Home › Topics › consumer data privacy
U.S. AI Laws: consumer data privacy
As of 2026-08-12, AI Laws USA tracks 384 U.S. AI rules on consumer data privacy across federal, state, county, and city government. Each entry links to its official source.
Federal consumer data privacy rules (38)
-
In effect
COPPA + 2025 Rule (childrens data)
United States · Effective 2025-06-23 · 15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312
COPPA requires online services aimed at children under 13 to get verifiable parental consent before collecting kids' personal data. The 2025 rule update — fully in effect since April 22, 2026 — adds biometric identifiers (like face templates and voiceprints, which matter for AI tools), requires separate parental consent before sharing children's data for targeted advertising, and tightens data retention limits.
-
In effect
TAKE IT DOWN Act
United States · Effective 2025-05-19 · Pub. L. No. 119-12 (S. 146)
Makes it a federal crime to knowingly publish intimate images of someone without consent, including AI-generated deepfakes. Social media and similar platforms must give victims a way to request removal and must take the content (and known copies) down within 48 hours. The platform removal requirement became enforceable May 19, 2026, and the FTC has already begun enforcement.
-
In effect
TCPA (AI voice calls)
United States · Effective 2024-02-08 · 47 U.S.C. § 227; FCC 24-17
Robocalls using AI-cloned or AI-generated voices are treated like other 'artificial voice' calls: callers need your prior express consent, must identify themselves, and must offer opt-outs for telemarketing. You can personally sue violators for $500 to $1,500 per illegal call.
-
In effect
Patel v. Facebook (BIPA)
N.D. Cal. · Effective 2021-02-26 · In re Facebook Biometric Info. Privacy Litig., No. 3:15-cv-03747 (N.D. Cal. Feb. 26, 2021); 932 F.3d 1264 (9th Cir. 2019)
The largest biometric-privacy settlement in U.S. history at the time — $650 million paid by Facebook to roughly 1.6 million Illinois users whose facial templates were extracted by the 'Tag Suggestions' feature without BIPA consent. Each class member received about $400.
-
In effect
FAA Part 107 (drones)
United States · Effective 2016-08-29 · 14 C.F.R. Part 107
The core federal rulebook for commercial and recreational small drones (under 55 lb). Operators need a Remote Pilot Certificate, must keep the drone within visual line of sight, fly below 400 ft, avoid most airspace without authorization, and follow operations-over-people limits. Waivers and Beyond-Visual-Line-of-Sight (BVLOS) approvals exist for advanced operators.
-
In effect
FCRA (AI in credit & background checks)
United States · Effective 1971-04-25 · 15 U.S.C. § 1681 et seq.
When a company uses a consumer report or score — including AI-generated risk scores from background-check and tenant/employment screening firms — to deny you credit, insurance, housing, or a job, it must tell you and identify the agency that supplied the report. You have the right to a free copy of your file and to dispute inaccurate information, no matter how algorithmic the scoring was.
-
In effect
Meta AI Layoff Discrimination Lawsuit (2026)
United States · Effective 2026-07-15 · 26 Meta employees v. Meta Platforms, Inc., N.D. Cal. (Oakland), filed July 15, 2026; FMLA, ADA, PDA, PWFA claims
Twenty-six current and former Meta employees filed a lawsuit on July 15, 2026 in the Northern District of California (Oakland) alleging that Meta's internal AI system called 'Metamate' was used to select workers for layoffs in a way that disproportionately targeted employees on medical leave, pregnancy leave, and parental leave. The plaintiffs allege violations of the Family and Medical Leave Act (FMLA), the Americans with Disabilities Act (ADA), the Pregnancy Discrimination Act, and the Pregnant Workers Fairness Act. The court denied an emergency injunction request on July 17, 2026. The case represents a significant test of employer liability when an AI system makes or influences employment termination decisions affecting workers with protected characteristics.
-
In effect
Doe v. X.AI (Grok NCII deepfakes class action)
United States · Effective 2026-01-23 · Doe v. X.AI Corp., No. 5:26-cv-00772 (N.D. Cal., filed Jan. 23, 2026); amended complaint July 7, 2026
A class action filed January 23, 2026 in the Northern District of California (Case No. 5:26-cv-00772) alleges that X.AI's Grok AI model generated over three million sexualized deepfake images in an 11-day period, including images of minors. An amended complaint filed July 7, 2026 added Stability AI as a co-defendant and two new plaintiffs, including one who alleges approximately 7,000 child sexual abuse material (CSAM) images were generated of them. Claims include product liability, negligence, public nuisance, and privacy violations. A companion case (Doe 1 v. X.AI Corp., No. 5:26-cv-02246) was filed March 16, 2026. Note: X.AI Corp. has rebranded to SpaceXAI following its merger with SpaceX.
-
In effect
Kistler v. Eightfold AI (FCRA, AI hiring)
United States · Effective 2026-01-20 · Kistler et al. v. Eightfold AI Inc., Case 3:26-cv-1768 (N.D. Cal.); 15 U.S.C. § 1681 et seq. (FCRA)
Erin Kistler and Sruti Bhaumik filed a class action in California Superior Court in January 2026 (later removed to federal court as Case 3:26-cv-1768 in the Northern District of California) against Eightfold AI, a leading AI hiring platform. The plaintiffs allege that Eightfold scraped over one billion worker profiles and used an AI model to rank job applicants on a scale of 0 to 5 without providing the disclosures and adverse action notices required by the Fair Credit Reporting Act (FCRA). The case targets AI hiring tools that function as employment screening reports, arguing that the FCRA's consumer-report protections extend to AI-driven applicant scoring systems. A motion to dismiss is set for hearing on August 4, 2026 before Judge Yvonne Gonzalez Rogers.
-
In effect
FinCEN deepfake-fraud BSA alert
United States · Effective 2024-11-13 · FinCEN Alert FIN-2024-Alert004 (Nov. 13, 2024)
FinCEN issued an alert telling banks and other financial institutions how to spot — and report — fraud schemes that use generative-AI deepfakes to defeat identity verification. Suspicious activity reports must use the SAR keyword 'FIN-2024-DEEPFAKEFRAUD' so FinCEN can track the trend in synthetic identity and account-takeover fraud.
-
In effect
FTC HBNR Rule (AI health apps)
United States · Effective 2024-07-29 · 16 C.F.R. Part 318; 89 Fed. Reg. 47028
Health apps and connected devices — including AI-powered mental health and fitness tools — must notify users, the FTC, and (in some cases) the media within 60 days of a breach of identifiable health information. The 2024 amendments confirm that AI-generated inferences about health are covered.
-
In effect
In re Clearview AI Class Settlement
N.D. Ill. · Effective 2024-06-21 · In re Clearview AI, Inc. Consumer Privacy Litig., MDL 2967, No. 1:21-cv-00135 (N.D. Ill.)
A nationwide BIPA class action against Clearview AI settled in 2024 on an unusual basis: rather than cash, class members receive a 23 percent equity interest in Clearview, valued by plaintiffs at up to $51 million depending on company valuation. The arrangement reflected Clearview's inability to pay cash damages of the magnitude BIPA would require.
-
In effect
FTC v. Amazon (Ring)
FTC · Effective 2023-07-31 · Federal Trade Commission v. Ring LLC, No. 1:23-cv-01549 (D.D.C. 2023)
The FTC settled with Amazon's Ring subsidiary for $5.8M in 2023 over privacy and security failures — including allowing employees and contractors to view customer videos without consent and failing to prevent stalkers from compromising accounts. The settlement restricts Ring's use of customer videos for product / AI development.
-
In effect
FTC v. Amazon (Alexa)
FTC · Effective 2023-07-25 · United States v. Amazon.com, Inc., No. 2:23-cv-00811 (W.D. Wash. July 25, 2023)
Companion FTC action settled with Amazon's Alexa division for $25M in 2023, alleging Amazon retained children's voice recordings indefinitely despite COPPA, deleted records when parents requested but kept transcripts and the underlying voice models, and used the data to train Alexa's voice-recognition AI.
-
In effect
In re Google Photos BIPA
Ill. Cir. Ct. Cook Cty. · Effective 2022-09-28 · Rivera v. Google LLC, No. 2019-CH-00990 (Ill. Cir. Ct. Cook Cty.)
Illinois Google Photos users won a $100 million settlement in 2022 over allegations Google extracted face templates from uploaded photos without BIPA consent. Each claimant was estimated to receive between $200 and $400.
-
In effect
In re TikTok ($92M)
N.D. Ill. · Effective 2022-07-28 · In re TikTok, Inc. Consumer Privacy Litig., MDL No. 2948 (N.D. Ill. 2022)
TikTok agreed to a $92 million multi-district settlement in 2021 (final approval July 2022) over claims it collected facial geometry, voiceprints, and biometric identifiers from minor and adult users without BIPA consent — among the first major social-media settlements covering algorithmic face/voice analysis on short-form video.
-
Blocked / in litigation
xAI v. Harwood (Grok NCII Counter-Suit 2026)
United States · Effective 2026-07-14 · xAI Corp. v. Terry Harwood, N.D. Tex. (Dallas Div.), filed July 14, 2026
xAI Corp. (the company behind the Grok AI chatbot, formerly operating as 'X.AI') filed a civil lawsuit on July 14, 2026 in the Northern District of Texas against Terry Harwood, a South Carolina man. The lawsuit alleges Harwood opened two Grok accounts between December 8, 2025 and February 18, 2026, uploading non-sexual photos of adults and minors and manipulating Grok into generating sexually explicit deepfake images — bypassing the system's safety guardrails. xAI seeks unspecified monetary damages and a permanent ban on Harwood from all xAI products. Harwood was separately arrested on February 26, 2026 on criminal charges of sexual exploitation of a minor. The case is notable as one of the first civil lawsuits filed by an AI company against a user for misusing the AI system to generate harmful content, rather than the more common pattern of a victim suing the AI company. xAI disclosed it suspended 52,222 accounts and filed 73,604 NCMEC reports related to Grok deepfake abuse in 2026, leading to at least 244 arrests.
-
Blocked / in litigation
Florida AG v. OpenAI (AI safety, minors)
United States · Effective 2026-06-01 · State of Florida ex rel. Uthmeier v. OpenAI LLC et al. (Highlands County 10th Jud. Cir., June 1, 2026; removed to S.D. Fla. July 2, 2026)
Florida Attorney General James Uthmeier filed the first-in-nation state-led lawsuit against OpenAI on June 1, 2026, in Highlands County Circuit Court, alleging ChatGPT was deceptively marketed to minors despite known safety risks. The 10-count complaint cites specific harms including the death of 16-year-old Adam Raine, who died by suicide following extensive ChatGPT conversations, and the alleged use of ChatGPT by the accused Florida State University mass shooter. OpenAI LLC and CEO Sam Altman (named personally) removed the case to federal court before Judge Aileen Cannon in Fort Pierce on July 2, 2026. Florida has moved to remand; the jurisdictional battle is ongoing.
-
In effect
Final Rule: Collection of Biometric Data From Aliens Upon En
United States · Effective 2025-12-26 · Final Rule: Collection of Biometric Data From Aliens Upon Entry to and Departure From the United States
This DHS/CBP final rule authorizes facial-biometric collection from all noncitizens on entry and exit at airports, seaports and land ports, removing prior exemptions and expanding to new travel modalities.
-
In effect
FBI 2024 Elder Fraud Report
United States · Effective 2025-04-29 · FBI IC3 2024 Elder Fraud Report (Apr. 29, 2025)
The FBI's annual Elder Fraud Report — published April 2025 for calendar year 2024 — documented $4.885 billion in losses by Americans 60+, with AI voice cloning, AI-driven romance and pig-butchering scams, and tech-support fraud identified as fastest-growing vectors. The report is the principal federal basis for AI elder-fraud policy and enforcement priorities.
-
In effect
FBI IC3 AI fraud PSA
United States · Effective 2024-12-03 · FBI IC3 PSA I-120324-PSA (Dec. 3, 2024)
The FBI's Internet Crime Complaint Center warned that criminals are using generative AI for phishing, impersonation, romance scams, investment fraud, and synthetic identity creation — and gave concrete defenses, like asking a 'secret word' on suspicious family calls. The PSA underpins FBI investigative priority and informs federal AI-fraud charging decisions.
-
In effect
Treasury AI Cyber Report (Fin. Services)
United States · Effective 2024-03-27 · Treasury Report (March 2024)
Treasury released a sector-wide report outlining AI-specific cybersecurity risks facing banks and financial institutions, the gap between large and small firms in AI-fraud defense, and supervisory expectations for AI-driven fraud, deepfakes, and prompt-injection attacks.
-
In effect
TSA Facial Comparison Technology (CAT-2 / Traveler Verificat
United States · Effective 2023-01-01 · TSA Facial Comparison Technology (CAT-2 / Traveler Verification Service)
TSA uses CAT-2 camera units at 350+ airport checkpoints to compare a live photo of a traveler to their ID photo (or to a CBP TVS gallery), with signage stating participation is voluntary and travelers may decline.
-
Blocked / in litigation
Doe v. GitHub (Copilot)
N.D. Cal. · Effective 2022-11-03 · Doe 1 v. GitHub, Inc., No. 4:22-cv-06823 (N.D. Cal.)
Anonymous software developers sued GitHub, Microsoft, and OpenAI in November 2022, alleging GitHub Copilot trained on their open-source code in violation of open-source licenses (which require attribution) and DMCA § 1202. After significant attrition of claims, a narrowed case survives.
-
In effect
OSTP AI Bill of Rights Blueprint
United States · Effective 2022-10-04 · OSTP Blueprint (October 2022)
The Blueprint laid out five non-binding principles for protecting Americans from automated systems: safe and effective systems, algorithmic discrimination protections, data privacy, notice and explanation, and human alternatives. It remains the most widely cited federal articulation of AI rights and is referenced by state AI laws.
-
In effect
Simplified Arrival Facial Biometric Comparison at All U.S. I
United States · Effective 2022-06-01 · Simplified Arrival Facial Biometric Comparison at All U.S. International Airports
CBP completed nationwide deployment of Simplified Arrival, which photographs international arrivals at airport inspection points and matches faces against government passport/visa galleries, with opt-out for U.S. citizens.
