending that its primary purpose would be illegal or illicit activity.
-
In effect
Wyo. Stat. 6-1-206 (using AI to commit a crime is no defense)
Wyoming · Effective 2026-07-01 · Wyo. Stat. Ann. 6-1-206; 2026 Wyo. Sess. Laws (HB0102 / HEA 32)
This Wyoming rule confirms that the criminal code applies to conduct carried out with the help of an AI system, and makes clear that using an AI system to commit a crime is not a defense to a criminal charge. A defendant cannot escape liability by arguing the AI, rather than the person, did the act.
-
In effect
Wyo. Stat. 6-4-701 (felony to build/distribute AI systems meant to promote self-harm)
Wyoming · Effective 2026-07-01 · Wyo. Stat. Ann. 6-4-701; 2026 Wyo. Sess. Laws (HB0102 / HEA 32)
This new Wyoming crime targets AI systems built to encourage people to hurt themselves. It is a felony to knowingly develop or distribute an AI system specifically designed to promote self-harm, when done with intent or knowledge that others will use it that way. 'Self-harm' covers self-directed behavior causing or risking bodily injury, serious bodily injury, or death. Prompt-only systems, bona fide education, law enforcement, licensed health care, and platform hosting are exempted.
-
In effect
SB 484 (FL Data Center Costs)
Florida · Effective 2026-07-01 · Fla. Ch. 2026-65 (SB 484, 2026)
One of the first state laws regulating AI data centers' utility impact: large data centers must bear their own electricity infrastructure costs rather than shifting them to households and small businesses, local governments keep their authority to reject data center projects, and Florida's water resources get new protections. Takes effect July 1, 2026.
-
In effect
SSB 5886 (WA Digital Likeness Rights)
Washington · Effective 2026-06-11 · Wash. SSB 5886, Ch. 69, 2026 Laws; RCW ch. 63.60 (amending personality rights statute)
Washington updated its personality-rights law so that AI-generated audio or video that realistically mimics someone's face or voice without consent — called a 'forged digital likeness' — is now a civil violation. Victims can seek court injunctions to stop the misuse, and the civil penalty for each infringement is $3,000 plus any actual damages they can prove. The law became effective June 11, 2026.
-
In effect
Order 26-154 Approving PGE Large-Load Tariff Framework for D
Oregon Public Utility Commission (Portland General Electric) · Effective 2026-05-07 · Order 26-154 Approving PGE Large-Load Tariff Framework for Data Centers
The Oregon PUC approved a large-load tariff for data centers exceeding 20 MW that requires customers to fund 100% of distribution upgrades, sign 10-to-30-year contracts, pay minimum demand charges at 90% of contracted capacity, and adds a 1 cent/kWh surcharge on projects over 100 MW to offset residential and low-income customer costs. In July 2026 the PUC approved PGE's compliance rate filing implementing the framework: data-center customers' rates rise about 29.7% while residential bills drop about 1.3%.
-
In effect
Utah SB 256 (AI is no defense to defamation; notice-and-removal)
Utah · Effective 2026-05-06 · Utah Code 45-2-3.5, 45-2-14 (S.B. 256, 2026 Gen. Sess.)
Utah's defamation law now expressly states it is not a defense to a libel or slander claim that the content was made with generative AI, computer animation, digital manipulation, or simulated/recreated content. Before suing over digitally created content, the person must send the publisher written notice; if the publisher removes it within 10 days, the plaintiff can recover only actual damages.
-
In effect
Model Tariff Framework for Large Load Customers (Docket M-20
Pennsylvania Public Utility Commission · Effective 2026-04-30 · Model Tariff Framework for Large Load Customers (Docket M-2025-3054271)
The Pennsylvania PUC adopted a first-of-its-kind model tariff framework requiring large load customers exceeding 50 MW individually or 100 MW in aggregate (e.g., data centers) to bear interconnection upgrade costs, post financial assurances, and follow a public application queue so existing ratepayers are not saddled with their costs.
-
In effect
CO AG Weiser
CO · Effective 2026-04-27 · CO AG Weiser — Suspension of Colorado AI Act Rulemaking and Enforcement (x.AI v. Weiser) (2026-04-27)
AG entered joint motion to stay enforcement of SB 24-205 in xAI Corp. v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo.; Chief Judge Daniel D. Domenico; Magistrate Judge Cyrus Y. Chung). DOJ intervened on xAI's side April 24, 2026; federal court entered enforcement stay April 27, 2026. Colorado enacted SB 26-189 (signed May 14, 2026) to repeal and replace SB 24-205; enforcement suspended until rulemaking under new ADMT law by December 31, 2026.
-
In effect
We Energies Very Large Customer (VLC) Data Center Tariff Ord
Public Service Commission of Wisconsin (We Energies) · Effective 2026-04-24 · We Energies Very Large Customer (VLC) Data Center Tariff Order
The Wisconsin PSC approved but overhauled We Energies' data center tariff, lowering the eligibility threshold from 500 MW to 100 MW, extending the minimum contract term to 15 years, and removing a capacity-only option so data centers pay their full share and existing customers are not subsidizing them.
-
In effect
Delaware AI Medical-Titles Ban (no AI 'doctors')
Delaware · Effective 2026-04-23 · Del. H.B. 191, 153rd Gen. Assemb. (2025-2026) (amending 24 Del. C.)
This law makes clear that artificial intelligence and other nonhuman entities cannot be licensed or certified to practice medicine or nursing in Delaware. It bars AI agents from being licensed as a physician, physician assistant, professional nurse, advanced practice nurse, or practical nurse, and from using the professional titles or abbreviations tied to those roles, such as 'Dr.,' 'MD,' 'RN,' 'APRN,' or 'PA.' The intent is to prevent AI tools from misrepresenting themselves as licensed human clinicians, while still allowing AI to be used as a support tool by licensed professionals.
-
In effect
Tennessee SB 837 (AI is not a 'person' under TN law)
Tennessee · Effective 2026-04-23 · 2026 Tenn. Pub. Ch. 781 (SB 837); amends Tenn. Code Ann. Title 1
Tennessee amended its rules of statutory construction to make clear that artificial intelligence and related technology are not legal persons. The law specifies that the terms 'person,' 'life,' and 'natural person' do not include artificial intelligence, computer algorithms, software programs, computer hardware, or any type of machine. It also adds definitions of 'human being' and 'natural person' as living members of homo sapiens. The change is purely definitional and creates no penalty.
-
In effect
VT AG Clark
VT · Effective 2026-03-24 · VT AG Clark — 17-State Coalition Letter on Data Broker AI Surveillance Loophole (2026-03-24)
Joined 17-state coalition urging Congress to close the loophole letting federal agencies purchase commercial data for AI surveillance, bypassing Fourth Amendment protections.
-
In effect
Attorney General Ellison releases consumer alert on DHS' digital surveillance an
MN · Effective 2026-01-15 · Attorney General Ellison releases consumer alert on DHS' digital surveillance and how to protect your privacy (2026-01-15)
Ellison alert and online reporting tool warn residents about AI-powered ID/tracking using biometric, app, and vehicle data; recommends disabling FaceID/TouchID. Follows expert filings in Kohls v. Ellison deepfake case.
-
In effect
Kentucky Consumer Data Protection Act
Kentucky · Effective 2026-01-01 · 2024 Ky. Acts (HB 15); KRS ch. 367
Kentucky's privacy law took effect January 1, 2026, giving residents rights to access, correct, delete, and copy their personal data, and to opt out of data sales and targeted advertising. Businesses need opt-in consent for sensitive data including biometrics.
-
In effect
RI Privacy Law (RIDTPPA)
Rhode Island · Effective 2026-01-01 · R.I. Gen. Laws § 6-48.1 (2024)
Rhode Island residents can access, correct, delete, and port their data, and opt out of targeted advertising, data sales, and profiling. The Attorney General enforces with fines up to $10,000 per violation and — unusually — no cure period.
-
In effect
Indiana Consumer Data Protection Act
Indiana · Effective 2026-01-01 · 2023 Ind. Acts P.L. 94-2023 (SB 5); I.C. 24-15-1 et seq.
Indiana's privacy law, effective January 1, 2026, gives residents rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, data sales, and profiling. Enforced exclusively by the Attorney General with a permanent 30-day cure period.
-
In effect
New Hampshire HB 143 (AI chatbot child-safety)
New Hampshire · Effective 2026-01-01 · N.H. RSA ch. 270 (HB 143, 2025); RSA 270:1-270:2
New Hampshire targets AI chatbots whose sole purpose is open-ended generative conversation. An owner or operator of such a program may not knowingly direct a communication to a child that is intended to facilitate, encourage, solicit, or recommend that the child imminently engage in sexually explicit conduct, illegal drug or alcohol use, self-harm or suicide, or violence. A harmed child — or the child's parent or next friend — may sue for damages, with a minimum of $1,000 in liquidated damages per violation. The Attorney General may also bring an enforcement action.
-
In effect
California AB 489 (AI can't use titles implying it's a licensed clinician)
California · Effective 2026-01-01 · Cal. Bus. & Prof. Code 4999.9 (AB 489, 2025)
This law stops AI technology from pretending to be a licensed health care provider. AI systems and the companies behind them cannot use titles, letters, or terms that falsely suggest the AI holds a health care license or that its services come from a licensed human professional. It extends an existing ban on impersonating licensed health professionals so that it clearly covers AI providers.
-
In effect
California AB 316 (defendants can't blame the AI for acting on its own)
California · Effective 2026-01-01 · Cal. Civ. Code 1714.46 (AB 316, 2025)
This law closes a potential loophole in lawsuits involving artificial intelligence. If someone develops, modifies, or uses an AI system that causes harm, they cannot escape liability by arguing that the AI acted autonomously or on its own.
-
In effect
California SB 243 (companion chatbots: AI disclosure + suicide-safety protocol)
California · Effective 2026-01-01 · Cal. Bus. & Prof. Code 22601 et seq. (SB 243, 2025)
This law sets safety rules for companion chatbots — AI systems designed to hold human-like, ongoing conversations that meet a user's social needs. Operators must tell users they are interacting with AI whenever a reasonable person might be fooled into thinking it is human, and must maintain a protocol for detecting and responding to signs of suicidal thoughts or self-harm, including pointing users to crisis resources. It adds extra protections for minors, such as disclosure, periodic break reminders, and measures to prevent sexually explicit content. Users harmed by violations can sue.