-
In effect
CBP Biometric Facial Comparison at Cruise Seaports
United States · Effective 2020-01-01 · CBP Biometric Facial Comparison at Cruise Seaports
CBP runs biometric facial comparison at roughly 11 U.S. cruise seaports (including Miami and Port Everglades), scanning disembarking passengers' faces against passport/visa photos with a U.S.-citizen opt-out.
-
Blocked / in litigation
Chatrie v. United States (Fourth Amendment protection for lo
United States · Chatrie v. United States (Fourth Amendment protection for location data / geofence warrants)
The U.S. Supreme Court ruled that people have a Fourth Amendment expectation of privacy in smartphone location data, holding that government access to such data (including via geofence warrants) is a search requiring constitutional protection.
-
Proposed / pending
Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757)
United States · Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757)
The U.S. House passed H.R. 7757 (267-117), imposing obligations on AI chatbot providers and online platforms to protect minors, including AI disclosure, crisis resources, use-break prompts, and policies against sexual exploitation and age-restricted content.
-
Proposed / pending
Traveler Privacy Protection Act of 2025 (S.1691)
United States · Traveler Privacy Protection Act of 2025 (S.1691)
This pending bipartisan Senate bill would guarantee travelers the right to opt out of TSA facial recognition at airports, bar worse treatment for opting out, and limit retention and secondary use of face data.
-
Proposed / pending
Stop Spying Bosses Act (Senate, 2026)
United States · Stop Spying Bosses Act, introduced June 18, 2026, U.S. Senate (Markey/Schatz/Booker et al.)
The Stop Spying Bosses Act, introduced June 18, 2026 in the U.S. Senate by Senators Markey, Schatz, and Booker, would sharply limit what data employers can collect on workers and how they can use it. Under the bill, employers could only collect data strictly necessary for a defined legitimate work purpose, and would be prohibited from monitoring union activity, political or religious views, immigration status, off-duty conduct, or health information. Biometric data collection — fingerprints, voiceprints, iris scans, facial maps, gait patterns — would require express consent and a legitimate work purpose. The bill would also prohibit using collected data to predict worker behavior, emotions, or beliefs unrelated to job performance. Companion legislation is the Senate No Robot Bosses Act (also introduced June 18, 2026). Senate companion to the House-side No Robot Bosses Act (HB 6371).
-
Proposed / pending
FTC Commercial Surveillance ANPR
United States · 87 Fed. Reg. 51273
The FTC's advance notice of proposed rulemaking on 'commercial surveillance and data security' asked whether to write rules limiting how companies collect data, train AI models on consumers, and use automated decision-making. The proceeding is technically open but has not advanced to a notice of proposed rulemaking.
-
Proposed / pending
DEFIANCE Act (deepfake-porn civil suits)
United States · S. 1837, 119th Cong. (DEFIANCE Act)
This bill would let victims of sexually explicit AI deepfakes sue the people who create or share them, with damages starting around $150,000. The Senate passed it unanimously on January 13, 2026 — the second time it has done so — but as of June 2026 it is still awaiting action in the House and is not yet law.
-
Proposed / pending
NO FAKES Act of 2025
United States · S.1367, 119th Congress (2025–2026)
Creates the first federal individual right against unauthorized AI-generated digital replicas of a person's image, likeness, or voice. Provides a right to subpoena online platforms for data about unauthorized deepfakes and establishes a DMCA-style notice-and-takedown procedure. Seniors and others whose voices are cloned without consent for use in grandparent or impersonation scams would have a direct cause of action against the parties responsible.
-
Proposed / pending
AI Scam Prevention Act
United States · S.3495, 119th Congress (2025–2026)
Prohibits using artificial intelligence to impersonate any person — family member, government official, or business — with intent to defraud. Codifies and expands the FTC's existing rule against impersonating government or business officials and updates definitions to include text messages, video conference calls, and AI-generated or prerecorded voice. Sen. Klobuchar's press release explicitly cited grandparent scams where criminals clone a grandchild's voice to defraud elderly relatives as a primary motivation.
-
Proposed / pending
AI Fraud Accountability Act
United States · S.3982, 119th Congress (2025–2026)
Amends the Communications Act of 1934 to create a new criminal offense for using a realistic digital impersonation in interstate or foreign communications with intent to defraud a person of money or things of value. Establishes extraterritorial jurisdiction — critical because many AI scam operations targeting American seniors originate overseas. Empowers the FTC with civil enforcement authority and directs NIST to develop best practices. Explicitly endorsed by AARP and the 60 Plus Association because of the devastating toll on seniors.
-
Proposed / pending
AI Fraud Accountability Act (House)
United States · H.R.7786, 119th Congress (2025–2026)
House companion to S.3982; criminalizes the use of realistic digital impersonation tools in interstate or foreign communications with fraudulent intent. Includes extraterritorial jurisdiction to reach foreign-based AI scam operations that frequently target American seniors. Buchanan's press release explicitly stated that the bill responds to 'a disturbing rise in AI-generated voice clones' used to defraud families including older adults.
-
Expired
APRA AI provisions (dead)
United States · APRA Discussion Draft (Apr. 2024) — pulled from markup June 27, 2024
The American Privacy Rights Act discussion draft (April 2024) included algorithmic impact assessment requirements. It was pulled from House markup in June 2024 — the last serious federal ADMT framework before the current 2026 federal drafts.
State consumer data privacy rules (160)
-
In effect
Washington SHB 1672 (employee monitoring notice, ADS restrictions, emotion AI ban)
Washington · Effective 2026-07-01 · Wash. SHB 1672 (2025 Session), effective July 1, 2026
Washington SHB 1672, effective July 1, 2026, is one of the most comprehensive U.S. employer monitoring laws. Employers must give employees 15 calendar days' written notice before any monitoring begins or before any change to monitoring. Notice must specify what is monitored, the method used, the purpose, who can access the data, and how long it is retained. The law prohibits off-duty monitoring, monitoring in private spaces (bathrooms, locker rooms), and monitoring personal vehicles. It restricts AI-based emotion recognition, gait recognition, and facial recognition in employment-related decisions. Employers must conduct impact assessments before deploying automated decision systems and must provide human oversight of ADS-driven performance evaluations. Employees have a private right of action with damages of at least $500 per violation plus attorney fees. Civil penalties may reach $10,000 per violation. The law applies to any employer with one or more Washington employees, including remote employees of out-of-state companies.
-
In effect
CA CPPA ADMT Regs
CA · Effective 2026-01-01 · 11 Cal. Code Regs. §§ 7200-7232
California's privacy agency finalized binding regulations governing automated decision-making and AI used to make significant decisions about Californians — including hiring, housing, education, healthcare, financial services, and ads to minors. Consumers gain rights to pre-use notice, opt-out, and access to information about how AI made the decision.
-
In effect
CCPA/CPRA + ADMT Regulations
California · Effective 2026-01-01 · Cal. Civ. Code § 1798.100 et seq.; Cal. Code Regs. tit. 11, div. 6
California's main privacy law gives consumers rights to know, delete, correct, and opt out of the sale or sharing of their personal information. New regulations finalized in 2025 add rights around automated decision-making technology (ADMT): businesses using ADMT for significant decisions (jobs, housing, credit, healthcare) must give pre-use notice, let people opt out, and provide access to how decisions were made.
-
In effect
Tohono O'odham Research Code
Tohono O'odham Nation · Effective 2013-05-23 · 17 Tohono O'odham Code ch. 8 (Resolution No. 13-165, May 23, 2013)
Tohono O'odham Nation's research code establishes a tribal IRB with sole authority to control publication of all research, disclosures, and findings on tribal land. Vests ownership of all research-derived work product and copyrights — including AI/data products — with the Nation.
-
In effect
Texas CUBI (2009)
TX · Effective 2009-09-01 · Tex. Bus. & Com. Code §503.001 (2009)
Enacted in 2009, the Texas Capture or Use of Biometric Identifier Act (CUBI) was the second state biometric privacy law in the country (after Illinois BIPA). It requires consent before commercial biometric capture and caps damages at $25,000 per violation. AG Paxton used CUBI to secure a $1.4B Meta settlement (2024) and $1.375B Google settlement (2025) — making it the most-recovered state biometric statute.
-
In effect
IL BIPA (2008, first-in-nation biometric law)
IL · Effective 2008-10-03 · 740 ILCS 14/1 et seq. (P.A. 95-994, 2008; amended P.A. 103-0769, 2024)
Signed October 3, 2008, the Illinois Biometric Information Privacy Act (BIPA) was the first state biometric privacy law in the United States — and remains the most powerful. Its private right of action and statutory damages ($1,000 negligent / $5,000 intentional per violation) have driven over $1.5B in class-action settlements, including the $650M Facebook face-tagging settlement (2021) and the $725M TikTok settlement (2021). 2024 amendment (P.A. 103-0769) limited claims to one accrual per person per collection method. Still in effect 2026.
-
In effect
BIPA
Illinois · Effective 2008-10-03 · 740 ILCS 14/1 et seq.
The strongest US biometric privacy law: companies must get written consent before collecting fingerprints, face scans, voiceprints, or other biometrics, publish retention/destruction policies, and cannot sell biometric data. Individuals can sue directly and recover $1,000–$5,000 per violation, which has produced major settlements against facial recognition and AI companies.
-
Enacted (not yet in effect)
Illinois Children's Social Media Safety Act — algorithmic recommendations ban for minors
Illinois · Effective 2028-01-01 · Illinois HB5511, Children's Social Media Safety Act (signed July 31, 2026; effective January 1, 2028)
Illinois's Children's Social Media Safety Act, signed by Governor Pritzker on July 31, 2026, bans social media platforms from using algorithmic content recommendations for users they know to be minors — restricting feeds to only content the user searched for or from accounts the user chose to follow. It requires operating system providers to verify user age at account setup and share an age-category signal with platforms. It mandates default privacy settings for minors that limit location sharing, nighttime notifications (banned 10 pm – 7 am), and digital currency features. The Illinois Attorney General may enforce violations with civil penalties up to $50,000 per violation. The law takes effect January 1, 2028.
-
Enacted (not yet in effect)
NJ Fair Pricing and Transparency Act S3952 (2026)
NJ · Effective 2027-07-23 · N.J. S3952 / A3929 (222nd Legislature, 2026) — signed July 23, 2026; effective July 23, 2027
Governor Meredith Sherrill signed New Jersey S3952/A3929, the Fair Pricing and Transparency Act, on July 23, 2026, making New Jersey the third state to ban surveillance-based grocery pricing, following Maryland and Connecticut. The law prohibits retail food stores from setting individualized prices based on a customer's personal data, purchasing history, or tracked attributes. It also imposes a one-year moratorium on electronic shelf labels (ESLs). Effective July 23, 2027. Notably, the law includes a private right of action for injured consumers — the first state surveillance-pricing law to do so.
-
In effect
PR Ley 163-2026 / P. del S. 441 (Image Rights)
Puerto Rico · Effective 2026-08-03 · Ley 163-2026 (P. del S. 441, 19th Leg. Assembly); signed August 3, 2026
Puerto Rico Law 163-2026 (P. del S. 441) expands the island's right-of-image statute (Law 139-2011) to expressly cover AI-generated deepfakes and voice clones. Creates civil causes of action when someone's appearance, voice, gestures, movements, or other identifiable attributes are synthetically generated, cloned, simulated, or altered without consent. Signed by Governor Jenniffer González Colón on August 3, 2026.
-
In effect
Maine LD 61 (employer surveillance disclosure & prohibition)
Maine · Effective 2026-07-14 · Maine P.L. 2025, Ch. 524 (LD 61 / H.P. 25), 26 M.R.S. § 620-A, effective July 14, 2026
Maine's LD 61 (P.L. 2025, Ch. 524) requires employers to notify employees before any surveillance begins and to disclose surveillance practices to job applicants during interviews. Employers must provide annual written notice to all current employees describing what is monitored, how, and why. Employees may refuse installation of monitoring software on their personal devices. The law prohibits audiovisual monitoring in an employee's home, personal vehicle, or personal property. Civil fines of $100–$500 apply per violation. The law covers all public and private employers in Maine. Effective July 14, 2026.
-
In effect
Virginia § 15.2-1723.2 (facial recognition by local law enforcement, eff. July 1, 2026)
Virginia · Effective 2026-07-01 · Va. Code § 15.2-1723.2 (2026), effective July 1, 2026
Virginia Code § 15.2-1723.2, effective July 1, 2026, imposes statewide binding requirements on how local law enforcement agencies in Virginia may use facial recognition technology. Agencies wishing to use facial recognition must publicly post a policy meeting or exceeding the State Police model, publish annual use reports by April 1 each year, and give 30 days written notice to their governing body before procuring the technology. The law bans real-time tracking of identified individuals in public spaces and prohibits creating a live-video database using facial recognition. All searches must be logged and violations by operators constitute a Class 3 misdemeanor. The law applies to all Virginia localities, including Northern Virginia regional law enforcement systems.
-
In effect
CPPA Honda ADMT settlement
CA · Effective 2025-03-12 · CPPA, In re American Honda Motor Co. (Mar. 12, 2025)
California's privacy agency fined American Honda $632,500 — its first public enforcement action — for making consumers go through hoops to exercise opt-out and access rights, including against automated decision-making and data-broker sharing. The agency signaled that ADMT (automated decision-making technology) compliance is now a top enforcement priority for AI-driven consumer profiling.
-
In effect
CA AB 1008 (CCPA + AI)
CA · Effective 2025-01-01 · Cal. Civ. Code § 1798.140; AB 1008 (Stats. 2024, ch. 853)
California clarified that personal information remains protected by the CCPA even when it is embedded in or generated by AI systems — including model weights and AI-generated synthetic content about a person. Closes a loophole AI developers had used to argue training data and model outputs fell outside privacy law.
-
In effect
An Order Establishing the Maine Artificial Intelligence Task
Maine · Effective 2024-12-20 · An Order Establishing the Maine Artificial Intelligence Task Force
Governor Janet Mills' executive order creates a 21-member Maine Artificial Intelligence Task Force to study AI's implications for the state, protect residents from harmful AI uses, and identify opportunities for public-sector AI deployment, with a final report due to the Governor and Legislature by October 31, 2025.