-
In effect
California AB 723 (real estate ads must disclose AI-altered images)
California · Effective 2026-01-01 · Cal. Bus. & Prof. Code 10140.8 (AB 723, 2025)
This law targets misleading property listings that use AI or other digital editing to alter images. A real estate licensee who uses a digitally altered image (including AI-altered images) in advertising to sell real property must disclose that the image was altered and provide a link, URL, or QR code to the original unaltered image. Routine adjustments like lighting, cropping, and color correction are excluded.
-
In effect
California AB 325 (bans anticompetitive use of shared pricing algorithms)
California · Effective 2026-01-01 · AB 325 (2025), amending the Cartwright Act (Cal. Bus. & Prof. Code 16700 et seq.)
This law amends California's main antitrust statute, the Cartwright Act, to address algorithmic price-fixing. It makes it unlawful to use or distribute a common pricing algorithm — a methodology that uses competitor data to recommend, align, stabilize, set, or influence a price or term — as part of an agreement or conspiracy to restrain trade, or to coerce another party into adopting a recommended price. It also makes it easier to bring antitrust conspiracy claims.
-
In effect
AB 2013 (Training Data Transparency)
California · Effective 2026-01-01 · Cal. Civ. Code §§ 3110–3111 (AB 2013, Stats. 2024)
Developers of generative AI systems made available to Californians must publicly post documentation about the datasets used to train their models, including sources, whether they contain personal information or copyrighted material, and time periods of collection. Applies to systems released or substantially modified since January 1, 2022.
-
In effect
SB 53 (Frontier AI Safety)
California · Effective 2026-01-01 · SB 53 (Stats. 2025)
The first US frontier-AI safety law in effect: the largest AI model developers must publish safety frameworks and transparency reports, report critical safety incidents to the state, and protect whistleblowers who raise catastrophic-risk concerns.
-
In effect
TRAIGA
Texas · Effective 2026-01-01 · Tex. Bus. & Com. Code Ch. 552; Tex. HB 149 (89th Leg., R.S., 2025), TRAIGA
Texas's AI law bans specific harmful uses of AI — intentional discrimination, behavioral manipulation encouraging self-harm or crime, social scoring by government, and certain biometric identification without consent — and requires government agencies to disclose AI interactions to consumers. It includes a regulatory sandbox and preempts local AI ordinances.
-
In effect
HI DOI AI Bulletin
HI · Effective 2025-12-10 · Hawaii Insurance Commissioner Memorandum 2025-13A (2025-12-10)
The HI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in HI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
New GS-5 Data Center / Large Load Rate Class, DEV 2025 Bienn
Virginia State Corporation Commission (Dominion Energy Virginia) · Effective 2025-11-25 · New GS-5 Data Center / Large Load Rate Class, DEV 2025 Biennial Review (Case PUR-2025-00058)
The Virginia SCC created a new GS-5 rate class (effective Jan 1, 2027) for customers exceeding 25 MW with load factor above 75%, requiring 14-year contracts and minimum demand charges of 85% for transmission/distribution and 60% for generation so data centers pay their own costs.
-
In effect
New York Algorithmic Pricing Disclosure Act (personalized prices need a label)
New York · Effective 2025-11-10 · N.Y. Gen. Bus. Law 349-A (art. 22-A)
If a business sets the price of a product or service using an algorithm that draws on your personal data, and then shows that personalized price to you as a New York consumer, it has to tell you so with the notice: 'THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA.' The goal is to make personalized 'surveillance pricing' visible rather than hidden. The Attorney General enforces the rule and can seek up to $1,000 per violation after a cease-and-desist notice.
-
In effect
AI Companion Safeguards Law
New York · Effective 2025-11-05 · N.Y. Gen. Bus. Law §§ 1700–1704
The first state law regulating emotionally responsive 'AI companion' chatbots. Operators must clearly tell users they are talking to an AI (with reminders at least every three hours in ongoing sessions) and must detect signs of suicidal ideation or self-harm and refer users to crisis services.
-
In effect
Montana MCDPA
Montana · Effective 2025-10-01 · Mont. Code Ann. §§ 30-14-2901 et seq. (SB 384, 2023; as amended by SB 297, 2025, eff. Oct. 1, 2025)
Montana's comprehensive consumer privacy law, strengthened by 2025 amendments, gives residents rights to access, correct, delete, and opt out of data processing. The SB 297 amendment removed the 'solely automated' qualifier for profiling opt-out, meaning consumers can now opt out of any automated decision-making that involves profiling with significant effects — not just fully automated decisions.
-
In effect
Maryland Online Data Privacy Act
Maryland · Effective 2025-10-01 · 2024 Md. Laws ch. 440 (SB 541); Md. Code Ann., Com. Law §§ 14-4601–14-4626
Maryland's privacy law is stricter than most: it prohibits processing sensitive personal data unless strictly necessary for the requested service. Consumers can access, correct, delete, and port their data, and opt out of automated profiling and targeted advertising. AG enforcement began April 2026.
-
In effect
Maine AI Chatbot Disclosure Law
Maine · Effective 2025-09-16 · 10 M.R.S. ch. 239, Sec. 1500-Y (reallocated to Sec. 1500-DD); P.L. 2025, ch. 294 (L.D. 1727)
Maine prohibits businesses from using an AI chatbot or other computer technology in commercial dealings with a consumer in a way that could mislead a reasonable person into thinking they are interacting with a human, unless the consumer is clearly and conspicuously told they are not. A violation is treated as a violation of the Maine Unfair Trade Practices Act.
-
In effect
PA Digital Forgery Law
Pennsylvania · Effective 2025-09-05 · 2025 Pa. Laws Act 35 (SB 649); 18 Pa. C.S. § 4935
Pennsylvania created the crime of 'digital forgery': making a forged AI-generated likeness of someone with intent to defraud or injure is a first-degree misdemeanor, escalating to a third-degree felony for financial fraud — directly targeting AI voice-clone scams like fake grandchild emergency calls. A clear fake-content disclaimer is an affirmative defense.
-
In effect
TX HB 581 — AI Sexual Material Age Verification
Texas · Effective 2025-09-01 · Tex. Civ. Prac. & Rem. Code (artificial sexual material harmful to minors) (HB 581, 89th Leg., R.S. (2025))
This law regulates commercial websites and apps that offer publicly available tools for generating 'artificial sexual material harmful to minors.' Operators must use reasonable age-verification methods to confirm users are at least 18, and must ensure that any real person used as the source of the generated material is also at least 18 and has consented to the use of their face and body. Operators that ignore these duties face civil penalties of up to $10,000 per day, rising to as much as $250,000 if a violation results in a minor accessing the material. The law includes safe-harbor protections for operators that adopt qualifying terms of use and take affirmative steps to limit such material.
-
In effect
TX SB 2373 (AI Media / Phishing Financial Abuse)
Texas · Effective 2025-09-01 · Tex. S.B. 2373, 89th Leg., R.S. (2025); Tex. Civ. Prac. & Rem. Code ch. 100B; Tex. Penal Code Sec. 32.56
Texas makes it unlawful to use AI-generated images, audio, video, or text — or phishing messages — to financially exploit or defraud another person. Victims can sue the wrongdoer and recover their actual losses, damages for mental anguish, the profits the wrongdoer earned, and their court costs and attorney's fees, and may seek an injunction. A separate civil penalty of up to $1,000 for each day the deceptive media or communication was circulated can be pursued. The same conduct can also be prosecuted criminally, with penalties scaling up to a first-degree felony based on the amount taken.
-
In effect
Texas SB 441 (deepfake NCII crime + website/AI-app/payment-processor liability)
Texas · Effective 2025-09-01 · Tex. S.B. 441, 89th Leg., R.S. (2025); amending Tex. Penal Code 21.165 and Tex. Civ. Prac. & Rem. Code ch. 98B (adding 98B.0021, 98B.0022, 98B.008, 98B.009); eff. Sept. 1, 2025
This Texas law makes it a crime to knowingly create or share, without consent, AI-generated or otherwise manipulated deepfake images that falsely depict a real person with computer-generated intimate parts or engaged in sexual conduct they never performed, and bans threatening to do so. It also lets victims sue the people who made or spread such artificial intimate visual material, and extends that liability to owners of websites, social platforms, AI 'nudification' apps, or payment systems that knowingly or recklessly facilitate the content. Covered websites and apps must offer an easy removal-request tool and can be liable if they fail to take material down within 72 hours of a depicted person's request. Victims may sue using a confidential identity and have up to 10 years to file.
-
In effect
Michigan Intimate Deep Fakes Act
Michigan · Effective 2025-08-26 · 2025 Mich. Pub. Acts 10–11 (HB 4047–4048)
Michigan makes it a crime to create or distribute AI-generated sexually explicit images of a real, identifiable person without their consent. First offenses carry up to one year in jail and a $3,000 fine; aggravated violations (posting online, extortion, prior conviction) escalate to a felony with up to three years. Victims may also sue for damages, injunctions, and up to $1,000/day for violating a restraining order.
-
In effect
AR Generative AI Ownership Act (Act 927)
Arkansas · Effective 2025-08-05 · Ark. Act 927 (2025) (HB1876), codified at Ark. Code Ann. tit. 18, ch. 4 (Sec. 18-4-101 et seq.)
Arkansas set default ownership rules for the inputs and outputs of generative AI tools. A person who supplies the input or direction to a generative AI tool owns the content it produces, as long as that content does not infringe existing intellectual property rights. A person who lawfully supplies the data used to train a model owns the resulting trained model. When an employee is directed to use a generative AI tool within the scope of their job, the employer owns the resulting output and model. The law sets property rights rather than prohibitions, so it does not impose penalties.
-
In effect
ND 12.1-17-07 (using a robot/AI to harass is a crime)
North Dakota · Effective 2025-08-01 · N.D. Cent. Code 12.1-17-07; 2025 N.D. Laws (HB 1429)
North Dakota updated its harassment law so that using a 'robot' to harass someone is itself a crime. A robot here means an artificial object or system that senses, processes, and acts using technology, including artificial intelligence. A person commits harassment if they use such a robot to engage in offensive conduct that serves no legitimate purpose.
-
In effect
ND 12.1-17-07.1 (stalking via robot/AI, e.g. tracking, is a crime)
North Dakota · Effective 2025-08-01 · N.D. Cent. Code 12.1-17-07.1; 2025 N.D. Laws (HB 1429)
North Dakota extended its stalking law to cover stalking carried out with a 'robot,' including artificial intelligence systems. This reaches conduct such as using a robot to track a person without authorization. The change makes clear that automated or AI-driven tools cannot be used as a workaround to stalk someone.
-
In effect
Minnesota Consumer Data Privacy Act
Minnesota · Effective 2025-07-31 · 2024 Minn. Laws ch. 123 (HF 4757); Minn. Stat. §§ 325M.01–.21
Minnesota's privacy law gives residents data rights plus something unique: the right to question automated profiling decisions with significant effects — including the right to know why the decision was made and what would change the outcome. Full AG enforcement began February 2026.
-
In effect
MA AG
MA · Effective 2025-07-10 · MA AG — $2.5M Earnest Operations Settlement (AI Underwriting Discrimination) (2025-07-10)
Settlement with student-loan lender Earnest over allegations its AI underwriting model and 'Knockout Rule' produced disparate impacts on Black, Hispanic, and non-citizen applicants. Mandates AI governance, annual fair-lending testing, AG reporting.
-
In effect
AEP Ohio Data Center Tariff Order (Case 24-0508-EL-ATA)
Public Utilities Commission of Ohio (AEP Ohio) · Effective 2025-07-09 · AEP Ohio Data Center Tariff Order (Case 24-0508-EL-ATA)
The Ohio PUC adopted a settlement creating a new data center customer class for loads of 25 MW or greater, requiring those customers to pay for at least 85% of contracted capacity for a minimum 12-year term plus exit fees and financial assurances to prevent cost-shifting to other customers.
-
In effect
Nevada AB 406 (AI can't pose as a therapist)
Nevada · Effective 2025-07-01 · 2025 Nev. Stat., AB 406, Sec. 7 (new section of NRS ch. 433)
Nevada prohibits an AI provider from making available in the state an AI system that is specifically programmed to provide a service that would amount to the practice of professional mental or behavioral health care if a person did it. AI providers also may not state or imply that their AI system can provide such care or that it is a therapist, counselor, psychiatrist, or doctor. The state must publish educational materials directing people to licensed care. Genuine self-help materials and AI used by licensed providers for administrative tasks are not prohibited.
-
In effect
Texas SB 6 (Data Center Grid Law)
Texas · Effective 2025-06-21 · Tex. SB 6 (2025), amending Tex. Util. Code
Texas now regulates how very large electricity users such as data centers connect to the ERCOT grid. Loads over 75 MW face a minimum $100,000 transmission study fee and financial commitments, and new large loads must install remote-disconnect capability so ERCOT can curtail them during grid emergencies.
-
In effect
Oregon POWER Act
Oregon · Effective 2025-06-05 · Or. HB 3546 (2025) (POWER Act)
Oregon's first-in-the-nation POWER Act makes data centers and crypto-mining operations pay for their own grid costs instead of shifting them onto household utility bills. Large users over 20 MW are placed in a separate rate class and must sign long-term contracts committing to minimum payments.
-
In effect
Walters v. OpenAI
GA · Effective 2025-05-19 · Walters v. OpenAI, L.L.C., No. 23-A-04860-2 (Gwinnett Cty. Super. Ct., Ga.)
Georgia radio host Mark Walters sued OpenAI after ChatGPT fabricated a story that he had embezzled from a gun-rights nonprofit. In May 2025, Judge Tracie Cason granted summary judgment to OpenAI, holding that no reasonable reader would treat ChatGPT output as a statement of fact and that OpenAI's disclaimers about hallucinations defeated 'actual malice.' The first U.S. AI defamation case to reach a merits ruling.
-
In effect
Utah S.B. 226 (must disclose you're talking to AI on request; AI use no excuse)
Utah · Effective 2025-05-07 · Utah Laws 2025, S.B. 226; Utah Code 13-75-101 to 13-75-106
Utah requires businesses using generative AI in consumer interactions to come clean about it. If a consumer clearly asks whether they are dealing with AI, a supplier must disclose they are interacting with generative AI and not a human. People in licensed occupations must prominently disclose AI use up front in 'high-risk' interactions (health, financial, legal, mental-health advice or sensitive data). A safe harbor applies for clear self-identification, and it is no defense that the AI made the offending statement.
-
In effect
HB 452 (Mental Health Chatbots)
Utah · Effective 2025-05-07 · Utah Code § 13-2c-101 et seq. (HB 452, 2025)
Utah regulates AI chatbots that act like therapists: suppliers must clearly disclose the chatbot is not human, may not advertise products mid-conversation without disclosure, and may not sell or share users' individually identifiable health information.
-
In effect
DC AG Schwalb senior AI-fraud unit
DC · Effective 2025-04-18 · D.C. Code § 28-3904; DC OAG Consumer Alert (Apr. 18, 2025)
The DC Attorney General announced an Elder Justice Initiative focused on AI-enabled scams targeting older Washingtonians — voice-clone grandparent scams, tech-support fraud using AI chatbots, and AI romance scams. The office uses DC's Consumer Protection Procedures Act and the Elder Financial Exploitation Act to investigate.
-
In effect
Arkansas Deepfake Sexual Content Act
Arkansas · Effective 2025-04-17 · 2025 Ark. Acts 827 (HB 1529)
Arkansas criminalizes creating or distributing deepfake sexual imagery — AI-generated or digitally manipulated images that appear authentic and depict an identifiable person in nudity or sexual conduct without consent. First offense is a Class A misdemeanor, repeats are felonies; victims can sue for punitive damages, and the Attorney General can sue platforms that lack reasonable safeguards against generating this content.
-
In effect
NJ Deceptive AI Deepfakes Act
New Jersey · Effective 2025-04-02 · P.L.2025, c.40 (N.J. A3540/S2544)
New Jersey's omnibus deepfake law establishes criminal and civil penalties for producing or distributing deceptive AI audio/video used to facilitate crimes — including sexual exploitation of minors, harassment, extortion, and election interference. Violations are a third-degree crime carrying up to five years and fines up to $30,000, and victims can sue.
-
In effect
WI DOI AI Bulletin
WI · Effective 2025-03-18 · Wisconsin OCI AI Bulletin (2025-03-18) (2025-03-18)
The WI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in WI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Large-Load Flexible Tariff Investigation for Facilities Reac
Utah Public Service Commission (Rocky Mountain Power / PacifiCorp) · Effective 2025-03-01 · Large-Load Flexible Tariff Investigation for Facilities Reaching 100 MW (per SB 132)
Following Utah SB 132 (2025), the Utah PSC opened an investigation into a flexible large-load tariff for Rocky Mountain Power covering facilities expected to reach at least 100 MW within five years, allowing such facilities to procure their own supply if serving them would require major ratepayer-funded upgrades.
-
In effect
Arkansas Frank Broyles Act AI amendment — voice and likeness protection (2025)
Arkansas · Effective 2025-02-25 · Ark. Act 159 / HB 1071 (2025 Regular Session), amending Ark. Code Ann. § 4-75-1101
Arkansas Act 159 (HB 1071), signed February 25, 2025, amends the Frank Broyles Publicity Rights Protection Act of 2016 to explicitly cover AI-generated voice and likeness. It adds 'voice' — including AI-simulated voice that sounds like a real person — and AI-generated images to the rights protected under the Act. Any commercial use of a person's AI-replicated voice or image without explicit consent is a violation. Named for the late UA Razorbacks coach Frank Broyles; became one of the first U.S. publicity-rights laws to specifically address AI-generated audio.
-
In effect
I&M Industrial Power (Large Load) Tariff Settlement Order (C
Indiana Utility Regulatory Commission (Indiana Michigan Power) · Effective 2025-02-19 · I&M Industrial Power (Large Load) Tariff Settlement Order (Cause No. 46097)
The Indiana URC approved a settlement modifying Indiana Michigan Power's Industrial Power Tariff for facilities of at least 70 MW (or 150 MW aggregated), requiring 12-year contracts, minimum monthly demand charges of 80% of contract capacity, exit fees, and collateral so grid-upgrade costs fall on data centers rather than existing ratepayers.
-
In effect
NJ DOI AI Bulletin
NJ · Effective 2025-02-11 · New Jersey DOBI Insurance Bulletin 25-03 (2025-02-11)
The NJ Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NJ must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
DE DOI AI Bulletin
DE · Effective 2025-02-05 · Delaware Domestic and Foreign Insurers Bulletin No. 148 (2025-02-05)
The DE Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in DE must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
CSU AI-Empowered University System initiative and systemwide
California State University (CSU System) · Effective 2025-02-04 · CSU AI-Empowered University System initiative and systemwide ChatGPT Edu deployment
CSU announced a first-in-the-nation systemwide AI initiative giving all 23 campuses' 460,000+ students and 63,000+ faculty/staff access to ChatGPT Edu plus AI Commons training and academic-use resources.
-
In effect
Rule Establishing Special Contract Terms for Large-Load Cust
Georgia Public Service Commission (Georgia Power) · Effective 2025-01-23 · Rule Establishing Special Contract Terms for Large-Load Customers Over 100 MW
The Georgia PSC unanimously approved a rule allowing Georgia Power to bill new customers using more than 100 MW under special terms, requiring them to cover transmission and distribution construction costs, permitting contracts up to 15 years, and mandating PSC review of each large-load contract.
-
In effect
New Jersey Data Protection Act
New Jersey · Effective 2025-01-15 · P.L.2024, c.9 (N.J. SB 332)
New Jersey's comprehensive privacy law grants residents rights to access, correct, delete, and port personal data and to opt out of data sales and targeted advertising. Controllers must get opt-in consent for sensitive data (health, biometric, precise location) and honor universal opt-out signals since July 2025.
-
In effect
CA AG Bonta AI legal advisory
CA · Effective 2025-01-13 · CA DOJ Legal Advisory (Jan. 13, 2025)
California's Attorney General issued a legal advisory making clear that existing California consumer-protection, civil-rights, and privacy laws fully apply to AI — including the False Advertising Law, Unfair Competition Law, CCPA, and FEHA. The advisory targets AI-washing, AI-driven discrimination, hallucination-driven misrepresentations, and AI scam impersonation.
-
In effect
NJ AG Platkin / DCR
NJ · Effective 2025-01-09 · NJ AG Platkin / DCR — Guidance on Algorithmic Discrimination and the NJLAD (2025-01-09)
13-page guidance affirming NJLAD applies to ADS-driven discrimination in employment, housing, credit, public accommodations. Launches Civil Rights and Technology Initiative and Civil Rights Innovation Lab.
-
In effect
IL Bar AI Standing Committee
IL · Effective 2025-01-01 · Ill. Sup. Ct. Policy on AI (eff. Jan. 1, 2025)
Illinois Supreme Court adopted a Policy on Artificial Intelligence (effective January 1, 2025) authorizing AI use by attorneys, judges, and court staff provided it complies with legal and ethical standards. The policy explicitly states that disclosure of AI use should not be required in a pleading, and does not impose mandatory CLE requirements; instead it supports ongoing education on AI and holds all users accountable for thoroughly reviewing AI-generated content before submission.