-
In effect
NCAI Res. NC-24-008 (Digital Sovereignty)
National Congress of American Indians · Effective 2024-11-15 · NCAI Resolution #NC-24-008 (2024)
Defines tribal digital sovereignty as tribes' sovereign authority over physical and virtual network infrastructure and data — acquisition, storage, transmission, access, use. Explicitly notes that AI tools can circumvent tribal data collection protocols.
-
In effect
NYDFS CL 7 (2024) — Insurance AI Anti-Discrimination
New York · Effective 2024-07-11 · NYDFS Insurance Circular Letter No. 7 (2024) (July 11, 2024)
New York's Department of Financial Services issued Insurance Circular Letter No. 7 on July 11, 2024, establishing the most substantive state insurance AI rule in the country. Going beyond the NAIC Model Bulletin adopted by 24+ states, NYDFS CL No. 7 requires insurers to conduct a comprehensive 'proxy assessment' before using any AI system (AIS) or external consumer data source (ECDIS) in underwriting or pricing — and prohibits any such use unless the insurer can demonstrate the system does not produce unfair or unlawful discrimination against protected classes. When an AI-influenced adverse underwriting decision is made, the insurer must provide written notice within 15 days of the decision. Governance, documentation, and DFS market-conduct examination requirements apply immediately.
-
In effect
Cherokee Nation EO 2024-07-CTH
Cherokee Nation (OK) · Effective 2024-07-01 · Cherokee Nation Executive Order 2024-07-CTH
Executive order from Principal Chief Hoskin establishing the Data Sovereignty and Governance Task Force. Charged with anticipating emerging technologies, safeguarding citizens' sensitive personal data, and defining Cherokee Nation data sovereignty. Produced the AI/data sovereignty/cybersecurity report that led to the 2025 AI policy.
-
In effect
NCAI Res. SAC-22-026 (Emerging Tech)
National Congress of American Indians · Effective 2022-11-04 · NCAI Resolution #SAC-22-026 (2022)
NCAI resolution addressing how emerging technologies including AI can circumvent tribal data collection protocols without proper consent. Reinforces tribal authority over data flowing through AI systems.
-
In effect
MN drone-warrant law (2020)
Minnesota · Effective 2020-08-01 · Minn. Stat. § 626.19
Minnesota requires police to get a search warrant before using a drone, with narrow exceptions, and to publish an annual public report listing every drone deployment, purpose, and cost. The annual transparency requirement is among the strongest in any state drone law.
-
In effect
CARE Principles (Indigenous Data)
Global Indigenous Data Alliance · Effective 2019-09-01 · Carroll et al., Data Science Journal 19:43 (2020); GIDA (2019)
Indigenous-authored complement to the FAIR data principles. Establishes that Indigenous data must be governed under Indigenous authority, used for Collective benefit, and handled with Responsibility and Ethics. Widely referenced in U.S. tribal research codes and increasingly in federal agency guidance.
-
In effect
NCAI Res. KAN-18-011 (IDS)
National Congress of American Indians · Effective 2018-06-04 · NCAI Resolution #KAN-18-011 (2018)
First collective NCAI resolution supporting U.S. tribes' exercise of Indigenous data sovereignty — the principle that tribes have inherent authority over data about their citizens, lands, and resources. Foundation document for tribal restrictions on AI training data and government data sharing.
-
In effect
NBDC Genomic Sovereignty
Native BioData Consortium · Effective 2018-01-01 · Native BioData Consortium governance protocols (est. 2018)
First U.S. Indigenous-led biorepository. Keeps Indigenous biological samples and derived genomic data under Indigenous governance and consent, with privacy-preserving protocols to prevent extractive AI/genomic research without tribal authorization. Based on the Cheyenne River Sioux Reservation in South Dakota.
-
In effect
Plateau Peoples TK/BC Labels
Plateau Peoples' Web Portal (Multi-Tribal) · Effective 2015-01-01 · Plateau Peoples' Web Portal — multi-tribal TK/BC Labels initiative
Six Plateau tribes — Colville, Umatilla, Warm Springs, Yakama, Spokane, and Coeur d'Alene — jointly implement Local Contexts Traditional Knowledge and Biocultural Labels on digital cultural-heritage collections. A working Indigenous data sovereignty mechanism applicable to AI training data: labels travel with the data and assert community-defined access and use rules.
-
In effect
TN drone trespass / FFUSA
Tennessee · Effective 2014-07-01 · Tenn. Code Ann. §§ 39-13-609, 39-13-902 to -905
Tennessee prohibits warrantless drone surveillance by law enforcement, makes it a misdemeanor for any person to capture images of an individual or private property from a drone without consent, and bars using drones to surveil critical infrastructure or fireworks/sporting events.
-
In effect
IL Drone Surveillance Act
Illinois · Effective 2014-01-01 · 725 ILCS 167
Illinois requires police to obtain a search warrant before using a drone to gather information, subject to narrow exceptions (terrorism, search-and-rescue, crime-scene reconstruction). The 2023 Drones as First Responders amendments (HB 3902) added regulated exceptions for crowd surveillance and emergency response.
-
In effect
TX HB 912 (2013 drone privacy)
Texas · Effective 2013-09-01 · Tex. Gov't Code Ch. 423
One of the broadest state drone-privacy laws: it is illegal in Texas to use a drone to capture images of a person or private real property without consent, subject to 19 enumerated exceptions (newsgathering, mapping, etc.). Texas's drone-privacy chapter was partially struck down in NPPA v. McCraw (2022) on First Amendment grounds, but most provisions remain in force.
-
In effect
OR weaponized-drone ban
Oregon · Effective 2013-07-29 · Or. Rev. Stat. §§ 837.300–837.380
Oregon prohibits anyone from operating a weaponized drone, requires law-enforcement drones to be authorized for specific missions, and provides a civil action for property owners whose airspace is repeatedly invaded by drones flying below 400 feet.
-
In effect
FL drone surveillance act
Florida · Effective 2013-07-01 · Fla. Stat. §§ 934.50, 330.41
Florida bars law enforcement from using drones for surveillance without a warrant or specific exception, and (after SB 92/2015 and SB 44/2021 amendments) prohibits anyone from using a drone to capture images of private property or people on private property in violation of reasonable expectations of privacy. SB 44 (2021) also tightened state preemption over local drone ordinances.
-
In effect
VA warrantless drone ban
Virginia · Effective 2013-04-03 · Va. Code § 19.2-60.1
Virginia was the first state to limit law-enforcement drone use, imposing a two-year moratorium in 2013 and then permanently barring police use of drones without a warrant or specific exception (search-and-rescue, training, surveillance of an Amber-alert subject). Evidence from unlawful drone surveillance is inadmissible.
-
In effect
Local Contexts TK/BC Labels
Local Contexts · Effective 2010-01-01 · Local Contexts TK Labels (2010); BC Labels (2018)
Indigenous-authored digital provenance labels that travel with cultural data to enforce community-set rules on access, attribution, and reuse. Foundational tool for asserting Indigenous data sovereignty against extractive AI training datasets. TK Labels launched 2010; BC Labels 2018. Adopted by 200+ Indigenous communities globally.
-
In effect
Navajo Nation Privacy Act
Navajo Nation · Effective 2005-01-01 · 2 N.N.C. § 81 et seq.
Navajo Nation's foundational privacy law. Regulates access to records held by Navajo government offices, enumerates 22 categories of public records, and establishes privacy protections governing release of citizen and government data — the legal backbone for any AI system processing Navajo citizen data.
-
In effect
Navajo NNHRRB
Navajo Nation · Effective 1996-01-01 · Navajo Nation Human Research Review Board (est. 1996)
Navajo Nation's IRB. All human-subjects research on the Navajo Nation — including any AI or data-driven studies — must be approved by NNHRRB and certify compliance with the Navajo Nation Privacy Act before data collection or publication.
-
Enacted (not yet in effect)
Vermont Data Broker Law (H.211)
Vermont · Vt. H.211 (2025-2026 biennium); signed June 16, 2026
Vermont enacted a law tightening rules on data brokers — companies that buy and sell people's personal information, the same data that feeds profiling and AI systems. Signed by Gov. Phil Scott on June 16, 2026, it strengthens Vermont's existing data-broker regulation and personal-information protections.
-
Enacted (not yet in effect)
Alabama Personal Data Protection Act (privacy / profiling opt-out)
Alabama · Effective 2027-05-01 · 2026 Ala. Acts (HB 351), Alabama Personal Data Protection Act
Alabama's comprehensive consumer privacy law gives residents the right to tell businesses to stop using their personal data for profiling that drives automated decisions with major consequences. This covers decisions about things like lending and credit, housing, insurance, education, employment, healthcare, criminal justice, and access to basic necessities. Consumers can also opt out of targeted advertising and the sale of their data. The Alabama Attorney General enforces the law, and there is no individual lawsuit right.
-
Enacted (not yet in effect)
Oklahoma SB 546 (opt out of profiling for significant decisions)
Oklahoma · Effective 2027-01-01 · Oklahoma Consumer Data Privacy Act, SB 546 (2026), eff. Jan. 1, 2027
Oklahoma's comprehensive consumer privacy law gives residents the right to tell a business to stop using their personal data for profiling that drives decisions carrying legal or similarly significant effects, such as those affecting credit, employment, or housing. Businesses must also run and document data protection assessments before high-risk processing, including risky profiling. The law is enforced only by the Attorney General; there is no consumer lawsuit right.
-
In effect
CT SB 1295 (AI training-data disclosure)
Connecticut · Effective 2026-07-01 · 2025 Conn. Public Acts 25-153 (SB 1295), amending Conn. Gen. Stat. Sec. 42-520
This amendment to Connecticut's Data Privacy Act adds a first-in-the-nation transparency rule about AI training data. Businesses must state in their privacy notice whether they collect, use, or sell personal data to train large language models. The disclosure applies regardless of how the trained model is ultimately used. Like the rest of the privacy act, it is enforced by the Attorney General under Connecticut's consumer protection law.
-
In effect
SUNY Systemwide Artificial Intelligence Policy
State University of New York (SUNY) · Effective 2026-04-30 · SUNY Systemwide Artificial Intelligence Policy
SUNY's Board of Trustees approved a systemwide AI policy requiring all 64 campuses to adopt AI governance, bias evaluation, data-privacy safeguards, and heightened oversight of high-risk systems affecting students by December 31, 2026.
-
In effect
Executive Order N-5-26 - Trusted AI Procurement
California · Effective 2026-03-30 · Executive Order N-5-26 - Trusted AI Procurement
This newer California executive order directs DGS and CDT to develop trust-and-safety certifications for state AI contracting (covering CSAM/NCII, harmful bias, and civil-rights violations), reforms to bar contracting with entities that unlawfully undermine privacy or civil liberties, and CDT guidance on watermarking AI-generated media.
-
In effect
VT AG Clark
VT · Effective 2026-03-24 · VT AG Clark — 17-State Coalition Letter on Data Broker AI Surveillance Loophole (2026-03-24)
Joined 17-state coalition urging Congress to close the loophole letting federal agencies purchase commercial data for AI surveillance, bypassing Fourth Amendment protections.
-
In effect
GenAI Tools and Acceptable Use Policy
Maine · Effective 2026-03-06 · GenAI Tools and Acceptable Use Policy
The Maine Office of Information Technology's generative AI policy (superseding the earlier GenAI moratorium) guides responsible use of GenAI on state IT infrastructure, requiring compliance with data classification standards, prohibiting confidential data inputs to public AI systems, and holding users accountable for AI outputs.
-
In effect
AI Systems Code of Ethics and Minimum Risk Management and Go
Texas · Effective 2026-03-01 · AI Systems Code of Ethics and Minimum Risk Management and Governance Standards (1 TAC Chapter 219)
Under Government Code 2054.702 and SB 1964, the Texas Department of Information Resources adopted a statewide AI code of ethics built on seven principles (human oversight, fairness, accuracy, redress, transparency, privacy, security) plus minimum risk-management standards for heightened-scrutiny AI systems.
-
In effect
Artificial Intelligence Framework for Utah P-12 Education: G
Utah State Board of Education (USBE) · Effective 2026-03-01 · Artificial Intelligence Framework for Utah P-12 Education: Guidance on the Use of AI in Our Schools
Utah's state board of education issued an AI framework guiding students, staff, and communities on responsible and prohibited use of generative AI, with special considerations for safety, security, and privacy.
-
In effect
Attorney General Tong Memorandum on Artificial Intelligence
Connecticut · Effective 2026-02-25 · Attorney General Tong Memorandum on Artificial Intelligence
Connecticut AG William Tong issued a memorandum explaining how existing Connecticut civil rights, data privacy and security, consumer protection (unfair trade practices), and antitrust laws already apply to AI systems, signaling enforcement priorities.
-
In effect
Attorneys General Derek Brown and Jeff Jackson Launch Nation
Utah · Effective 2026-01-17 · Attorneys General Derek Brown and Jeff Jackson Launch Nationwide Bipartisan AI Task Force
Utah's Attorney General co-launched a nationwide bipartisan attorneys-general task force to identify emerging AI harms and develop safeguards AI developers should follow to protect the public, especially children.
-
In effect
Attorney General Ellison releases consumer alert on DHS' digital surveillance an
MN · Effective 2026-01-15 · Attorney General Ellison releases consumer alert on DHS' digital surveillance and how to protect your privacy (2026-01-15)
Ellison alert and online reporting tool warn residents about AI-powered ID/tracking using biometric, app, and vehicle data; recommends disabling FaceID/TouchID. Follows expert filings in Kohls v. Ellison deepfake case.
-
In effect
Executive Order 26-02 (Strategic Framework for Integration o
Missouri · Effective 2026-01-13 · Executive Order 26-02 (Strategic Framework for Integration of Artificial Intelligence within State Government Operations)
Governor Mike Kehoe ordered the Office of Administration to develop a strategic framework for integrating AI into Missouri state government, prioritizing data privacy and security, human decision-making, transparency, accountability, and data quality.
-
In effect
AI Model Policy for Ohio Districts and Schools
Ohio Department of Education and Workforce · Effective 2026-01-06 · AI Model Policy for Ohio Districts and Schools
Ohio's education department released a state model AI policy that all public, community, and STEM schools must adopt (or customize) a formal AI policy from by July 1, 2026, covering student/staff use, privacy, ethics, and vendor evaluation.