-
Blocked / in litigation
CA AB 2655 (deepfake takedown)
CA · Effective 2025-01-01 · Cal. Elec. Code §§ 20510–20517; AB 2655, Ch. 261, Stats. 2024
California passed a law requiring large online platforms to label or remove materially deceptive AI-generated content related to elections, and authorized candidates and election officials to sue for injunctive relief and damages. A federal court has blocked enforcement of key provisions while First Amendment litigation proceeds.
-
In effect
Iowa Consumer Data Protection Act
Iowa · Effective 2025-01-01 · Iowa SF 262 (2023), Iowa Code ch. 715D
Iowa's privacy law gives consumers rights to access, delete, copy, and opt out of the sale of their personal data and targeted advertising. Notably it does NOT include a profiling opt-out, making it one of the more business-friendly state privacy laws.
-
In effect
Nebraska NDPA
Nebraska · Effective 2025-01-01 · Neb. Rev. Stat. §§ 87-901 et seq. (LB 1074, 108th Leg., 2024), eff. Jan. 1, 2025
Nebraska's comprehensive consumer privacy law gives residents the right to access, correct, delete, and port their personal data and to opt out of targeted advertising, data sales, and automated profiling used in decisions with significant legal or financial effects. The Attorney General enforces with fines up to $7,500 per violation with no private right of action.
-
In effect
NH Consumer Privacy Act
New Hampshire · Effective 2025-01-01 · RSA 507-H (2024 NH SB 255)
New Hampshire residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions. Applies at low thresholds (35,000 residents), so it covers many businesses.
-
In effect
Delaware Privacy Law (DPDPA)
Delaware · Effective 2025-01-01 · 6 Del. C. § 12D-101 et seq. (2023 DE HB 154)
Delaware residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions with legal effects. Applies at low thresholds (35,000 consumers).
-
In effect
California AB 2885 (one statewide statutory definition of 'AI')
California · Effective 2025-01-01 · AB 2885, Stats. 2024 (definition codified at Cal. Gov. Code 11546.45.5)
This is a definitional clean-up bill rather than a regulatory one. It establishes a single, consistent statutory meaning of artificial intelligence and applies that uniform definition across several parts of California law, so different statutes stop using inconsistent definitions. On its own it imposes no obligations or penalties.
-
In effect
California AB 2905 (robocalls must disclose an AI-generated voice)
California · Effective 2025-01-01 · Cal. Pub. Util. Code 2874 (AB 2905, Stats. 2024)
When a caller uses an automatic dialing-announcing device to play a prerecorded message, California already requires a live-voice introduction. This law adds that the introduction must also tell the person if the prerecorded message uses an artificial voice, meaning a voice generated or significantly altered using AI. The point is to keep people from being deceived by synthetic voices in automated calls.
-
In effect
OR AG Rosenblum
OR · Effective 2024-12-24 · OR AG Rosenblum — AI Guidance (UTPA, OCPA, Equality Act) (2024-12-24)
Clarifies that Oregon's UTPA, OCPA, and Equality Act apply to AI absent AI-specific law. Misrepresenting AI capabilities, discriminatory outcomes, and processing biometric/sensitive data without consent are actionable.
-
In effect
NC DOI AI Bulletin
NC · Effective 2024-12-18 · North Carolina DOI Bulletin 24-B-19 (2024-12-18)
The NC Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NC must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
MA DOI AI Bulletin
MA · Effective 2024-12-09 · Massachusetts Division of Insurance Bulletin 2024-10 (2024-12-09)
The MA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in MA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
OK DOI AI Bulletin
OK · Effective 2024-11-14 · Oklahoma ID Bulletin 2024-11 (2024-11-14)
The OK Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in OK must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
IA DOI AI Bulletin
IA · Effective 2024-11-07 · Iowa Insurance Division Bulletin 24-04 (2024-11-07)
The IA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in IA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Cruise SF Pedestrian Incident
CA · Effective 2024-10-31 · In re GM Cruise LLC — NHTSA Consent Order (Sept. 2024); confidential personal-injury settlement
A San Francisco pedestrian was struck by a hit-and-run driver, thrown into the path of a GM Cruise robotaxi, and then dragged ~20 feet by the Cruise vehicle in October 2023. NHTSA fined Cruise; the California PUC suspended its driverless permit; Cruise reached confidential settlement with the victim and ultimately shut down driverless robotaxi operations in 2024.
-
In effect
NY AG James AI scam consumer alert
NY · Effective 2024-10-17 · NY OAG Press Release (Oct. 17, 2024)
New York Attorney General Letitia James issued consumer alerts warning New Yorkers about AI voice-cloning grandparent scams, AI romance and pig-butchering schemes, and AI investment fraud — and pledged enforcement under New York's GBL § 349 against deceptive AI uses.
-
In effect
Texas v. Pieces Technologies
TX · Effective 2024-09-18 · Texas v. Pieces Technologies — Healthcare Generative AI Settlement (2024-09-18)
First state AG settlement targeting deceptive GenAI clinical marketing. Alleged Pieces misrepresented hallucination rates of a hospital summarization tool at four TX hospitals; settlement mandates accurate disclosures and monitoring. This action is an Assurance of Voluntary Compliance (AVC), not a monetary settlement; no penalty was assessed and Pieces Technologies denies wrongdoing.
-
In effect
MI AG AI scam alert
MI · Effective 2024-08-15 · Mich. Comp. Laws § 445.903; MI OAG Press Release (Dec. 11, 2024)
Michigan Attorney General Dana Nessel issued an alert warning consumers about AI deepfake video scams, voice clones, and synthetic image fraud — including AI-generated investment ads using fake celebrity endorsements — and pledged enforcement under the Michigan Consumer Protection Act.
-
In effect
WV DOI AI Bulletin
WV · Effective 2024-08-09 · West Virginia OIC Insurance Bulletin 24-06 (2024-08-09)
The WV Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in WV must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
MI DOI AI Bulletin
MI · Effective 2024-08-07 · Michigan DIFS Bulletin 2024-20-INS (2024-08-07)
The MI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in MI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
AR DOI AI Bulletin
AR · Effective 2024-07-31 · Arkansas Insurance Department Bulletin 13-2024 (2024-07-31)
The AR Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in AR must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
VA DOI AI Bulletin
VA · Effective 2024-07-22 · Virginia SCC Bureau of Insurance Administrative Letter 2024-01 (2024-07-22)
The VA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in VA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Florida Digital Bill of Rights (privacy / profiling opt-out)
Florida · Effective 2024-07-01 · Fla. CS/CS/SB 262 (2023); ch. 2023-201, Laws of Fla.; Fla. Stat. Secs. 501.701-501.722
Florida's Digital Bill of Rights gives covered consumers a set of data-privacy rights, including the right to opt out of profiling carried out solely by automated processing when that profiling is used to make decisions that have a legal or similarly significant effect on the person. Businesses that meet the law's thresholds must also conduct and document data-protection assessments for higher-risk processing activities such as profiling, targeted advertising, and the sale of personal data. The Florida Attorney General enforces the law; consumers cannot sue directly. The law applies only to a relatively narrow set of very large businesses.
-
In effect
TDPSA
Texas · Effective 2024-07-01 · Tex. Bus. & Com. Code ch. 541 (HB 4, 2023)
Texans can access, correct, delete, and obtain copies of personal data held by covered businesses, and can opt out of targeted advertising, data sales, and profiling used for decisions with significant effects (like jobs, housing, or credit). Businesses must get consent for sensitive data, including biometrics.
-
In effect
NE DOI AI Bulletin
NE · Effective 2024-06-11 · Nebraska Insurance Guidance Document IGD-H1 (2024-06-11)
The NE Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NE must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
AI Policy Template for Local Education Agencies
Alabama State Department of Education (ALSDE) · Effective 2024-06-01 · AI Policy Template for Local Education Agencies
Alabama's education department released a customizable AI policy template for LEAs built on eight pillars (strategy, governance, data privacy/security, procurement, implementation, competency, risk management, effectiveness).
-
In effect
DC DOI AI Bulletin
DC · Effective 2024-05-21 · DC DISB Bulletin 24-IB-002-05/21 (2024-05-21)
The DC Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in DC must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
AZ Digital Impersonation Law
Arizona · Effective 2024-05-21 · 2024 Ariz. Sess. Laws (HB 2394); A.R.S. § 13-2006
Any Arizona citizen or candidate can go to court to stop the unconsented publication of a digital impersonation of themselves, and using AI-generated images, voice, or video of another person with intent to defraud or harass is a felony. Passed 57-0.
-
In effect
South Carolina 40-57-820 (realtors accountable for AI-assisted work)
South Carolina · Effective 2024-05-21 · S.C. Code Ann. 40-57-820, enacted by 2024 Act No. 204 (H.4754), approved May 21, 2024
South Carolina makes licensed real estate professionals fully responsible for any work product they create with the help of artificial intelligence, machine learning, or similar tools. If a violation of the real estate licensing law is committed using such tools, it is treated as though the licensee committed it directly. Licensees must double-check AI-assisted work for compliance with advertising, intellectual property, confidentiality, and related rules.
-
In effect
Utah AI Policy Act
Utah · Effective 2024-05-01 · Utah Code § 13-72-101 et seq. (SB 149, 2024; amended 2025)
The first state generative-AI consumer law: businesses can't hide behind AI — they remain liable under consumer protection law for what their chatbots say. People in regulated occupations (like healthcare providers) must proactively disclose AI use in high-risk interactions, and any business must disclose AI use when clearly asked.
-
In effect
DC Bar Op. 388 (GenAI)
DC · Effective 2024-04-24 · D.C. Bar Op. 388 (Apr. 24, 2024)
DC lawyers using generative AI must understand the tools they use, supervise AI output, protect client confidentiality, communicate with clients about AI, comply with billing rules, and avoid the unauthorized practice of law by AI chatbots.
-
In effect
MD DOI AI Bulletin
MD · Effective 2024-04-22 · Maryland Insurance Administration Bulletin 24-11 (2024-04-22)
The MD Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in MD must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
WA DOI AI Bulletin
WA · Effective 2024-04-22 · Washington OIC Technical Assistance Advisory 2024-02 (2024-04-22)
The WA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in WA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
MA AG Campbell
MA · Effective 2024-04-16 · MA AG Campbell — Advisory on Consumer Protection, Anti-Discrimination, Data Security and AI (2024-04-16)
Clarifies that Chapter 93A, the Anti-Discrimination Law, and MA Data Security Regs apply fully to AI developers, suppliers, and users; identifies algorithmic discrimination and misrepresenting AI capabilities as unfair/deceptive.