-
In effect
Kentucky Consumer Data Protection Act
Kentucky · Effective 2026-01-01 · 2024 Ky. Acts (HB 15); KRS ch. 367
Kentucky's privacy law took effect January 1, 2026, giving residents rights to access, correct, delete, and copy their personal data, and to opt out of data sales and targeted advertising. Businesses need opt-in consent for sensitive data including biometrics.
-
In effect
RI Privacy Law (RIDTPPA)
Rhode Island · Effective 2026-01-01 · R.I. Gen. Laws § 6-48.1 (2024)
Rhode Island residents can access, correct, delete, and port their data, and opt out of targeted advertising, data sales, and profiling. The Attorney General enforces with fines up to $10,000 per violation and — unusually — no cure period.
-
In effect
Indiana Consumer Data Protection Act
Indiana · Effective 2026-01-01 · 2023 Ind. Acts P.L. 94-2023 (SB 5); I.C. 24-15-1 et seq.
Indiana's privacy law, effective January 1, 2026, gives residents rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, data sales, and profiling. Enforced exclusively by the Attorney General with a permanent 30-day cure period.
-
In effect
California SB 361 (data brokers must report sharing data with GenAI developers)
California · Effective 2026-01-01 · Cal. Civ. Code 1798.99.82 (SB 361, 2025)
This law expands what data brokers must reveal when they register each year with the California Privacy Protection Agency. Among the new disclosures, brokers must state whether, during the prior year, they sold or shared consumers' personal information with developers of generative AI systems. The aim is to give the public and regulators visibility into how personal data flows into AI training and development.
-
In effect
AB 2013 (Training Data Transparency)
California · Effective 2026-01-01 · Cal. Civ. Code §§ 3110–3111 (AB 2013, Stats. 2024)
Developers of generative AI systems made available to Californians must publicly post documentation about the datasets used to train their models, including sources, whether they contain personal information or copyrighted material, and time periods of collection. Applies to systems released or substantially modified since January 1, 2022.
-
In effect
Guidance for the Safe and Effective Use of Artificial Intell
California Department of Education · Effective 2026-01-01 · Guidance for the Safe and Effective Use of Artificial Intelligence in California Public Schools
California's education department issued voluntary guidance for K-12 districts covering human-centered AI, AI literacy, equitable access, academic integrity, data privacy (FERPA/COPPA/CCPA/SOPIPA), and procurement.
-
In effect
Acceptable Use Policy for Artificial Intelligence
Mississippi · Effective 2025-11-25 · Acceptable Use Policy for Artificial Intelligence
Mississippi ITS adopted an AI acceptable-use policy (implementing EO 1584) setting ten guiding principles including human oversight of AI decisions, bias testing, data-protection restrictions, and a prohibition on deepfakes and using AI for final sensitive decisions.
-
In effect
Artificial Intelligence Guideline
North Dakota · Effective 2025-11-17 · Artificial Intelligence Guideline
North Dakota Information Technology's guideline outlines best practices for secure, private, and ethical use of AI, supplementing the state's AI Policy and requiring GRC risk assessment before AI business use.
-
In effect
New York Algorithmic Pricing Disclosure Act (personalized prices need a label)
New York · Effective 2025-11-10 · N.Y. Gen. Bus. Law 349-A (art. 22-A)
If a business sets the price of a product or service using an algorithm that draws on your personal data, and then shows that personalized price to you as a New York consumer, it has to tell you so with the notice: 'THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA.' The goal is to make personalized 'surveillance pricing' visible rather than hidden. The Attorney General enforces the rule and can seek up to $1,000 per violation after a cease-and-desist notice.
-
In effect
Commonwealth Office of Technology Enterprise Policy CIO-126:
Kentucky · Effective 2025-10-06 · Commonwealth Office of Technology Enterprise Policy CIO-126: Artificial Intelligence Policy
Kentucky's Commonwealth Office of Technology enterprise AI policy bans state agency use of high-risk AI systems, mandates human review before any consequential decision, and requires transparency disclaimers, bias controls, privacy protections, training, and vendor AI-use disclosure.
-
In effect
Montana MCDPA
Montana · Effective 2025-10-01 · Mont. Code Ann. §§ 30-14-2901 et seq. (SB 384, 2023; as amended by SB 297, 2025, eff. Oct. 1, 2025)
Montana's comprehensive consumer privacy law, strengthened by 2025 amendments, gives residents rights to access, correct, delete, and opt out of data processing. The SB 297 amendment removed the 'solely automated' qualifier for profiling opt-out, meaning consumers can now opt out of any automated decision-making that involves profiling with significant effects — not just fully automated decisions.
-
In effect
Maryland Online Data Privacy Act
Maryland · Effective 2025-10-01 · 2024 Md. Laws ch. 440 (SB 541); Md. Code Ann., Com. Law §§ 14-4601–14-4626
Maryland's privacy law is stricter than most: it prohibits processing sensitive personal data unless strictly necessary for the requested service. Consumers can access, correct, delete, and port their data, and opt out of automated profiling and targeted advertising. AG enforcement began April 2026.
-
In effect
Executive Order JML 25-109: Amended State Government's Use o
Louisiana · Effective 2025-09-29 · Executive Order JML 25-109: Amended State Government's Use of AI
Governor Jeff Landry's amended executive order requires Chief Information Officer or agency-head approval before any state agency uses AI, pauses AI procurement until December 15, 2025, mandates AI acquisition/information-management policies and an inventory of AI contracts and use cases, and restricts sensitive data inputs pending those policies.
-
In effect
Artificial Intelligence Acceptable Use Policy
Louisiana · Effective 2025-09-29 · Artificial Intelligence Acceptable Use Policy
Louisiana's Office of Technology Services policy governs employee AI use, prohibiting entry of confidential/restricted state data into commercial AI, barring AI from making independent consequential decisions, and requiring human verification, AI-content labeling, and use of only state-approved systems.
-
In effect
Attorney General Labrador Joins Bipartisan Coalition Urging
Idaho · Effective 2025-09-08 · Attorney General Labrador Joins Bipartisan Coalition Urging Tech Companies to Stop the Spread of Deepfake Nonconsensual Intimate Imagery
The Idaho Attorney General joined a 47-state coalition demanding that search engines and payment platforms adopt safeguards to curb AI-generated deepfake nonconsensual intimate imagery.
-
In effect
Attorney General Raoul Urges Tech Companies to Stop the Spre
Illinois · Effective 2025-08-26 · Attorney General Raoul Urges Tech Companies to Stop the Spread of Deepfake Nonconsensual Intimate Imagery
The Illinois Attorney General joined a bipartisan coalition of attorneys general pressing search engines and payment platforms to curb AI-generated deepfake nonconsensual intimate imagery, referencing Illinois's AI-generated CSAM and NCII law.
-
In effect
Attorney General Skrmetti Leads 44 States in Demanding Compa
Tennessee · Effective 2025-08-25 · Attorney General Skrmetti Leads 44 States in Demanding Companies End Predatory AI Interactions with Kids
Tennessee's Attorney General led a bipartisan coalition of 44 states in a demand letter to 12 major AI companies to implement safeguards against sexualized AI chatbot interactions with minors, applying consumer-protection authority to AI harms.
-
In effect
Attorney General Brenna Bird Warns of Deepfake Dangers as St
Iowa · Effective 2025-08-19 · Attorney General Brenna Bird Warns of Deepfake Dangers as Students Head Back to School
The Iowa Attorney General issued a consumer alert warning parents and schools that AI-generated deepfake images used to harass or bully students are criminal acts under state and federal law.
-
In effect
Attorney General Ken Paxton Investigates Meta and Character.
Texas · Effective 2025-08-18 · Attorney General Ken Paxton Investigates Meta and Character.AI for Misleading Children with Deceptive AI-Generated Mental Health Services
The Texas Attorney General issued Civil Investigative Demands to Meta AI Studio and Character.AI to determine whether their AI chatbots deceptively marketed themselves as mental-health tools to children in violation of Texas consumer-protection law.
-
In effect
Adoption and Usage of Artificial Intelligence: Guidelines an
Michigan · Effective 2025-08-09 · Adoption and Usage of Artificial Intelligence: Guidelines and Responsibilities
Michigan's Department of Technology, Management and Budget issued guidelines establishing responsibilities for ethical AI use across state agencies, requiring data-classification awareness and human-in-the-loop review of AI-generated content.
-
In effect
ND 12.1-17-07 (using a robot/AI to harass is a crime)
North Dakota · Effective 2025-08-01 · N.D. Cent. Code 12.1-17-07; 2025 N.D. Laws (HB 1429)
North Dakota updated its harassment law so that using a 'robot' to harass someone is itself a crime. A robot here means an artificial object or system that senses, processes, and acts using technology, including artificial intelligence. A person commits harassment if they use such a robot to engage in offensive conduct that serves no legitimate purpose.
-
In effect
ND 12.1-17-07.1 (stalking via robot/AI, e.g. tracking, is a crime)
North Dakota · Effective 2025-08-01 · N.D. Cent. Code 12.1-17-07.1; 2025 N.D. Laws (HB 1429)
North Dakota extended its stalking law to cover stalking carried out with a 'robot,' including artificial intelligence systems. This reaches conduct such as using a robot to track a person without authorization. The change makes clear that automated or AI-driven tools cannot be used as a workaround to stalk someone.
-
In effect
Artificial Intelligence (AI) Governance Policy, Standard, an
Idaho · Effective 2025-08-01 · Artificial Intelligence (AI) Governance Policy, Standard, and Guideline
Idaho ITS's enterprise AI governance policy establishes a risk-classification framework, oversight responsibilities, and implementation requirements for AI use across state agencies and departments.
-
In effect
Minnesota Consumer Data Privacy Act
Minnesota · Effective 2025-07-31 · 2024 Minn. Laws ch. 123 (HF 4757); Minn. Stat. §§ 325M.01–.21
Minnesota's privacy law gives residents data rights plus something unique: the right to question automated profiling decisions with significant effects — including the right to know why the decision was made and what would change the outcome. Full AG enforcement began February 2026.
-
In effect
Minnesota State systemwide Generative AI guidance and approv
Minnesota State (Minnesota State Colleges and Universities) · Effective 2025-07-03 · Minnesota State systemwide Generative AI guidance and approved-tools policy
Minnesota State issues systemwide generative-AI guidance authorizing secured tools like Microsoft Copilot, blocking services such as Otter.AI and Fireflies.AI for security, and ensuring system data is not used to train external AI models.
-
In effect
Tennessee Information Protection Act (opt out of automated profiling decisions)
Tennessee · Effective 2025-07-01 · Tenn. Code Ann. 47-18-3301 et seq. (TIPA); profiling opt-out at 47-18-3304
Tennessee's consumer privacy law gives state residents rights over how businesses handle their personal information, including the right to opt out of profiling that is carried out solely through automated processing and used to make decisions with legal or similarly significant effects. Businesses that act as controllers must also conduct and document data protection assessments for higher-risk processing activities, including certain profiling. The Tennessee Attorney General has exclusive enforcement authority, and there is no private right of action.
-
In effect
Generative AI Responsible Use (SS-25-001)
Georgia · Effective 2025-07-01 · Generative AI Responsible Use (SS-25-001)
The Georgia Technology Authority's enterprise standard requires executive-branch agencies to obtain GTA approval before procuring or using generative AI, keep humans in the loop reviewing GenAI output, disclose GenAI use, bar entry of PII/PHI without approval, maintain a GenAI inventory, and report incidents within 48 hours.
-
In effect
New AI Features for State of Alaska Employees - OIT Guidance
Alaska · Effective 2025-06-18 · New AI Features for State of Alaska Employees - OIT Guidance
Alaska's Office of Information Technology issued guidance for state employees using Microsoft 365 Copilot and Teams AI features, requiring them to review AI-generated content for accuracy and privacy, follow the ISP-172 acceptable-use policy, and recognize that Copilot-generated records may be subject to disclosure.
-
In effect
State of New Mexico: Generative AI Use Guidelines Policy (Ve
New Mexico · Effective 2025-06-01 · State of New Mexico: Generative AI Use Guidelines Policy (Version 1.0)
New Mexico's Department of Information Technology issued a signed policy leveraging the NIST AI Risk Management Framework to govern how executive agencies plan, develop, and deploy generative AI, including protection of non-public data.
-
In effect
Texas v. Google
TX · Effective 2025-05-09 · Texas v. Google — $1.375B Biometric and Location Data Settlement (2025-05-09)
Paxton resolved 2022 claims that Google unlawfully captured voiceprints and face geometry and tracked location/Incognito searches without consent, violating Texas CUBI and DTPA. Largest single-state privacy recovery from Google.
-
In effect
Texas v. Google ($1.375B)
TX · Effective 2025-05-09 · State of Texas v. Google LLC (Harrison Cty., Tex., May 9, 2025)
Texas AG Ken Paxton secured a $1.375 billion settlement from Google in May 2025 over voiceprint, faceprint, and Incognito-mode tracking claims under the Texas Capture or Use of Biometric Identifier Act and Deceptive Trade Practices Act. Largest single-state privacy recovery against a tech company.
-
In effect
HB 452 (Mental Health Chatbots)
Utah · Effective 2025-05-07 · Utah Code § 13-2c-101 et seq. (HB 452, 2025)
Utah regulates AI chatbots that act like therapists: suppliers must clearly disclose the chatbot is not human, may not advertise products mid-conversation without disclosure, and may not sell or share users' individually identifiable health information.
-
In effect
Policy on the Acceptable and Responsible Use of Artificial I
Illinois · Effective 2025-04-01 · Policy on the Acceptable and Responsible Use of Artificial Intelligence
The Illinois DoIT policy governs how state agencies under the Governor's jurisdiction may develop, deploy, and use AI systems, requiring each utilizing agency to designate an AI point of contact and inventory deployed AI systems within 30 days.
-
In effect
Generative Artificial Intelligence (AI) Policy (ENTERPRISE P
Iowa · Effective 2025-03-31 · Generative Artificial Intelligence (AI) Policy (ENTERPRISE PY-AI)
Iowa's enterprise generative-AI policy, issued under Iowa Administrative Code 129-8.4(8B), sets minimum requirements and prohibited uses for generative AI, mandating human review of AI outputs and disclosure of AI-generated code.
-
In effect
State of Wisconsin Acceptable Technology Use, Access, and Se
Wisconsin · Effective 2025-03-10 · State of Wisconsin Acceptable Technology Use, Access, and Security Policy (includes AI-use provisions)
The Wisconsin Department of Administration's enterprise technology policy governs acceptable use of state IT resources by executive-branch employees and incorporates guidance on the use of artificial intelligence.
-
In effect
UT System Policy IT0002 / procedure, Acceptable Use of Gener
University of Tennessee System · Effective 2025-03-01 · UT System Policy IT0002 / procedure, Acceptable Use of Generative AI
The University of Tennessee System's acceptable-use policy for generative AI bars entering FERPA/HIPAA-protected and confidential data into AI tools and requires independent verification and disclosure of AI-generated content.
-
In effect
Responsible AI Usage Policy (107-004-190)
Oregon · Effective 2025-02-11 · Responsible AI Usage Policy (107-004-190)
Oregon Enterprise Information Services establishes enterprise-wide governance for generative and agentic AI across executive-branch agencies, requiring AI adoption plans, human review of outputs, approval of new AI uses, and use of only approved tools.
-
In effect
Initial Report - Arkansas Artificial Intelligence and Analyt
Arkansas · Effective 2025-02-07 · Initial Report - Arkansas Artificial Intelligence and Analytics Center of Excellence
The Arkansas AI and Analytics Center of Excellence (Department of Shared Administrative Services) delivered the governor an initial report recommending statewide AI governance, a Chief AI Officer, NIST-based evaluation of AI systems, updated procurement policies to safeguard citizen data, and AI-literacy training for state employees.
-
In effect
Alabama Generative AI Acceptable Use Policy (AI-GV-P2)
Alabama · Effective 2025-01-31 · Alabama Generative AI Acceptable Use Policy (AI-GV-P2)
Alabama's Office of Information Technology issued a NIST AI RMF-based acceptable-use policy requiring human review of GenAI output, annotation of AI-generated code/output, prohibition of confidential-data inputs, and OIT authorization before contractors use GenAI in state systems.
-
In effect
New Jersey Data Protection Act
New Jersey · Effective 2025-01-15 · P.L.2024, c.9 (N.J. SB 332)
New Jersey's comprehensive privacy law grants residents rights to access, correct, delete, and port personal data and to opt out of data sales and targeted advertising. Controllers must get opt-in consent for sensitive data (health, biometric, precise location) and honor universal opt-out signals since July 2025.
-
In effect
Texas v. Allstate / Arity
TX · Effective 2025-01-13 · Texas v. Allstate / Arity — Driving Data Collection Suit (TDPSA + Data Broker Law) (2025-01-13)
First-ever TDPSA and Data Broker Law suit. Alleges SDK-based collection of geolocation and driving-behavior data from 45M+ Americans via Life360, GasBuddy, etc., used to score drivers and set premiums. Active in 2026.
-
In effect
CA AG Bonta AI legal advisory
CA · Effective 2025-01-13 · CA DOJ Legal Advisory (Jan. 13, 2025)
California's Attorney General issued a legal advisory making clear that existing California consumer-protection, civil-rights, and privacy laws fully apply to AI — including the False Advertising Law, Unfair Competition Law, CCPA, and FEHA. The advisory targets AI-washing, AI-driven discrimination, hallucination-driven misrepresentations, and AI scam impersonation.
-
In effect
Attorney General Bonta Legal Advisories on the Application o
California · Effective 2025-01-13 · Attorney General Bonta Legal Advisories on the Application of California Law to AI
California Attorney General Rob Bonta issued two legal advisories clarifying that entities developing, selling, or using AI must comply with existing California consumer-protection, civil-rights, competition, data-privacy, and election-misinformation laws, plus new AI laws effective January 1, 2025, with a second advisory targeting healthcare entities.
-
In effect
Executive Order No. 1584 (Fostering Stakeholder Collaboratio
Mississippi · Effective 2025-01-08 · Executive Order No. 1584 (Fostering Stakeholder Collaboration and Harnessing Artificial Intelligence)
Governor Tate Reeves directed the Department of Information Technology Services to inventory all state-agency AI, evaluate existing AI processes and procurement guidelines, and develop statewide responsible-AI policy recommendations.
-
In effect
Iowa Consumer Data Protection Act
Iowa · Effective 2025-01-01 · Iowa SF 262 (2023), Iowa Code ch. 715D
Iowa's privacy law gives consumers rights to access, delete, copy, and opt out of the sale of their personal data and targeted advertising. Notably it does NOT include a profiling opt-out, making it one of the more business-friendly state privacy laws.
-
In effect
Nebraska NDPA
Nebraska · Effective 2025-01-01 · Neb. Rev. Stat. §§ 87-901 et seq. (LB 1074, 108th Leg., 2024), eff. Jan. 1, 2025
Nebraska's comprehensive consumer privacy law gives residents the right to access, correct, delete, and port their personal data and to opt out of targeted advertising, data sales, and automated profiling used in decisions with significant legal or financial effects. The Attorney General enforces with fines up to $7,500 per violation with no private right of action.
-
In effect
NH Consumer Privacy Act
New Hampshire · Effective 2025-01-01 · RSA 507-H (2024 NH SB 255)
New Hampshire residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions. Applies at low thresholds (35,000 residents), so it covers many businesses.
-
In effect
Delaware Privacy Law (DPDPA)
Delaware · Effective 2025-01-01 · 6 Del. C. § 12D-101 et seq. (2023 DE HB 154)
Delaware residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions with legal effects. Applies at low thresholds (35,000 consumers).
-
In effect
OR AG Rosenblum
OR · Effective 2024-12-24 · OR AG Rosenblum — AI Guidance (UTPA, OCPA, Equality Act) (2024-12-24)
Clarifies that Oregon's UTPA, OCPA, and Equality Act apply to AI absent AI-specific law. Misrepresenting AI capabilities, discriminatory outcomes, and processing biometric/sensitive data without consent are actionable.
-
In effect
Texas A&M System Regulation 29.01.05, Artificial Intelligenc
Texas A&M University System · Effective 2024-12-10 · Texas A&M System Regulation 29.01.05, Artificial Intelligence
The Texas A&M University System's AI regulation governs all AI activities system-wide, requiring AI inventories, data classification, bias audits, safeguards against algorithmic discrimination, and academic-integrity citation rules.
-
In effect
NY AG James AI scam consumer alert
NY · Effective 2024-10-17 · NY OAG Press Release (Oct. 17, 2024)
New York Attorney General Letitia James issued consumer alerts warning New Yorkers about AI voice-cloning grandparent scams, AI romance and pig-butchering schemes, and AI investment fraud — and pledged enforcement under New York's GBL § 349 against deceptive AI uses.
-
In effect
Artificial Intelligence in Louisiana Schools: Guidance for K
Louisiana Department of Education (LDOE) · Effective 2024-08-28 · Artificial Intelligence in Louisiana Schools: Guidance for K-12 Schools
Louisiana's education department, acting on its AI Task Force recommendations, released K-12 AI guidance including a four-tier use system (AI-Empowered/Enhanced/Assisted/Prohibited) and a cyclical framework for policy, stakeholders, and monitoring.
-
In effect
North Carolina State Government Responsible Use of Artificia
North Carolina · Effective 2024-08-01 · North Carolina State Government Responsible Use of Artificial Intelligence Framework
NCDIT published a NIST-based framework of principles, practices, and guidance for state agencies deploying AI while reducing privacy and data-protection risks to residents.
-
In effect
Empowering Lifelong Learning: AI Guidance for Enhancing K-12
Wisconsin Department of Public Instruction (DPI) · Effective 2024-07-29 · Empowering Lifelong Learning: AI Guidance for Enhancing K-12 and Library Education
Wisconsin's education department released 22-page guidance for K-12 classrooms and libraries covering core AI concepts, ethics/data policy, security, professional development, and curriculum integration.
-
In effect
Florida Digital Bill of Rights (privacy / profiling opt-out)
Florida · Effective 2024-07-01 · Fla. CS/CS/SB 262 (2023); ch. 2023-201, Laws of Fla.; Fla. Stat. Secs. 501.701-501.722
Florida's Digital Bill of Rights gives covered consumers a set of data-privacy rights, including the right to opt out of profiling carried out solely by automated processing when that profiling is used to make decisions that have a legal or similarly significant effect on the person. Businesses that meet the law's thresholds must also conduct and document data-protection assessments for higher-risk processing activities such as profiling, targeted advertising, and the sale of personal data. The Florida Attorney General enforces the law; consumers cannot sue directly. The law applies only to a relatively narrow set of very large businesses.
-
In effect
Oregon SB 619 (opt out of profiling; child-data & assessment rules)
Oregon · Effective 2024-07-01 · Oregon Consumer Privacy Act, 2023 Or. Laws (SB 619), ORS 646A.570-646A.589, eff. July 1, 2024
Oregon's consumer privacy law lets residents opt out of having their personal data used for profiling that supports decisions with legal or similarly significant effects. It adds stronger protections for data about people the business knows are under 16, and requires businesses to complete and document data protection assessments for processing that poses a heightened risk, including risky profiling. The Attorney General enforces it; there is no private lawsuit right.
-
In effect
TDPSA
Texas · Effective 2024-07-01 · Tex. Bus. & Com. Code ch. 541 (HB 4, 2023)
Texans can access, correct, delete, and obtain copies of personal data held by covered businesses, and can opt out of targeted advertising, data sales, and profiling used for decisions with significant effects (like jobs, housing, or credit). Businesses must get consent for sensitive data, including biometrics.
-
In effect
Human-Centered AI Guidance for K-12 Public Schools
Washington Office of Superintendent of Public Instruction (OSPI) · Effective 2024-07-01 · Human-Centered AI Guidance for K-12 Public Schools
Washington's state superintendent issued 'Human-AI-Human' guidance for K-12 schools covering AI foundations, classroom implementation, ethical considerations, policy suggestions, and privacy compliance.
-
In effect
South Carolina State Agencies' Artificial Intelligence (AI)
South Carolina · Effective 2024-06-19 · South Carolina State Agencies' Artificial Intelligence (AI) Strategy
The South Carolina Department of Administration published a statewide AI strategy rooted in 'protect, promote, pursue' that establishes a Center of Excellence and AI Advisory Group and directs development of statewide acceptable-use, procurement, and data-protection policies for agencies.
-
In effect
AI Policy Template for Local Education Agencies
Alabama State Department of Education (ALSDE) · Effective 2024-06-01 · AI Policy Template for Local Education Agencies
Alabama's education department released a customizable AI policy template for LEAs built on eight pillars (strategy, governance, data privacy/security, procurement, implementation, competency, risk management, effectiveness).
-
In effect
SUNY generative-AI education initiative (Empire AI / systemw
State University of New York (SUNY) · Effective 2024-05-09 · SUNY generative-AI education initiative (Empire AI / systemwide AI chatbot program)
New York and SUNY launched a systemwide generative-AI education program described as the largest LLM-enabled education system, providing customized tutoring while pledging to protect privacy and academic integrity.
-
In effect
MA AG Campbell
MA · Effective 2024-04-16 · MA AG Campbell — Advisory on Consumer Protection, Anti-Discrimination, Data Security and AI (2024-04-16)
Clarifies that Chapter 93A, the Anti-Discrimination Law, and MA Data Security Regs apply fully to AI developers, suppliers, and users; identifies algorithmic discrimination and misrepresenting AI capabilities as unfair/deceptive.
-
In effect
Artificial Intelligence: Guidance for K-12 Classrooms
Mississippi Department of Education (MDE) · Effective 2024-04-05 · Artificial Intelligence: Guidance for K-12 Classrooms
Mississippi's education department published procedural guidance and instructional strategies for district and school leaders and teachers on appropriate AI use, including definitions, classroom impact, and policy-development considerations.
-
In effect
My Health My Data Act
Washington · Effective 2024-03-31 · RCW ch. 19.373
A sweeping health-data privacy law covering 'consumer health data' far beyond HIPAA — including biometric data, health inferences drawn by algorithms, and reproductive health information. Companies need consent to collect or share such data, must honor deletion requests, and cannot geofence health facilities. Consumers can sue under Washington's Consumer Protection Act.
-
In effect
California GenAI Procurement Guidelines and Toolkit
California · Effective 2024-03-21 · California GenAI Procurement Guidelines and Toolkit
California's Government Operations Agency and Department of Technology issued procurement guidelines and a toolkit requiring state entities to complete a SIMM 5305-F GenAI risk assessment, use written solicitations with a GenAI Disclosure & Fact Sheet, engage the CIO/AIO, and report GenAI contracts before procuring generative AI.
-
In effect
State of Arizona Statewide Policy P2000 - Generative AI Poli
Arizona · Effective 2024-03-01 · State of Arizona Statewide Policy P2000 - Generative AI Policy
The Arizona Department of Administration issued statewide policy P2000 governing responsible generative-AI use, requiring careful review of AI output, prohibiting feeding proprietary or sensitive information to public models, and emphasizing data governance, transparency, security, and privacy.
-
In effect
Executive Order 24-06: Artificial Intelligence and Data Cent
Rhode Island · Effective 2024-02-29 · Executive Order 24-06: Artificial Intelligence and Data Centers of Excellence
Governor Dan McKee's executive order establishes an AI Task Force, an AI Center of Excellence and a Data Center of Excellence, and directs the Department of Administration to develop a state code of ethics for AI and secure AI adoption across state agencies.
-
In effect
Executive Order No. 738 - Alabama Generative Artificial Inte
Alabama · Effective 2024-02-28 · Executive Order No. 738 - Alabama Generative Artificial Intelligence Task Force
Governor Kay Ivey created a Generative AI Task Force to study current GenAI use in executive-branch agencies and recommend policies for responsible and effective adoption within a governance structure ensuring transparency, bias testing, and privacy.