-
In effect
KY DOI AI Bulletin
KY · Effective 2024-04-16 · Kentucky DOI Bulletin 2024-02 (2024-04-16)
The KY Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in KY must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Huang v. Tesla
CA · Effective 2024-04-08 · Huang v. Tesla, Inc., No. 19CV346663 (Cal. Super. Ct. Santa Clara Cty.)
Apple engineer Walter Huang died in 2018 when his Tesla Model X on Autopilot crashed into a highway divider. His family sued; the case settled confidentially on the eve of trial in April 2024 — the first Autopilot wrongful-death case to reach (and settle on the eve of) a jury verdict.
-
In effect
NY Bar AI Report
NY · Effective 2024-04-06 · NYSBA AI Task Force Report (Apr. 6, 2024)
The New York State Bar adopted recommendations on AI in legal practice covering competence, confidentiality, supervision, candor to the court, and advertising — explicitly noting that 'hallucination' sanctions in Mata v. Avianca apply to all New York lawyers using AI.
-
In effect
PA DOI AI Bulletin
PA · Effective 2024-04-06 · Pennsylvania ID Insurance Notice 2024-04 (54 Pa.B. 1910) (2024-04-06)
The PA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in PA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
My Health My Data Act
Washington · Effective 2024-03-31 · RCW ch. 19.373
A sweeping health-data privacy law covering 'consumer health data' far beyond HIPAA — including biometric data, health inferences drawn by algorithms, and reproductive health information. Companies need consent to collect or share such data, must honor deletion requests, and cannot geofence health facilities. Consumers can sue under Washington's Consumer Protection Act.
-
In effect
RI DOI AI Bulletin
RI · Effective 2024-03-15 · Rhode Island DBR Insurance Bulletin 2024-03 (2024-03-15)
The RI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in RI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
IL DOI AI Bulletin
IL · Effective 2024-03-13 · Illinois DOI Company Bulletin 2024-08 (2024-03-13)
The IL Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in IL must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
VT DOI AI Bulletin
VT · Effective 2024-03-12 · Vermont DFR Insurance Bulletin 229 (2024-03-12)
The VT Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in VT must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
CT DOI AI Bulletin
CT · Effective 2024-02-26 · Connecticut Insurance Department Bulletin MC-25 (2024-02-26)
The CT Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in CT must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
NV DOI AI Bulletin
NV · Effective 2024-02-23 · Nevada DOI Bulletin 24-001 (2024-02-23)
The NV Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NV must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
NH DOI AI Bulletin
NH · Effective 2024-02-20 · New Hampshire ID Docket INS 24-011-AB (2024-02-20)
The NH Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NH must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
AK DOI AI Bulletin
AK · Effective 2024-02-01 · Alaska Division of Insurance Bulletin B 24-01 (2024-02-01)
The AK Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in AK must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
CA AG Bonta
CA · Effective 2024-01-26 · CA AG Bonta — CCPA Investigative Sweep of Streaming Services (2024-01-26)
Sweep into streaming services' opt-out compliance; led to a $530K Sling TV settlement in 2025 and parallel CPPA actions (Honda $632,500) on ADMT-adjacent practices.
-
In effect
NJ Supreme Court GenAI Notice
NJ · Effective 2024-01-25 · NJ Supreme Court Notice (Jan. 25, 2024)
The New Jersey Supreme Court issued a binding notice requiring lawyers using generative AI to comply with the Rules of Professional Conduct, including verifying citations, protecting client confidentiality, and supervising AI output. Sanctions follow citation hallucination.
-
In effect
FL Bar Op. 24-1 (GenAI)
FL · Effective 2024-01-19 · Fla. Bar Ethics Op. 24-1
Florida lawyers using generative AI must obtain informed client consent before using AI to handle client information, supervise AI like nonlawyer staff, verify factual and legal accuracy, comply with advertising rules for AI chatbots, and follow billing requirements that prevent overcharging.
-
In effect
CCC systemwide AI guidance and HUMANS responsible-AI framewo
California Community Colleges Chancellor's Office · Effective 2024-01-01 · CCC systemwide AI guidance and HUMANS responsible-AI framework
The California Community Colleges Chancellor's Office issues systemwide AI guidance built on its HUMANS framework (human-centered, privacy, algorithmic-discrimination protections, notice and explanation, safety) governing AI in instruction and student support.
-
In effect
CA Bar GenAI Guidance
CA · Effective 2023-11-16 · State Bar of California, COPRAC Practical Guidance (Nov. 16, 2023)
California lawyers using ChatGPT, CoPilot, or other generative AI tools must protect client confidentiality, verify AI-generated work, supervise AI outputs, disclose AI use where required, and avoid billing for time saved by AI. Misuse of generative AI is a discipline-eligible violation.
-
In effect
Virginia VCDPA (opt out of profiling, $7,500/violation)
Virginia · Effective 2023-01-01 · Va. Code 59.1-575 to 59.1-585 (esp. 59.1-577, 59.1-580, 59.1-584); HB 2307 / SB 1392 (2021)
Virginia's comprehensive privacy law gives consumers the right to opt out of 'profiling' used to make decisions producing legal or similarly significant effects, such as automated decisions affecting credit, housing, employment, or essential services. Businesses must obtain heightened consent before processing the data of a known child (via federal COPPA) and must conduct documented data protection assessments for higher-risk processing, including certain profiling. The Attorney General enforces the law and may seek up to $7,500 per violation; there is no private right of action.
-
In effect
PA Act 130 of 2022 (HAVs)
Pennsylvania · Effective 2022-11-03 · Act 130 of 2022; 75 Pa. C.S. Ch. 88
Pennsylvania's comprehensive AV law authorized fully driverless operation, created a PennDOT permitting regime for testing and commercial deployment, required incident reporting to PennDOT and State Police, and authorized 'highly automated work zone vehicles' and platooning. Pennsylvania had been an AV testing hub since 2016 under non-statutory PennDOT guidance; Act 130 finally codified the framework.
-
In effect
OH HB 7 (2022 AV)
Ohio · Effective 2022-09-13 · Ohio Rev. Code §§ 4501.01, 4511.01, 4511.991
Ohio's 2022 statute codified what had been executive-order policy under DriveOhio: fully driverless AV operation is allowed, the registered owner is the legal operator for traffic enforcement, AV networks must carry $5 million in insurance, and the state must maintain an AV testing program (the Smart Mobility / TRC framework).
-
In effect
Idaho AI Personhood Prohibition
Idaho · Effective 2022-07-01 · Idaho Code Sec. 5-346 (HB 720, 2022, ch. 322)
Idaho law declares that artificial intelligence cannot be granted legal personhood in the state, alongside environmental elements, nonhuman animals, and inanimate objects. The provision preserves the existing legal-person status of municipalities, corporations, and other recognized entities that held it before July 1, 2022. It is a structural/definitional statute and carries no penalty.
-
In effect
CO Insurance Algorithmic Discrimination Law
Colorado · Effective 2021-07-06 · Colo. Rev. Stat. Sec. 10-3-1104.9 (SB 21-169)
Colorado prohibits insurers from using outside consumer data, algorithms, or predictive models in ways that unfairly discriminate against people based on protected characteristics such as race, sex, religion, sexual orientation, disability, or gender identity. The law directs the state Insurance Commissioner to write rules that require insurers to test their data and models and show they do not produce discriminatory outcomes. Insurers must also maintain a risk-management framework to monitor for unfair discrimination. Coverage was later expanded to additional lines such as private passenger auto and health benefit plans.
-
In effect
PA PDD law (Act 130/2020)
Pennsylvania · Effective 2021-01-04 · Act 130 of 2020; 75 Pa. C.S. § 3550
Pennsylvania authorized personal delivery devices to operate on sidewalks, shoulders, and roadways up to 25 mph (high relative to most PDD laws), requires $100,000 liability insurance, and reserves limited regulation to local governments.
-
In effect
NJ Bot Disclosure Act (bots must identify themselves)
New Jersey · Effective 2020-07-19 · N.J.S.A. 56:18-1 et seq.; P.L. 2019, c.486
New Jersey makes it unlawful to use an online bot to communicate or interact with a person in the state in order to deceive them about the bot's artificial identity, when the goal is to sell or advertise merchandise or real estate, or to solicit support for a candidate, party, or ballot question in an election. The use of the bot is allowed if it is clearly and conspicuously disclosed up front. The Attorney General enforces the law and can pursue civil penalties.
-
In effect
AR Act 1096 (2019 AV)
Arkansas · Effective 2019-07-24 · Act 1096 of 2019; Ark. Code Ann. §§ 27-51-1801 et seq.
Arkansas authorized commercial driver-assistive truck platooning and limited driverless AV pilots, established a Pilot Program for Driverless-Capable Vehicles administered by the Arkansas State Highway Commission, and required pilots to file insurance and incident-reporting plans.
-
In effect
CA SB 1001 BOT Act (2018, historical framing)
CA · Effective 2019-07-01 · Cal. Bus. & Prof. Code §§ 17940-17943 (SB 1001, 2018)
Signed by Governor Brown on September 28, 2018, California SB 1001 was the first U.S. state law requiring bots to disclose they are not human when used to incentivize a sale or influence a vote. Still in effect 2026 at Cal. Bus. & Prof. Code §17940-17943. The first state bot-disclosure law and direct precursor to NJ Bot Disclosure Act (2019), federal Bot Disclosure Act of 2018 (S. 3127, died), and modern chatbot disclosure laws (UT SB 226, NE LB 525, etc.).
-
In effect
California Bot Disclosure Act (bots must self-identify in sales/election messaging)
California · Effective 2019-07-01 · Cal. Bus. & Prof. Code 17940-17943 (SB 1001, Stats. 2018)
California makes it unlawful to use a bot to communicate with someone in the state while concealing that it is a bot, when the goal is to deceive the person in order to push a commercial sale or influence their vote. There is a safe harbor: there is no liability as long as the operator clearly and conspicuously discloses that a bot is in use. In practice it is a disclosure mandate rather than a ban on automated accounts.
-
In effect
UT HB 101 (2019 AV statute)
Utah · Effective 2019-05-14 · Utah Code §§ 41-26-101 et seq.
Utah's AV law expressly allows fully driverless operation, treats the automated driving system as the 'driver' for traffic-law purposes, authorizes commercial AV networks, and preempts local AV regulation.
-
In effect
OH PDD law (SB 156)
Ohio · Effective 2019-04-04 · Ohio Rev. Code § 4511.513
Ohio authorized sidewalk delivery robots up to 200 lb (one of the highest weight caps in the country) and up to 10 mph, with $100,000 in liability insurance. Local governments retain authority to set additional operating rules.
-
In effect
AZ PDD law (HB 2422)
Arizona · Effective 2018-08-03 · Ariz. Rev. Stat. §§ 28-9601–28-9605
Arizona authorized sidewalk delivery robots statewide and prohibited municipalities from imposing taxes, fees, or registration requirements on PDDs, while letting them set operating rules (time of day, density, sidewalk type).
-
In effect
NE LB 989 (2018 AV)
Nebraska · Effective 2018-04-25 · Neb. Rev. Stat. §§ 60-3,201 et seq.
Nebraska's Driverless-Capable Vehicle Act explicitly allows fully driverless operation on Nebraska public roads, treats the automated driving system as the driver for traffic-law purposes, sets minimum insurance ($5 million for on-demand AV networks), and preempts local regulation.
-
In effect
AZ EO 2018-04 (AV oversight)
Arizona · Effective 2018-03-01 · Ariz. Exec. Order No. 2018-04
On March 1, 2018 — 17 days before the fatal Uber self-driving crash in Tempe — Governor Doug Ducey issued EO 2018-04 to update his permissive 2015 AV order and advance Arizona's position as a national leader for autonomous vehicle development. The order requires AV operators to certify compliance with federal and state law before operating in Arizona and to file safety information with the DOT. After the Uber crash on March 18, 2018, Ducey separately suspended Uber's testing privileges by letter rather than by executive order. Arizona's AV regime remains executive-order based, with no comprehensive statute.
-
In effect
CT Rideshare Dynamic-Pricing Law (surge-price limits)
Connecticut · Effective 2018-01-01 · Conn. Gen. Stat. Sec. 13b-118; Sec. 13b-117 (penalty); P.A. 17-140
When a ride-hailing company (like Uber or Lyft) uses dynamic or 'surge' pricing, Connecticut law requires it to warn riders before they request a ride, give them a tool to estimate the fare, and make them confirm they understand surge pricing will apply. The law also caps price gouging during emergencies: a company cannot charge more than 2.5 times its usual fare in any area covered by a declared disaster emergency. The state transportation commissioner oversees TNC registration and can suspend or revoke it for violations. Operating without a valid registration can draw a substantial fine.
-
In effect
NC HB 469 (2017 AV statute)
North Carolina · Effective 2017-12-01 · S.L. 2017-166; N.C. Gen. Stat. §§ 20-400–20-403
North Carolina legalized fully autonomous vehicles, treats the registered owner as the operator for traffic-enforcement purposes, allows AVs to transport unaccompanied minors only with parental consent, and preempts local AV regulation.
-
In effect
FL PDD law (2017)
Florida · Effective 2017-10-01 · Fla. Stat. § 316.008
Florida authorized personal delivery devices to operate on sidewalks and bicycle facilities statewide (10 mph cap, 80 lb cargo, $100,000 insurance) and preempted municipal bans, leaving cities only limited authority to set time-of-day and crowd-size rules.
-
In effect
TX SB 2205 (2017 AV statute)
Texas · Effective 2017-09-01 · Tex. Transp. Code §§ 545.451–545.456
Texas's main autonomous-vehicle law explicitly authorizes AVs to operate on Texas roads without a human driver, defines the 'owner' of an automated driving system as the legal operator for liability and traffic enforcement, and preempts local AV bans. It set the framework that later allowed Waymo, Cruise, and Aurora freight to operate in Texas.
-
In effect
IL AV local-preemption (2017)
Illinois · Effective 2017-08-25 · P.A. 100-352; 625 ILCS 65
Illinois has not enacted a comprehensive AV testing/deployment statute; instead, the Autonomous Vehicles Act preempts local governments (including Chicago) from prohibiting the use of automated driving systems or requiring an AV-specific operator license. As of 2026 the legislature still has not adopted a Texas/Florida-style operational framework.
-
In effect
GA SB 219 (2017 AV statute)
Georgia · Effective 2017-07-01 · 2017 Ga. Laws Act 245
Georgia legalized fully driverless autonomous vehicles statewide, required AVs to be registered, insured ($250,000 minimum for fully autonomous vehicles), and capable of complying with traffic laws. The statute preempts local AV-specific ordinances.
-
In effect
TN SB 151 (2017 AV Act)
Tennessee · Effective 2017-07-01 · 2017 Tenn. Pub. Acts Ch. 474; Tenn. Code Ann. §§ 55-30-101 et seq.
Tennessee's Automated Vehicles Act authorized fully driverless operation on Tennessee roads, set minimum-insurance requirements for AV networks ($5 million coverage), explicitly preempted local AV-specific regulation, and treated the automated driving system as the legal operator for traffic-law purposes.
-
In effect
WI PDD Act 13 (2017)
Wisconsin · Effective 2017-07-01 · Wis. Stat. § 346.804; 2017 Wis. Act 13
Wisconsin authorized sidewalk delivery robots up to 80 lb at up to 10 mph, requires operators to carry $100,000 in liability insurance, and allows cities to set additional rules but not outright bans.
-
In effect
ID PDD law (HB 191)
Idaho · Effective 2017-07-01 · Idaho Code §§ 49-2701 et seq.
Idaho authorized statewide sidewalk delivery robots under a uniform framework (80 lb, 10 mph), required $100,000 in liability insurance, and gave local governments limited authority to add operating rules.
-
In effect
CO SB 17-213 (AV statute)
Colorado · Effective 2017-06-01 · Colo. Rev. Stat. § 42-4-242
Colorado authorized automated driving systems, allowing AVs that can comply with all traffic laws to operate without a separate state authorization — but if the ADS cannot fully comply, the operator must coordinate with CDOT and the State Patrol before deployment.
-
In effect
NY AV testing pilot
New York · Effective 2017-04-20 · Part FF, Ch. 55, Laws of 2017 (uncodified session law)
New York requires AV operators to obtain DMV pilot-program authorization, maintain a licensed human safety driver behind the wheel, post a $5 million insurance bond, and coordinate with State Police for each test deployment. New York remains one of the most restrictive states — fully driverless operation is not authorized as of 2026.
-
In effect
MI SAVE Acts (2016 AV package)
Michigan · Effective 2016-12-09 · P.A. 332–335 of 2016
Michigan's 2016 four-bill 'SAVE' package made the state one of the most comprehensive AV jurisdictions: it legalized fully driverless operation, authorized commercial AV networks (ride-hail with self-driving cars), allowed truck platooning, established the American Center for Mobility, and explicitly limited manufacturer liability when third parties convert vehicles to autonomous operation.
-
In effect
FL HB 7027 (2016 driverless AV)
Florida · Effective 2016-04-04 · Ch. 2016-181, Laws of Fla.; Fla. Stat. §§ 316.85, 316.86
Florida became one of the first states to allow fully driverless autonomous vehicles on public roads. HB 7027 removed the prior requirement that a licensed driver be present in the vehicle and built on Florida's 2012 AV testing law, paving the way for the 2019 'driverless deployment' law (HB 311) that explicitly authorizes AVs with no human driver.
-
In effect
CA AB 856 (2015 drone trespass)
California · Effective 2016-01-01 · Cal. Civ. Code § 1708.8(b)
California amended its anti-paparazzi statute so the existing 'physical invasion of privacy' tort applies when someone uses a drone to enter the airspace above a person's land to capture images or recordings of personal or familial activities — closing the 'I never set foot on the property' loophole.
-
In effect
CA SB 1298 (2012 AV authorization)
California · Effective 2013-01-01 · Cal. Veh. Code §§ 38750 et seq.
California's foundational autonomous-vehicle statute. SB 1298 directed the DMV to adopt regulations for testing and eventual deployment of AVs on California roads, including an autonomous-vehicle tester permit, insurance and bonding rules, and the framework later used for the Cruise and Waymo robotaxi authorizations.
-
In effect
NV AB 511 (2011 — first AV statute)
Nevada · Effective 2011-06-17 · NRS Ch. 482A (2011 Nev. Stat. Ch. 461)
Nevada was the first U.S. state to legalize autonomous vehicles. AB 511 directed the DMV to write rules for testing and operating self-driving cars on Nevada roads, including a special license endorsement and an autonomous-vehicle testing license, and made Nevada the proving ground for the early Google self-driving project.
-
In effect
Guam Breach Notification (9 GCA Ch. 48)
Guam · Effective 2009-01-01 · 9 G.C.A. ch. 48
Guam's data breach notification statute. Requires entities holding personal information to notify affected residents of breaches. Relevant to AI systems processing personal data because any compromise must trigger notice.
-
Enacted (not yet in effect)
Virginia FY2026-2028 Biennial Budget: Data Center Electricit
Virginia · Virginia FY2026-2028 Biennial Budget: Data Center Electricity Tax, Water Cooling and Noise Provisions
Virginia's new two-year budget imposes a first-of-its-kind $0.011/kWh tax on data center electricity consumption effective July 1, 2026, and directs regulators to establish water-cooling scarcity rules and first-ever noise standards for data centers.
-
Proposed / pending
House Bill 2512 — Banning surveillance pricing by rideshare
Pennsylvania · House Bill 2512 — Banning surveillance pricing by rideshare companies
Pennsylvania's House passed HB 2512 to prohibit transportation network companies (Uber/Lyft) from using consumers' personal data to set individualized 'surveillance' prices, now advancing to the Senate.
-
Enacted (not yet in effect)
S731/A796 — Data center ratepayer protection and grid-demand
New Jersey · NJ S731/A796 (Data Center Fair Share Act), signed by Governor Sherrill July 7, 2026
New Jersey Governor Sherrill signed S731/A796 — the Data Center Fair Share Act — into law on July 7, 2026. The law requires large data centers (those with 100 megawatts or more of contracted electricity) to pay for the full amount of electricity they contract for, and to reduce or shift energy use during peak grid stress events. The law is designed to prevent large data centers from reserving grid capacity that ordinary ratepayers then subsidize.