-
In effect
Mayor's Order 2024-028: Articulating DC's Artificial Intelli
District of Columbia · Effective 2024-02-08 · Mayor's Order 2024-028: Articulating DC's Artificial Intelligence Values and Establishing Artificial Intelligence Strategic Benchmarks
Mayor Bowser's order defines six AI values (clear benefit to the people, safety & equity, accountability, transparency, sustainability, and privacy & cybersecurity), establishes an AI Advisory Group and AI Taskforce, and requires District agencies to verify AI-values alignment before deploying any AI tool.
-
Proposed / pending
OCTO AI/ML Governance Policy
District of Columbia · Effective 2024-02-08 · OCTO AI/ML Governance Policy
The Office of the Chief Technology Officer's governance policy establishes rules for the responsible and secure use of AI/ML in DC government, requiring written agency-director approval before using agency data with AI, cybersecurity and business risk assessments, use of only OCTO-approved platforms, data-classification restrictions, and continuous monitoring.
-
In effect
CA AG Bonta
CA · Effective 2024-01-26 · CA AG Bonta — CCPA Investigative Sweep of Streaming Services (2024-01-26)
Sweep into streaming services' opt-out compliance; led to a $530K Sling TV settlement in 2025 and parallel CPPA actions (Honda $632,500) on ADMT-adjacent practices.
-
In effect
NC Generative AI Implementation Recommendations and Consider
North Carolina Department of Public Instruction (NCDPI) · Effective 2024-01-16 · NC Generative AI Implementation Recommendations and Considerations for PK-13 Public Schools
North Carolina's education department released a generative AI guidebook (including the 'EVERY' responsible-use framework) covering leadership, human capacity, curriculum, data privacy, and technology infrastructure for public schools.
-
In effect
Acceptable Use of Artificial Intelligence Technologies (NYS-
New York · Effective 2024-01-08 · Acceptable Use of Artificial Intelligence Technologies (NYS-P24-001)
New York's Office of Information Technology Services set enterprise rules requiring state agencies to conduct NIST-based risk assessments, maintain human oversight of AI decisions affecting the public, and disclose AI chatbots as non-human.
-
In effect
State of Indiana Artificial Intelligence Policy
Indiana · Effective 2024-01-01 · State of Indiana Artificial Intelligence Policy
Indiana's state AI policy, issued by the Office of the Chief Data Officer, applies the NIST AI Risk Management Framework and requires agencies to submit an AI Readiness Assessment Questionnaire and report existing AI systems before use.
-
In effect
Public Artificial Intelligence Services Security Standard
Minnesota · Effective 2024-01-01 · Public Artificial Intelligence Services Security Standard
Minnesota IT Services set a security standard governing state employees' use of public AI services (such as ChatGPT), restricting inputs to public/low-classification data and setting guardrails to prevent breaches of private or sensitive information.
-
In effect
Use of AI in Oklahoma State Government Standard
Oklahoma · Effective 2024-01-01 · Use of AI in Oklahoma State Government Standard
Oklahoma's Office of Management and Enterprise Services, under the state CIO, sets a mandatory standard requiring agencies to use only CIO-approved AI tools, complete AI awareness training, verify AI output, and never input sensitive data.
-
In effect
State of South Dakota Generative Artificial Intelligence Gui
South Dakota · Effective 2024-01-01 · State of South Dakota Generative Artificial Intelligence Guidelines & Acceptable State Use
The Bureau of Information and Telecommunications sets acceptable-use guidelines for generative AI in state government, requiring employees to fact-check, edit, and treat AI output as a starting point while managing bias, privacy, and cybersecurity risks.
-
In effect
CCC systemwide AI guidance and HUMANS responsible-AI framewo
California Community Colleges Chancellor's Office · Effective 2024-01-01 · CCC systemwide AI guidance and HUMANS responsible-AI framework
The California Community Colleges Chancellor's Office issues systemwide AI guidance built on its HUMANS framework (human-centered, privacy, algorithmic-discrimination protections, notice and explanation, safety) governing AI in instruction and student support.
-
In effect
Penn State systemwide Generative AI Guidelines
Pennsylvania State University (Penn State) · Effective 2024-01-01 · Penn State systemwide Generative AI Guidelines
Penn State's systemwide AI guidelines set responsible-use rules covering FERPA/HIPAA compliance, output verification, accessibility review of AI tools, disclosure, and restrictions on AI-assisted grading across its multi-campus system.
-
In effect
Use of Artificial Intelligence (AI) in State of Ohio Solutio
Ohio · Effective 2023-12-04 · Use of Artificial Intelligence (AI) in State of Ohio Solutions (Policy IT-17)
Ohio's Department of Administrative Services adopted Policy IT-17 requiring state AI use to be fair, accountable, transparent, and human-centric, mandating piloting, human verification for consequential decisions, and limiting generative-AI inputs to public-record data.
-
In effect
Policy on Responsible Use of Generative Artificial Intellige
New Jersey · Effective 2023-11-17 · Policy on Responsible Use of Generative Artificial Intelligence by State Employees
New Jersey's policy directs state employees using generative AI to disclose and label AI use, independently fact-check outputs, and refrain from entering confidential or personally identifiable information into AI tools.
-
In effect
Generative Artificial Intelligence (AI) in K-12 Classrooms G
Oregon Department of Education · Effective 2023-11-01 · Generative Artificial Intelligence (AI) in K-12 Classrooms Guidance
Oregon's education department maintains generative AI guidance and a companion 'Developing Policy and Protocols' document to help districts adopt safe, ethical, equitable AI policies in K-12 classrooms.
-
In effect
Commissioner's Determination Prohibiting Facial Recognition
New York State Education Department · Effective 2023-09-27 · Commissioner's Determination Prohibiting Facial Recognition Technology in Schools
NYSED Commissioner Betty Rosa issued a statewide determination prohibiting all New York public and nonpublic schools from purchasing or using facial recognition technology, while leaving other biometric tools to local discretion subject to privacy and civil-rights review.
-
In effect
New York Biometrics in Schools Ban (statewide prohibition on
New York State (Education Law / biometrics ban) · Effective 2023-09-01 · New York Biometrics in Schools Ban (statewide prohibition on facial recognition purchase/use)
Effective September 2023 following the NYSED Commissioner determination, all New York schools are prohibited from purchasing or using facial recognition technology, making NY the first state with such a comprehensive school ban.
-
In effect
Interim Guidelines for Purposeful and Responsible Use of Gen
Washington · Effective 2023-08-08 · Interim Guidelines for Purposeful and Responsible Use of Generative Artificial Intelligence (AI) in Washington State Government
WaTech's interim guidelines establish principles and dos-and-don'ts for state employees using generative AI, covering fact-checking, bias reduction, attribution, and protection of sensitive or confidential data.
-
In effect
State of Kansas Generative Artificial Intelligence Policy (P
Kansas · Effective 2023-07-31 · State of Kansas Generative Artificial Intelligence Policy (PPM 8200.00)
The Kansas Office of Information Technology Services enterprise policy sets acceptable-use rules for generative AI, requiring human review of all AI outputs, barring Restricted Use Information from AI tools, and imposing vendor disclosure and data-control requirements.
-
In effect
Colorado Privacy Act (CPA)
Colorado · Effective 2023-07-01 · Colo. Rev. Stat. Sec. 6-1-1301 et seq. (SB 21-190)
The Colorado Privacy Act gives state residents the right to opt out of having their personal data used for profiling when that profiling drives decisions that produce legal or similarly significant effects, such as decisions about credit, housing, employment, or services. Businesses that engage in higher-risk processing, including certain profiling, must conduct and document a data protection assessment weighing the benefits against the risks. The Colorado Attorney General enforces the law, and since January 1, 2025 may bring actions without first offering a chance to cure.
-
In effect
Connecticut Data Privacy Act (CTDPA) (profiling opt-out)
Connecticut · Effective 2023-07-01 · Conn. Gen. Stat. Sec. 42-515 to 42-525; P.A. 22-15
Connecticut's consumer privacy law lets residents opt out of having their personal data used for profiling that feeds automated decisions carrying legal or similarly significant effects. Businesses that profile consumers for high-risk purposes must also run data protection assessments to weigh the risks. Other consumer rights include access, correction, deletion, and opting out of targeted advertising and data sales. The Attorney General enforces the law under Connecticut's unfair trade practices framework, and there is no individual right to sue.
-
In effect
Cothron v. White Castle
IL · Effective 2023-02-17 · Cothron v. White Castle Sys., Inc., 2023 IL 128004
The Illinois Supreme Court held in February 2023 that BIPA claims accrue each time a biometric identifier is captured or disclosed — so a fingerprint scan to clock in twice a day for years generates thousands of separate violations per worker. The ruling forced the Illinois legislature to amend BIPA in 2024 to cap per-method accrual (P.A. 103-0769).
-
In effect
Virginia VCDPA (opt out of profiling, $7,500/violation)
Virginia · Effective 2023-01-01 · Va. Code 59.1-575 to 59.1-585 (esp. 59.1-577, 59.1-580, 59.1-584); HB 2307 / SB 1392 (2021)
Virginia's comprehensive privacy law gives consumers the right to opt out of 'profiling' used to make decisions producing legal or similarly significant effects, such as automated decisions affecting credit, housing, employment, or essential services. Businesses must obtain heightened consent before processing the data of a known child (via federal COPPA) and must conduct documented data protection assessments for higher-risk processing, including certain profiling. The Attorney General enforces the law and may seek up to $7,500 per violation; there is no private right of action.
-
In effect
ACLU v. Clearview AI
IL · Effective 2022-05-09 · ACLU v. Clearview AI, Inc., No. 2020-CH-04353 (Cir. Ct. Cook Cty., Ill.)
Clearview AI, which scraped billions of online photos to build a face-search engine sold to police, agreed to a nationwide consent order in May 2022. Clearview is permanently barred from selling its faceprint database to most private U.S. businesses, with additional Illinois-specific restrictions on government contracts.
-
In effect
GA Synthetic NCII Transmission Law
Georgia · Effective 2022-05-02 · O.C.G.A. Sec. 16-11-90
Georgia makes it a crime to electronically send or post a nude or sexually explicit image of an identifiable adult without that person's consent when the purpose is to harass or cause financial harm. The statute expressly reaches a 'falsely created' video or still image, meaning synthetic or deepfake depictions are treated the same as real photographs. Posting such material to certain explicit websites is punished more harshly than other electronic transmission.
-
In effect
UC Responsible AI Principles and AI Council governance frame
University of California (UC System) · Effective 2021-10-01 · UC Responsible AI Principles and AI Council governance framework
UC was the first US university system to adopt Responsible AI Principles and stand up a systemwide AI Council that issues guidance, training, and risk assessments for AI use across its campuses.
-
In effect
Va. Code 32.1-127 (rules for patient voice assistants in care facilities)
Virginia · Effective 2021-07-01 · Va. Code 32.1-127; HB 2154 (2021 Sp. Sess. I), Va. Acts cc. 219, 233, 525
Virginia directed its Board of Health to write regulations requiring hospitals, nursing homes, and certified nursing facilities to adopt policies on when and how a patient may use their own voice-driven 'intelligent personal assistant' (such as a smart speaker or AI digital assistant) during inpatient care, consistent with HIPAA. The statute defines an intelligent personal assistant as a device-and-software combination that uses natural language processing and AI.
-
In effect
Wyo. Stat. 6-4-306 (revenge-porn law covers computer-generated images)
Wyoming · Effective 2021-07-01 · Wyo. Stat. Ann. 6-4-306(a)(iii); 2021 Wyo. Sess. Laws (HB0085)
This 2021 Wyoming law makes it a crime for an adult to share someone's intimate image without consent when the person had a reasonable expectation it would stay private. The definition of a covered 'image' expressly includes a 'computer generated image' that purports to represent an identifiable person, so fabricated or digitally generated intimate depictions fall within its scope. The offense is a misdemeanor.
-
In effect
HI SB 309 (deepfake intimate-image crime)
Hawaii · Effective 2021-06-23 · Haw. SB 309 (2021), Act 59; HRS Sec. 711-1110.9
Hawaii expanded its first-degree violation-of-privacy crime to cover deepfake-style imagery. It is now an offense to intentionally create or disclose a nude or sexually explicit image or video of a 'composite fictitious person' that includes the recognizable features of a real, identifiable individual so that it appears to show that real person, when done with intent to substantially harm them or as revenge. The crime is a class C felony.
-
In effect
Attorney General Donovan Sues Clearview AI for Violations of
Vermont · Effective 2020-03-10 · Attorney General Donovan Sues Clearview AI for Violations of Consumer Protection Act and Data Broker Law
The Vermont Attorney General sued Clearview AI under the Consumer Protection Act and Data Broker Law for scraping Vermonters' photos and using facial-recognition AI to map faces and sell access without consent.
-
In effect
AB 602 (Deepfake Intimate Images)
California · Effective 2020-01-01 · Cal. Civ. Code § 1708.86 (AB 602, 2019); Cal. Penal Code § 647(j)(4)
Californians depicted in sexually explicit deepfakes made or shared without their consent can sue the people responsible for damages, including statutory damages and attorney's fees. Criminal liability also exists under separate provisions (SB 926, 2024).
-
In effect
Rosenbach v. Six Flags
IL · Effective 2019-01-25 · Rosenbach v. Six Flags Entm't Corp., 2019 IL 123186, 129 N.E.3d 1197
The Illinois Supreme Court ruled in January 2019 that a BIPA plaintiff does not need to plead actual injury to be 'aggrieved' under the statute — a violation of BIPA's notice/consent requirements is itself the injury. This made BIPA the most consequential biometric-privacy statute in the U.S. and triggered a wave of AI-faceprint, voiceprint, and fingerprint litigation.
-
In effect
BART Surveillance Technology Ordinance
Bay Area Rapid Transit (BART) · Effective 2018-09-13 · BART Surveillance Technology Ordinance
BART became the first transit district in the country to adopt a CCOPS-style ordinance requiring board approval, a surveillance impact report, a use policy, and annual reports before acquiring surveillance technology.