-
Vetoed
Arizona HB 2133 deepfake sexual content — vetoed 2026
Arizona · Ariz. H.B. 2133, 57th Leg., 2d Reg. Sess. (2026) — vetoed June 19, 2026
Arizona HB 2133 would have amended the state's existing unlawful-image-disclosure statute to include 'synthetic depictions' — AI-generated images of nudity or sexual activity — and would have required websites hosting sexual material to verify that each depicted person consented and was of legal age. The Senate approved a reconciled conference bill 16-12 on June 9, 2026 and the House passed 35-20. Gov. Hobbs vetoed it on June 19, writing that the bill had 'a chilling effect on free speech' and would violate First Amendment rights to engage in satirical discourse about elected officials, and that existing Arizona law and the federal TAKE IT DOWN Act already address AI-generated revenge porn.
-
Repealed / replaced
Colorado AI Act (repealed)
Colorado · SB 24-205, Colo. Rev. Stat. § 6-1-1701 et seq. (repealed/replaced 2026)
The first comprehensive US state AI law would have required developers and deployers of 'high-risk' AI systems to use reasonable care to prevent algorithmic discrimination in decisions about jobs, housing, lending, insurance, education, and healthcare. After repeated delays, it was repealed and replaced in May 2026 by a narrower transparency-focused law (SB 26-189) before it ever took effect.
-
Proposed / pending
LG&E/KU CPCN Order Addressing Extremely High Load Factor Dat
Kentucky Public Service Commission (LG&E and KU) · LG&E/KU CPCN Order Addressing Extremely High Load Factor Data Center Tariff (Case 2025-00045)
The Kentucky PSC authorized LG&E/KU to build two gas plants for future data centers and endorsed an 'extremely high load factor' tariff under which new data centers using at least 100 MW must pay for at least 80% of their stated monthly consumption for 15 years, while deferring the cost-recovery mechanism to a later rate case.
-
Proposed / pending
Large Load Tariff Docket Opened via Duke Energy Progress/Car
Public Service Commission of South Carolina · Large Load Tariff Docket Opened via Duke Energy Progress/Carolinas Settlements
Settlements with Duke Energy Progress and Duke Energy Carolinas require the South Carolina PSC to open a large load tariff docket that could establish consumer protections ensuring incremental data-center costs are not shifted onto residential and traditional business customers.
-
Proposed / pending
NJ Kids Code Act A4015 (2026)
NJ · N.J. A4015/S3413 (222nd Legislature, 2026) — cleared both chambers June 30, 2026; enrolled to governor
New Jersey A4015/S3413, the NJ Kids Code Act, is an Age-Appropriate Design Code bill modeled on the UK ICO Children's Code and California AB 2273 (CAADCA). It requires online platforms and services likely to be accessed by children under 18 to conduct data protection impact assessments, default privacy settings to the highest protective level for minor users, prohibit profiling children for commercial purposes without parental consent, and restrict design features that extend children's engagement. The Assembly cleared it 73-5-0; the Senate cleared it; enrolled to Governor Sherrill as of July 1, 2026. Governor Sherrill has not yet signed.
-
Proposed / pending
Algorithmic rent price-fixing ban
Illinois · IL SB343 (104th General Assembly, 2025-2026)
Would amend the Illinois Antitrust Act to ban landlords from using shared rent-setting algorithms or third-party pricing software (such as RealPage) to coordinate residential rental prices. Targets "algorithmic" or "AI-enabled" rent price-fixing, where competing landlords feed data into a common service that recommends prices, indirectly coordinating rents across the market. Prohibits fixing, controlling, or maintaining rental pricing or terms for residential units, including through any service or product that involves price coordination.
-
Proposed / pending
NY AI Professional Impersonation Liability Bill
New York · S.7263-A, 2025–2026 New York Legislature; adds GBL § 390-f
This pending New York bill would make AI-chatbot operators legally responsible if their chatbot impersonates a licensed professional — like a doctor, lawyer, or nurse — in a way that would be illegal if a person did it. The state Attorney General could sue violators for up to $15,000 per day, and operators would have to clearly tell users they are talking to an AI chatbot. After advancing on the Senate floor it was sent back to the Rules Committee in June 2026.
-
Repealed / replaced
CO SB24-205 (original)
CO · Effective 2026-02-01 · Colo. SB 24-205 (2024) — substantially superseded by SB 26-189 (May 14, 2026)
Colorado SB24-205 was the first U.S. comprehensive high-risk AI statute (2024). The original framework was substantially rewritten by SB 26-189 after the 2026 special session — this entry is the historical record of the original law.
-
Repealed / replaced
UT SB 149 (superseded)
UT · Effective 2024-05-01 · Utah SB 149 (2024) — substantially superseded by SB 226/SB 332 (2025)
Utah SB 149 was the first-in-nation generative AI disclosure statute (2024), establishing a regulatory sandbox and consumer disclosure requirements. Substantially rewritten and narrowed by SB 226 and SB 332 in 2025.
-
Repealed / replaced
CCPA Original (AB 375, 2018)
CA · Effective 2020-01-01 · Cal. AB 375 (2018), 2018 Cal. Stats. ch. 55 — substantially superseded by Prop 24 (CPRA) and 2025 CPPA ADMT regs
Governor Jerry Brown signed AB 375 — the original California Consumer Privacy Act — on June 28, 2018, the most comprehensive state privacy law in U.S. history at the time. Substantially amended by Prop 24 (CPRA, 2020) and the 2025 CPPA ADMT regulations. This entry captures the original 2018 framework as historical baseline.
-
Vetoed
CA SB 1047 (vetoed)
CA · Cal. SB 1047 (2023-24 Reg. Sess.) — vetoed Sept. 29, 2024
California SB 1047 would have required safety testing, kill-switches, and developer liability for frontier AI models trained above compute/cost thresholds. Governor Newsom vetoed it on September 29, 2024 — a landmark veto that reshaped the U.S. frontier-AI policy debate.
-
Vetoed
VA HB 2094 (vetoed)
VA · Va. HB 2094 (2025) — vetoed Mar. 24, 2025
Virginia HB 2094 would have imposed Colorado-style duties on developers and deployers of high-risk AI systems with consumer disclosures and impact assessments. Governor Youngkin vetoed it on March 24, 2025 — the first red-state veto of an EU-AI-Act-style framework.
-
Expired
CA AB 2930 (died)
CA · Cal. AB 2930 (2023-24 Reg. Sess.) — held on suspense file Aug. 31, 2024
California AB 2930 (Bauer-Kahan) would have imposed algorithmic-discrimination duties on developers and deployers of automated decision tools used for consequential decisions. Held on Senate Appropriations suspense file in August 2024 — never received floor vote.
-
Expired
CT SB 2 (died)
CT · Conn. SB 2 (2024 Reg. Sess.) — died in House
Connecticut SB 2 was a comprehensive AI bill mirroring Colorado SB24-205. Passed the Senate in 2024 but was never called for a House vote after Governor Lamont opposition over potential business impact.
-
Expired
NY S7623B (died)
NY · N.Y. S7623B (2023-24 Reg. Sess.) — died in committee
New York S7623B was a comprehensive AI rights and disclosure bill. Never advanced past the Senate Internet committee in 2024.
-
Expired
OK HB 3577 (died)
OK · Okla. HB 3577 (2024 Reg. Sess.) — died on Senate floor
Oklahoma HB 3577 was a red-state AI rights framework with consumer disclosure requirements. Passed the House in 2024 but never received a Senate floor vote.
County consumer protection rules (2)
-
In effect
Ordinance outlawing algorithmic rent price fixing in unincor
King County, WA · Effective 2025-09-23 · Ordinance outlawing algorithmic rent price fixing in unincorporated King County
King County (sponsored by Councilmember Teresa Mosqueda, passed Sept 23, 2025 as the 11th US jurisdiction) prohibits landlords in unincorporated King County from contracting with algorithmic rent-setting services like RealPage, letting harmed renters sue for up to $7,500 per violation plus damages and attorneys' fees.
-
In effect
PA Allegheny AFST
Allegheny County, PA · Effective 2016-08-01 · Allegheny County DHS AFST Methodology (May 2019 update)
Allegheny County deploys a predictive risk model — the Allegheny Family Screening Tool — to score child-welfare hotline calls. Decisions to screen-in cases for investigation incorporate AFST scores. The DOJ has investigated the tool for ADA discrimination concerns; the county continues to operate it with documented protocols.
City / local consumer protection rules (26)
-
In effect
NYC Biometric Identifier Law (LL3)
New York City, NY · Effective 2021-07-09 · NYC Admin. Code §§ 22-1201–22-1205 (Local Law 3 of 2021)
NYC retail stores, restaurants, and entertainment venues that collect customers' biometric data (face scans, fingerprints, iris scans, voiceprints) must post clear signs at entrances disclosing it. Selling or otherwise profiting from customers' biometric data is flatly banned. Customers can sue: $500 per signage or negligent-sale violation and $5,000 per intentional or reckless sale, plus attorneys' fees.
-
In effect
Portland OR Twin FR Bans (2020, broadest-in-nation)
Portland, OR · Effective 2021-01-01 · Portland City Code Ch. 34.10 (private-sector); Council Action Sept. 9, 2020
On September 9, 2020, Portland, Oregon became the first U.S. city to ban both government AND private-sector use of facial recognition in places of public accommodation. The private-sector ban — codified at Portland City Code Ch. 34.10 — included a private right of action and remains the broadest municipal FR ban in the United States.
-
In effect
Portland Private-Sector FR Ban
Portland, OR · Effective 2021-01-01 · Portland, Or., City Code ch. 34.10 (Ordinance 190114, 2020)
Portland is the first US city to ban private businesses from using facial recognition in places of public accommodation such as stores, restaurants, and entertainment venues. People can sue violators for damages. The ban remains in effect as of June 2026.
-
Blocked / in litigation
Liu v. Willow Bridge/RealPage (Philadelphia)
Philadelphia, PA · Effective 2026-07-28 · Liu et al. v. Willow Bridge Property Co. & RealPage, Inc., Phila. County Ct. of Common Pleas (filed July 28, 2026)
Three class-action lawsuits were filed in Philadelphia's Court of Common Pleas on July 28, 2026 — the first known enforcement actions under Philadelphia's algorithmic rent-fixing ban (Bill 240823). Tenant Yiyao Liu and others sued Willow Bridge Property Co. (one of the largest U.S. residential property managers) and RealPage Inc., alleging Willow Bridge used RealPage's software to obtain rent recommendations derived from nonpublic competitor data in violation of the city ordinance. Plaintiffs seek treble damages or $2,000 statutory amount per violation, plus injunctive relief.