-
In effect
WA Biometric Identifiers Act (2017)
WA · Effective 2017-07-23 · RCW Ch. 19.375 (HB 1493, 2017)
Washington's 2017 HB 1493 was the third state biometric privacy law (after IL BIPA and TX CUBI). It requires notice and consent before 'enrolling' a biometric identifier in a database for a commercial purpose, but excludes photographs and audio recordings — a significant carve-out that distinguishes it from BIPA. Enforced by the Washington AG; no private right of action.
-
In effect
CA AB 856 (2015 drone trespass)
California · Effective 2016-01-01 · Cal. Civ. Code § 1708.8(b)
California amended its anti-paparazzi statute so the existing 'physical invasion of privacy' tort applies when someone uses a drone to enter the airspace above a person's land to capture images or recordings of personal or familial activities — closing the 'I never set foot on the property' loophole.
-
In effect
WI drone-surveillance ban
Wisconsin · Effective 2014-04-10 · Wis. Stat. §§ 942.10, 175.55
Wisconsin made it a Class A misdemeanor to use a drone to observe or record any person in a place where they have a reasonable expectation of privacy, and requires police to obtain a warrant before using drones for surveillance.
-
In effect
Guam EDPA (5 GCA Ch. 14)
Guam · Effective 2012-01-01 · 5 G.C.A. ch. 14
Guam's baseline statute on government use of personal data — predates the AI wave but is the foundation any AI system using citizen data must comply with. Governs collection, use, and protection of personal data by Guam executive-branch agencies.
-
In effect
Guam Breach Notification (9 GCA Ch. 48)
Guam · Effective 2009-01-01 · 9 G.C.A. ch. 48
Guam's data breach notification statute. Requires entities holding personal information to notify affected residents of breaches. Relevant to AI systems processing personal data because any compromise must trigger notice.
-
Proposed / pending
House Bill 2512 — Banning surveillance pricing by rideshare
Pennsylvania · House Bill 2512 — Banning surveillance pricing by rideshare companies
Pennsylvania's House passed HB 2512 to prohibit transportation network companies (Uber/Lyft) from using consumers' personal data to set individualized 'surveillance' prices, now advancing to the Senate.
-
Vetoed
Arizona HB 2133 deepfake sexual content — vetoed 2026
Arizona · Ariz. H.B. 2133, 57th Leg., 2d Reg. Sess. (2026) — vetoed June 19, 2026
Arizona HB 2133 would have amended the state's existing unlawful-image-disclosure statute to include 'synthetic depictions' — AI-generated images of nudity or sexual activity — and would have required websites hosting sexual material to verify that each depicted person consented and was of legal age. The Senate approved a reconciled conference bill 16-12 on June 9, 2026 and the House passed 35-20. Gov. Hobbs vetoed it on June 19, writing that the bill had 'a chilling effect on free speech' and would violate First Amendment rights to engage in satirical discourse about elected officials, and that existing Arizona law and the federal TAKE IT DOWN Act already address AI-generated revenge porn.
-
Expired
Newark Liberty Facial Recognition eGates for TSA Screening
Port Authority of New York and New Jersey (Newark Liberty International Airport) · Newark Liberty Facial Recognition eGates for TSA Screening
The Port Authority of NY & NJ deployed facial-recognition eGates at Newark Liberty that let enrolled travelers pass TSA checkpoints by matching a live facial scan against their identity document instead of a manual ID check.
-
Expired
Newark Biometric Self-Boarding E-Gate Pilot (with IDEMIA/Luf
Port Authority of New York and New Jersey (Newark Liberty International Airport, Terminal B) · Newark Biometric Self-Boarding E-Gate Pilot (with IDEMIA/Lufthansa/CBP)
The Port Authority piloted a biometric self-boarding e-gate at Newark Gate 62 that captured passengers' faces and verified them against CBP's passport database to board without documents, with scans deleted within 12 hours.
-
Proposed / pending
MTA AI Video Analytics Solicitation for Subway Camera Monito
New York Metropolitan Transportation Authority (MTA) · MTA AI Video Analytics Solicitation for Subway Camera Monitoring (Suspicious/Problematic Behavior Detection)
The MTA solicited vendors for AI computer-vision software to analyze feeds from its 15,000+ subway cameras to flag weapons, unattended items, and dangerous behavior, while stating facial recognition will not be used.
-
Repealed / replaced
CCPA Original (AB 375, 2018)
CA · Effective 2020-01-01 · Cal. AB 375 (2018), 2018 Cal. Stats. ch. 55 — substantially superseded by Prop 24 (CPRA) and 2025 CPPA ADMT regs
Governor Jerry Brown signed AB 375 — the original California Consumer Privacy Act — on June 28, 2018, the most comprehensive state privacy law in U.S. history at the time. Substantially amended by Prop 24 (CPRA, 2020) and the 2025 CPPA ADMT regulations. This entry captures the original 2018 framework as historical baseline.
-
Expired
AK SB 177 — AI deepfakes / cybersecurity / data privacy (dead, 2024)
Alaska · AK SB 177 (33rd Alaska Legislature, 2023-2024)
A 2023-2024 Alaska Senate bill that would have required disclosure of AI-generated deepfakes in campaign communications and addressed state cybersecurity and data privacy. It died without passing: the 33rd Alaska Legislature adjourned on May 15, 2024 with the bill still stuck in Senate committee referrals (Judiciary, then Finance). This entry is kept only as a historical record of a dead bill — it is NOT a law in effect and does not protect anyone today. The same subject matter is being pursued in the current 34th Legislature as AK SB 2.
County consumer data privacy rules (42)
-
In effect
Montgomery County PA Generative AI Governance Policy
Montgomery County, PA · Effective 2025-11-18 · Montgomery County PA Commissioners policy (2025) (2025-11-18)
Montgomery County PA (Norristown) adopted AI governance policy: bars PII/PHI in public LLMs, requires CIO approval for AI procurement, mandates inventory of AI tools, and requires impact review before deployment in benefits or eligibility contexts.
-
In effect
Allen County IN County AI Use Policy
Allen County, IN · Effective 2025-11-04 · Allen County Commissioners policy (2025) (2025-11-04)
Allen County IN (Fort Wayne) adopted generative AI use policy: bars CJIS/PHI/PII in public LLMs, requires departmental approval, mandates human review of AI outputs, and prohibits AI-only adverse decisions in benefits or eligibility.
-
In effect
Rutherford County TN County AI Use Policy
Rutherford County, TN · Effective 2025-10-21 · Rutherford County Mayor policy (2025) (2025-10-21)
Rutherford County TN adopted AI use policy for county employees: bars PII/PHI/CJIS in public LLMs, requires departmental approval, and bans AI-only adverse decisions affecting residents.
-
In effect
Sonoma County CA AI Use Guidelines for County Government
Sonoma County, CA · Effective 2025-10-14 · Sonoma County Administrator policy (2025) (2025-10-14)
Sonoma County adopted AI use guidelines for county employees prohibiting PII/PHI in public LLMs, requiring departmental approval before AI use, mandating disclosure of AI assistance in resident-facing communications, and barring AI-only consequential decisions.
-
In effect
Lexington-Fayette Urban County Government AI Use Policy
Fayette County, KY · Effective 2025-09-23 · LFUCG Administrative Regulation on AI (2025) (2025-09-23)
Lexington-Fayette Urban County Government (consolidated city-county) adopted AI use policy: prohibits PII/PHI in public LLMs, requires CIO approval for AI procurement, mandates inventory, and requires impact review before deployment in resident-facing services.
-
In effect
Williamson County TN Generative AI Use Policy
Williamson County, TN · Effective 2025-09-09 · Williamson County Mayor policy (2025) (2025-09-09)
Williamson County TN (Franklin/Brentwood) adopted generative AI use policy: prohibits CJIS/PHI/PII in public LLMs, requires human review of AI outputs, and mandates departmental inventory of AI-enabled tools.
-
In effect
Lane County OR
Lane County, OR · Effective 2025-08-19 · Lane County Administrator policy (2025) (2025-08-19)
Lane County OR adopted generative AI use policy for county employees: prohibits PII/PHI/CJIS in public LLMs, requires departmental approval, mandates human review of AI outputs, and requires disclosure of AI assistance in resident-facing communications.
-
In effect
Riverside County CA Sheriff ALPR Policy & Retention
Riverside County, CA · Effective 2025-07-22 · RCSD ALPR Policy (2025) (2025-07-22)
Riverside County Sheriff's Department adopted ALPR policy aligning with California Civil Code §1798.90.5 et seq.: 90-day retention cap, documented investigative purpose for queries, audit logging, and quarterly reporting to the Board of Supervisors.
-
In effect
City of Indianapolis & Marion County IN Generative AI Use Policy
Marion County, IN · Effective 2025-07-22 · Indianapolis-Marion County Mayor / Administrator AI Policy (2025) (2025-07-22)
Indianapolis (Unigov) / Marion County adopted citywide and countywide generative AI use policy: prohibits PII/PHI/CJIS in public LLMs, requires CIO approval for AI procurement, mandates inventory, and requires impact review before AI-driven decisions in resident services.
-
In effect
Clackamas County OR Generative AI Use Policy
Clackamas County, OR · Effective 2025-07-01 · Clackamas County administrative order (2025) (2025-07-01)
Clackamas County issued a generative AI use policy for staff: prohibits CJIS, HIPAA, and PII entry into public LLMs; requires human-in-the-loop review; mandates departmental inventory of AI tools.
-
In effect
Ventura County CA Sheriff ALPR Policy
Ventura County, CA · Effective 2025-05-20 · VCSO ALPR Policy (2025) (2025-05-20)
Ventura County Sheriff's Office adopted ALPR policy with 90-day retention, documented investigative purpose required for queries, audit logging, and prohibition on sharing data with commercial brokers, per California Civil Code §1798.90.5.
-
In effect
Boulder County CO Generative AI Use Policy
Boulder County, CO · Effective 2025-05-13 · Boulder County Administrative Policy (2025) (2025-05-13)
Boulder County adopted generative AI use policy: requires staff training, prohibits entry of confidential or PII data into public LLMs, requires disclosure when AI is used in resident-facing communications, and bans AI-only decisions on benefits or enforcement.
-
In effect
Montgomery County MD AI Governance Framework
Montgomery County, MD · Effective 2025-04-30 · Montgomery County Executive Order 2-25 (AI) (2025-04-30)
Montgomery County Executive Order establishing AI governance framework: requires AI inventory, impact assessment before deployment in resident-facing services, mandatory human review of consequential decisions, prohibition on facial-recognition use by county departments without Council authorization, and annual public reporting.
-
In effect
Orange County CA Sheriff ALPR Use & Retention Policy
Orange County, CA · Effective 2025-04-15 · OCSD ALPR Policy (2025) (2025-04-15)
Orange County (CA) Sheriff's Department adopted ALPR governance policy with 90-day retention cap, documented investigative purpose requirement, audit logging, and quarterly reporting to the Board of Supervisors per California Civil Code §1798.90.5 et seq.
-
In effect
Loudoun County Sheriff's Office ALPR General Order 401.8
Loudoun County, VA · Effective 2025-03-24 · LCSO General Order 401
Loudoun County Sheriff's Office General Order 401.8 (Operations) governs Automated License Plate Recognition (ALPR / Flock Safety) use by LCSO personnel. Last reviewed March 24, 2025 with the next review scheduled for November 1, 2027. The order requires data-sharing among other agencies to be governed by MOUs, states that ALPR data is owned by LCSO and is not sold to third parties, and is updated to reflect VA legislative changes effective July 1, 2025.
-
In effect
Montgomery County MD Police Directive FC 0627
Montgomery County, MD · Effective 2024-10-01 · MCPD Directive FC 0627 (Use of Facial Recognition Technology), posted 2024-10-01
Montgomery County Police Department Function Code 0627 — 'Use of Facial Recognition Technology' — is the operational directive governing MCPD's use of facial recognition. The directive was published October 1, 2024 on the official MCPD policy library. It is paired with Council Bill 33-22 (adopted Feb. 13, 2023) at the legislative level. Maryland's statewide HB 338/SB 182 (signed May 16, 2024) adds reasonable-suspicion-of-qualifying-offense and no-sole-basis-for-arrest constraints that apply to all state, county, and municipal law-enforcement agencies including MCPD.
-
In effect
Orleans Parish / New Orleans Facial Recognition Restrictions
Orleans Parish County, LA · Effective 2024-07-25 · New Orleans City Council Ordinance (Orleans Parish coterminous) (2024-07-25)
Orleans Parish (coterminous with New Orleans) restricts NOPD's use of facial-recognition technology to investigations of specific violent crimes with supervisory approval, prohibits use as sole basis for arrest, and requires reporting to City Council.
-
In effect
Arlington County VA ACPD Automated License Plate Reader
Arlington County, VA · Effective 2024-04-01 · ACPD General Order 605 (ALPR policy) (2024-04-01)
Arlington County Police Department adopted formal ALPR governance policy with 30-day data retention limit, restricted access, audit trails, and required reasonable-suspicion or investigative purpose for queries; aligns with Virginia Code §15.2-1723.1.
-
In effect
King County FR Ban
King County, WA · King County, Wash., Ordinance 19296 (June 1, 2021)
King County (the Seattle area) was the first US county to ban its government, including the Sheriff's Office, from using facial recognition technology. The unanimous 2021 ordinance also bars county agencies from getting facial recognition information through third parties. Remains in effect as of June 2026.
-
In effect
Santa Clara County Surveillance Ordinance
Santa Clara County, CA · Santa Clara County, Cal., Ordinance Code div. A40 (NS-300.897, 2016)
Santa Clara County passed the nation's first county-level surveillance oversight law in 2016. County departments must get Board of Supervisors approval, publish a surveillance use policy, and file an impact report before acquiring surveillance technology, plus annual reports afterward. Still actively administered by the County Privacy Office.
-
In effect
FCPS formal generative AI restrictions — elementary ban, secondary authorization required
Fairfax County Public Schools, VA · Effective 2026-08-01 · Fairfax County Public Schools School Board formal policy action on generative AI restrictions (adopted July 16, 2026; effective SY 2026-27)
The Fairfax County School Board voted on July 16, 2026 to adopt formal generative AI restrictions that take effect for the 2026-27 school year. Elementary students are prohibited from using any generative AI tools. Secondary students may only use generative AI if they receive written authorization from a principal, superintendent, or designee for a specific project. Pre-K and kindergarten students are banned from using school-issued tablets and laptops, with exceptions for students whose IEP, 504 plan, or multilingual learner status requires device access. The restrictions supersede the district's prior interim guidance (FCPS Forward: AI & The Future of Learning, September 2025), which had approved certain tools including Adobe Express and a ChatGPT pilot for teachers. Parental opt-out for school-issued devices and a YouTube content firewall were also under consideration.