-
In effect
Hoboken Algorithmic Rent-Fixing Ban
Hoboken, NJ · Effective 2025-07-09 · Hoboken City Council ordinance banning algorithmic rent-fixing, adopted July 9, 2025
Hoboken, NJ banned landlords from using algorithmic rent-fixing software. The ordinance passed unanimously (8-0) on July 9, 2025 and took effect immediately. It defines 'price fixing using algorithmic pricing' as the use of software or algorithms that collect nonpublic competitor data to coordinate rental pricing across multiple properties. Violations carry fines up to $20,000 per offense, up to 90 days imprisonment, or up to 90 days of community service. All residential rental properties are covered, excluding medical/long-term care and detention facilities.
-
In effect
Philadelphia Bill 240823 — Algorithmic Rent-Fixing Ban
Philadelphia, PA · Effective 2024-11-13 · Philadelphia Bill No. 240823 (adopted Oct. 24, 2024; signed Nov. 13, 2024; effective Nov. 13, 2024)
Philadelphia's Bill 240823 (sponsored by Councilmember Nicolas O'Rourke, passed 17-0 on October 24, 2024 and signed November 13, 2024) bars landlords from using revenue-management software that pools private competitor leasing data to coordinate rents, with fines up to $2,000 per violation and a private right of action for tenants. On July 28, 2026 three class-action lawsuits were filed — the first known enforcement actions under the ordinance — against Willow Bridge Property Co. and RealPage Inc.
-
In effect
SF delivery-robot permit (2017)
San Francisco · Effective 2018-01-21 · S.F. Pub. Works Code § 794
San Francisco became the first U.S. city to comprehensively restrict sidewalk delivery robots after constituent backlash. Supervisor Norman Yee's ordinance limits autonomous delivery devices to a small permit program (initially 9 city-wide and 3 per company), bans them from most sidewalks, caps speed at 3 mph in pedestrian zones, and requires a human chaperone.
-
In effect
Ordinance 192122 - Prohibition of anti-competitive algorithm
Portland, OR · Effective 2025-11-19 · Ordinance 192122 - Prohibition of anti-competitive algorithmic rental pricing (City Code 30.01.088)
Portland's Ordinance 192122 (passed 8-2 on Nov 19, 2025, effective ~Feb 2026) bans the sale and use of revenue-management 'algorithmic devices' that analyze competitor data to coordinate rents, with fines and a tenant right to sue up to $1,000 per violation.
-
In effect
Santa Monica Algorithmic Rent-Setting Ban
Santa Monica, CA · Effective 2025-06-24 · Santa Monica City Council ordinance banning algorithmic rent-setting software, adopted approx. June 24, 2025
Santa Monica, CA banned the sale and use of algorithmic rent-setting software that relies on nonpublic competitor data to coordinate rental pricing. Adopted around June 24, 2025, the ordinance provides tenants with an affirmative defense in eviction proceedings where such software was used to set rent, and allows civil enforcement by renters or the city. The ordinance was motivated in part by housing affordability concerns following the January 2025 LA wildfires. It targets RealPage YieldStar-type systems that aggregate competitor pricing data to raise rents across multiple properties.
-
In effect
Council Bill 121000 - Ban on algorithmic rent fixing (SMC 7.
Seattle, WA · Effective 2025-06-24 · Council Bill 121000 - Ban on algorithmic rent fixing (SMC 7.34)
Seattle's CB 121000 (sponsored by Councilmember Cathy Moore, passed 7-0 on June 24, 2025, signed July 1, 2025) prohibits landlords from using software that runs automated analysis of housing-market data to generate inflated rent recommendations, with penalties up to $7,500 per violation and a tenant private right of action.
-
In effect
Ordinance prohibiting price-fixing rental algorithms
Providence, RI · Effective 2025-05-15 · Ordinance prohibiting price-fixing rental algorithms
Providence (ordinance by Council President Rachel Miller, final passage May 15, 2025) bans landlords from using price-fixing rental algorithms like RealPage, with civil penalties up to $500 per day per instance of violation.
-
In effect
Ordinance banning algorithmic rent-setting software
Jersey City, NJ · Effective 2025-05-14 · Ordinance banning algorithmic rent-setting software
Jersey City passed a ban on algorithmic rent-setting software in May 2025 after statewide New Jersey efforts stalled, prohibiting landlords from using coordinated pricing algorithms.
-
Proposed / pending
Ordinance prohibiting use of algorithmic rent-setting device
Berkeley, CA · Effective 2025-03-11 · Ordinance prohibiting use of algorithmic rent-setting devices (Berkeley City Council, March 11, 2025; suspended 2025 pending RealPage litigation)
Berkeley's City Council voted 8-1 in March 2025 to prohibit landlords from using algorithms to coordinate rent prices or manage vacancies. The ban was subsequently suspended by a follow-up Council ordinance after RealPage filed a First Amendment lawsuit challenging the measure. The suspension ordinance's second reading was scheduled for July 8, 2025; a November 2025 amendment extended the suspension to March 1, 2026. Post-March 2026 status remains unclear — RealPage litigation is ongoing. The ban is currently NOT being enforced.
-
In effect
Ordinance prohibiting sale or use of algorithmic devices to
San Francisco, CA · Effective 2024-10-14 · Ordinance prohibiting sale or use of algorithmic devices to set rents (Administrative Code / Rent Ordinance Section 37.10C)
San Francisco, the first US city to do so, bans landlords from selling or using algorithmic revenue-management software that uses non-public competitor data to recommend rents or occupancy levels, with civil penalties up to $1,000 per violation plus damages and attorneys' fees.
-
In effect
NYC LL 60 (delivery robots)
New York City · Effective 2024-01-01 · N.Y.C. Admin. Code § 19-176.4; Local Law 60 of 2023
New York City authorized a pilot framework for sidewalk delivery robots ('motorized assistive devices'), giving DOT rulemaking authority over speed, weight, sidewalk vs. bike-lane use, and operator registration. The DOT pilot launched in 2024 with explicit weight caps (550 lb) and 12 mph maximum speed.
-
Proposed / pending
Bellingham Initiative 26-01 to Ban Algorithmic Rental Price-
Bellingham · Bellingham Initiative 26-01 to Ban Algorithmic Rental Price-Fixing
A certified citizen initiative would prohibit landlords from using algorithmic coordinating services to set rental prices, heading toward Bellingham's November 2026 ballot.
-
Proposed / pending
Use of Algorithms in Rental Rates Ordinance
Minneapolis, MN · Use of Algorithms in Rental Rates Ordinance
Minneapolis (third US city, 11-2 vote in March 2025) prohibits owners from using 'algorithmic devices' relying on non-public competitor data to set rents or occupancy, enforced through rental-license self-attestation and a tenant private right of action, effective March 1, 2026.
-
Proposed / pending
Cambridge MA algorithmic rent-setting ban (policy order, Jun. 2026)
Cambridge, MA · Cambridge, MA City Council unanimous policy order (late June 2026) directing draft ordinance banning algorithmic rent-setting (Councillor Sobrinho-Wheeler)
The Cambridge, Massachusetts City Council voted unanimously in late June 2026 on a policy order directing city staff to draft an ordinance banning algorithmic rent-setting — software (such as RealPage-style tools) that landlords use to coordinate and set rents. The order, led by Councillor Sobrinho-Wheeler, follows municipal bans in Berkeley, CA and Providence, RI. A policy order directs drafting; the ban itself is not yet law, so this is indexed as proposed until an ordinance is drafted and enacted.
-
Proposed / pending
Office of Artificial Intelligence Oversight
New York City · NYC Int 0919-2026
Would establish an Office of Artificial Intelligence Oversight within the Department of Consumer and Worker Protection. The office would investigate complaints about AI systems violating consumer protection laws, recommend enforcement actions, maintain a public complaint portal, run AI-harm consumer awareness campaigns, and propose rules clarifying how existing consumer protections apply to AI.
-
Proposed / pending
Ban biometric recognition in public accommodations (Ban The Scan)
New York City · NYC Int 0213-2026
Would make it illegal for places of public accommodation (stores, restaurants, music venues, theaters, etc.) to use biometric recognition systems to verify or identify customers without notice and prior written consent. Requires written policies governing use of collected biometric data and procedures for customers to request erasure of their biometric information.
-
Status unknown
Atlanta City Council resolution accepting AI Commission recommendations
Atlanta · Atlanta 26-R-3663 (introduced June 1, 2026)
Resolution accepting the final report and 16 recommendations of the Atlanta AI Commission. Recommendations include equity impact assessments in AI procurement, role-specific staff training, cybersecurity standards for AI vendors, a public registry of all AI systems in use across City departments, and creation of a permanent AI Advisory Board co-chaired by the City's Chief Information Officer and Senior Technology Advisor. Directs the Mayor's office to examine administrative implementation steps while Council considers legislative follow-up.
-
Proposed / pending
DC SDAA (B24-0558)
Washington, DC · B24-0558 (DC Council, 2021; reintroduced)
DC's Stop Discrimination by Algorithms Act would bar algorithmic decision-making that discriminates in housing, employment, education, credit, healthcare, insurance. Mandates annual bias audits, consumer notice, disclosure; private right of action with civil penalties up to $10,000 per violation. Pending across DC Council sessions since 2021.
-
Proposed / pending
NYC Int 1003-2024
New York, NY · NYC Int 1003-2024
NYC Int 1003-2024 would amend the admin code to create an AI working group at the Commission on Human Rights to study AI's impact on employment and AEDT effects on protected classes — complementing Local Law 144.
-
Proposed / pending
DC SDAA (B25-0114)
Washington, DC · D.C. Council B25-0114 (proposed)
A DC Council bill that would ban using algorithms to discriminate based on race, sex, age, or disability in important life decisions such as employment, housing, credit, insurance, and education, and would require notice and audits.
-
Expired
Baltimore FR Ban (Expired)
Baltimore, MD · Effective 2021-09-08 · Baltimore, Md., Council Bill 21-0001 (2021) (expired Dec. 31, 2022)
Baltimore's 2021 ordinance banned private entities and individuals (and most city agencies) from using face surveillance systems, with criminal penalties. It contained a sunset clause and EXPIRED on December 31, 2022 when the City Council did not extend it. As of June 2026 the ban is no longer in effect; 2023 successor bills were not confirmed as enacted.
-
Expired
DC Algorithm Bill (not enacted)
Washington, DC · D.C. Council B24-0558 (2021); B25-0114 (2023) (not enacted)
A proposed DC law that would ban businesses from using algorithms that discriminate based on protected traits in decisions about jobs, housing, credit, insurance, and education, and would require annual bias audits and consumer disclosures. Despite multiple introductions since 2021, it has never been enacted — DC residents rely on federal protections.