-
In effect
Monongalia County Commission approves Flock Safety automated
Monongalia County, WV · Effective 2025-12-10 · Monongalia County Commission approves Flock Safety automated license plate reader (ALPR) surveillance program
The Monongalia County Commission voted on December 10, 2025 to approve a three-year contract using $60,000 in opioid settlement funds for 20 Flock Safety automated license plate reader cameras, over resident privacy objections.
-
In effect
Board Policy O-AIU and CMS Generative AI Guidance (2025-26)
Charlotte-Mecklenburg Schools, NC · Effective 2025-10-28 · Board Policy O-AIU and CMS Generative AI Guidance (2025-26)
The Charlotte-Mecklenburg Schools board approved Board Policy O-AIU on Oct. 28, 2025, requiring an AI committee to review any AI system using staff or student data, mandating FERPA-compliant vetting, age-appropriate tools, and barring AI from replacing human decision-making.
-
In effect
District Policy 3750 - Artificial Intelligence (AI) Use
Washington County School District, UT · Effective 2025-09-08 · District Policy 3750 - Artificial Intelligence (AI) Use
Washington County (UT) School District's board policy frames AI as a teacher assistant requiring human oversight, generally prohibits using confidential or FERPA-protected student data with AI tools, and bars students from using AI to plagiarize, generate deepfakes, or bypass security filters.
-
In effect
Board Policy 2130 (Emerging Technologies) and HCPS Artificia
Hillsborough County Public Schools, FL · Effective 2025-06-02 · Board Policy 2130 (Emerging Technologies) and HCPS Artificial Intelligence Implementation Guide
Hillsborough County Public Schools adopted Board Policy 2130 and an AI Implementation Guide setting age-based generative-AI limits (no unsupervised use before 8th grade; written parental consent and teacher approval thereafter) built on six guiding principles.
-
In effect
Johnson County Sheriff nationwide Flock ALPR search (abortio
Johnson County, TX (Johnson County Sheriff's Office) · Effective 2025-05-09 · Johnson County Sheriff nationwide Flock ALPR search (abortion 'death investigation')
Johnson County Sheriff's deputies ran nationwide Flock automated license plate reader searches across tens of thousands of cameras and thousands of networks to locate a woman in a self-managed-abortion investigation, illustrating an operational sheriff ALPR practice.
-
In effect
BCPS AI Task Force resources and districtwide AI (Microsoft
Broward County Public Schools, FL · Effective 2024-11-01 · BCPS AI Task Force resources and districtwide AI (Microsoft Copilot) rollout guidance
Broward County Public Schools stood up an AI Task Force in November 2024 that produced responsible-use resources for administrators, teachers, and students alongside a large districtwide Microsoft Copilot rollout addressing academic integrity and AI literacy.
-
In effect
King County GenAI Guidelines
King County, WA · Effective 2024-09-27 · King County, GenAI Guidelines for Employees (Sept. 2024)
King County issued guidelines for employee use of generative AI, developed jointly by King County IT and the Office of Equity, Racial and Social Justice. The guidelines aim to reduce bias and protect sensitive personal data entrusted to the county, with a software review process for GenAI tools.
-
In effect
Montgomery County Police Department Drone as First Responder
Montgomery County, MD · Effective 2023-11-20 · Montgomery County Police Department Drone as First Responder Program
Montgomery County Police launched a DFR program on November 20, 2023, limited to responding to calls for service, with no proactive surveillance, audio recording, or facial recognition and a warrant requirement for private areas.
-
In effect
Santa Cruz County AI Policy
Santa Cruz County, CA · Effective 2023-09-19 · County of Santa Cruz, AI Policy (Sept. 19, 2023)
Santa Cruz County adopted one of the earliest county-level AI policies in the US, approved in September 2023 and incorporated into the county's procedures manual. It governs how county employees may use AI (including generative AI), with safeguards for sensitive data and human accountability for outputs.
-
In effect
Spokane County Real-Time Crime Center (RTCC) surveillance us
Spokane County, WA (Spokane County Sheriff's Office) · Effective 2023-04-01 · Spokane County Real-Time Crime Center (RTCC) surveillance use policy
The Spokane County Sheriff's RTCC fuses surveillance cameras, license plate readers, BriefCam video analytics, 911 and social media data for real-time intelligence while stating it does not use facial recognition biometric software and applies access controls and audits.
-
In effect
Central Bucks School District GoGuardian Beacon Student Moni
Central Bucks School District, PA · Effective 2023-03-01 · Central Bucks School District GoGuardian Beacon Student Monitoring Trial
Central Bucks SD (PA) authorized a district-wide trial of GoGuardian Beacon to conduct 24/7 AI monitoring of middle- and high-school students' online activity on district devices, with a potential $114,000+ subscription pending trial-data review.
-
In effect
Ordinance prohibiting King County government and Sheriff use
King County, WA · Effective 2021-06-01 · Ordinance prohibiting King County government and Sheriff use of facial recognition technology
King County became the first U.S. county to ban its administrative agencies and the Sheriff's Office from using facial recognition technology, with a narrow exception for the National Child Search Assistance Act.
-
In effect
King County Facial Recognition Technology Ban (Ordinance 202
King County, WA (home to Seattle-Tacoma International Airport) · Effective 2021-06-01 · King County Facial Recognition Technology Ban (Ordinance 2021)
King County (which operates Sea-Tac's environs and the Sheriff's Office) became the first U.S. county to ban all county-agency use of facial recognition, though federal CBP use at Sea-Tac is unaffected.
-
In effect
Orange County SD Policy Manual, Policy 308 - Unmanned Aerial
Orange County, CA (Orange County Sheriff-Coroner Department) · Effective 2021-03-01 · Orange County SD Policy Manual, Policy 308 - Unmanned Aerial Vehicle (UAV)
The Orange County Sheriff's UAV policy sets rules for lawful, FAA Part 107-compliant drone operations, requiring mission briefs, after-action reports, and prohibiting missions that violate the public's privacy rights.
-
In effect
Facial Recognition Policy (Riverside Cal-ID / RCSD)
Riverside County, CA (Riverside Cal-ID Biometric Identification Network / RCSD) · Effective 2020-03-23 · Facial Recognition Policy (Riverside Cal-ID / RCSD)
The Riverside County Sheriff's Department's Cal-ID biometric network governs use of its facial recognition system, restricting acceptable search reasons, requiring training, data-quality assurance, retention/purging rules, and oversight for participating law-enforcement agencies.
-
In effect
Suffolk County Jail AI inmate-call monitoring (LEO Technolog
Suffolk County, NY (Suffolk County Sheriff's Office) · Effective 2019-04-01 · Suffolk County Jail AI inmate-call monitoring (LEO Technologies 'Verus')
The Suffolk County Sheriff's jail deployed LEO Technologies' Verus AI, which uses Amazon speech-to-text to transcribe and keyword-flag inmate phone calls, monitoring over 2.5 million calls between April 2019 and May 2020.
-
In effect
Delta-CBP Biometric Boarding and Simplified Arrival at Detro
Wayne County Airport Authority / Delta (Detroit Metropolitan Airport) · Effective 2018-07-01 · Delta-CBP Biometric Boarding and Simplified Arrival at Detroit Metro Airport
Delta, the Wayne County Airport Authority and CBP deployed facial-recognition boarding at Detroit Metro, letting international passengers board by facial scan matched to CBP's photo gallery.
-
Proposed / pending
Cook County Jail AI-powered video surveillance system (Brief
Cook County, IL (Cook County Sheriff / Cook County Jail) · Cook County Jail AI-powered video surveillance system (BriefCam) contract
The Cook County Sheriff's Office proposed a $1.12M three-year BriefCam contract to add AI video analytics, facial recognition, and object identification across Cook County Jail's video, drawing opposition from 80 community groups.
-
Proposed / pending
Santa Fe County Sheriff proposed Clearview AI facial recogni
Santa Fe County, NM (Santa Fe County Sheriff's Office) · Santa Fe County Sheriff proposed Clearview AI facial recognition pilot contract
The Santa Fe County Sheriff's Office asked the County Commission to approve a $17,100 one-year Clearview AI facial recognition pilot, but commissioners tabled it and required the office to first present a use policy and vet vendor data-sharing (including with ICE).
-
Proposed / pending
Policy Code 1910 Generative Artificial Intelligence (draft)
Wake County Public School System, NC · Policy Code 1910 Generative Artificial Intelligence (draft)
Wake County Public School System advanced draft Policy 1910 on generative AI on June 17, 2026, which discourages AI detectors, requires students to disclose and explain AI use and cite it, and bars sharing student PII with certain AI systems, pending board approval.
-
Proposed / pending
Fort Bend ISD GoGuardian Web Content Filter and Student Moni
Fort Bend Independent School District, TX · Fort Bend ISD GoGuardian Web Content Filter and Student Monitoring Procurement
Fort Bend ISD's board approved a procurement of GoGuardian web content filtering and monitoring modules not to exceed $1.6 million over five years, part of a wave of Houston-area districts (including Humble ISD and Cypress-Fairbanks ISD) deploying AI-driven student-device monitoring.
City / local consumer data privacy rules (144)
-
In effect
NYC Biometric Identifier Law (LL3)
New York City, NY · Effective 2021-07-09 · NYC Admin. Code §§ 22-1201–22-1205 (Local Law 3 of 2021)
NYC retail stores, restaurants, and entertainment venues that collect customers' biometric data (face scans, fingerprints, iris scans, voiceprints) must post clear signs at entrances disclosing it. Selling or otherwise profiting from customers' biometric data is flatly banned. Customers can sue: $500 per signage or negligent-sale violation and $5,000 per intentional or reckless sale, plus attorneys' fees.
-
In effect
Portland Private-Sector FR Ban
Portland, OR · Effective 2021-01-01 · Portland, Or., City Code ch. 34.10 (Ordinance 190114, 2020)
Portland is the first US city to ban private businesses from using facial recognition in places of public accommodation such as stores, restaurants, and entertainment venues. People can sue violators for damages. The ban remains in effect as of June 2026.
-
In effect
SF Stop Secret Surveillance Ordinance (2019, first-in-nation)
San Francisco, CA · Effective 2019-07-15 · S.F. Ordinance No. 107-19 (2019); S.F. Admin. Code ch. 19B
San Francisco became the first city in the United States to ban its own government — including police — from using facial recognition technology. The Board of Supervisors gave final passage 10-1 on June 4, 2019; the ordinance became law without the mayor's signature on June 14, 2019 and took effect July 15, 2019, codified at SF Admin. Code Chapter 19B. It also requires Board approval and public use policies before city departments acquire any other surveillance technology. Still in effect 2026 and the template for municipal facial-recognition bans nationwide.
-
In effect
Oakland Surveillance Ordinance & FR Ban
Oakland, CA · Oakland, Cal., Mun. Code ch. 9.64
Oakland requires City Council approval and public use policies before city agencies acquire any surveillance technology, and bans city use of facial recognition. In December 2020 the city added first-in-the-nation bans on predictive policing and other biometric surveillance (such as voice and gait recognition). Remains in effect, overseen by Oakland's Privacy Advisory Commission.
-
In effect
Portland (Maine) Facial Surveillance Ban
Portland, ME · Portland, Me., facial surveillance ban (Aug. 2020), as amended by Question B (Nov. 2020)
Portland, Maine's City Council banned city employees, including police, from using facial surveillance in August 2020, and voters strengthened the ban that November by passing Question B, which lets people sue the city for violations. Because it was enacted by referendum, the council could not amend it for five years. Remains in effect as of June 2026.
-
Blocked / in litigation
ACLU-WV v. Huntington (Flock contract mandamus)
Huntington, WV · Effective 2026-07-16 · ACLU-WV mandamus petition (relator Gregory Jimison) v. City of Huntington and Mayor Farrell, Cabell County Circuit Court, filed July 16, 2026
On July 16, 2026 — two days after the Huntington City Council approved a $2.1 million Flock Safety surveillance contract 6-4 — the ACLU of West Virginia filed a mandamus petition in Cabell County Circuit Court against the City of Huntington and Mayor Farrell seeking to block the contract. Rather than a constitutional privacy claim, the petition rests on a procurement/property-law theory challenging how the city entered the contract. The relator (the party on whose behalf mandamus is sought) is Huntington resident Gregory Jimison. The case is an early example of surveillance-contract litigation attacking the purchasing process itself.
-
In effect
Minneapolis rejects Skydio DFR contract 6-6 (Jul. 16, 2026)
Minneapolis, MN · Effective 2026-07-16 · Minneapolis City Council 6-6 deadlock, July 16, 2026, rejecting MPD Skydio drone-as-first-responder contract
On July 16, 2026, the Minneapolis City Council deadlocked 6-6 on a proposed contract with drone maker Skydio for a police drone-as-first-responder (DFR) program, killing the deal. The vote followed a 75-day free trial Skydio provided the Minneapolis Police Department in north Minneapolis. Council opposition centered on Skydio's sales to ICE and to Israel, and on data-leak concerns. The rejection ends, for now, MPD's path to a permanent DFR program, making Minneapolis one of the larger US cities to decline a police drone contract after piloting one.
-
In effect
Watchung Hills NJ AI policy 2365 (2026)
Watchung Hills Regional High School District, NJ · Effective 2026-07-14 · Watchung Hills Regional BOE Policy 2365 (adopted 2026-07-14)
Policy 2365 permits but does not mandate generative AI use, leaving per-assignment discretion to the teacher, who must state the permitted level using a three-tier AI Use Scale: Level 0 Red (no AI, individual effort only), Level 1 Yellow (AI-assisted brainstorming, outlining, grammar, clarity, tone and formatting) and Level 2 Green (co-creation with human oversight and demonstrated comprehension). Students must disclose and cite AI use under uniform district citation standards, including the prompt used or a link to the chat transcript where feasible. The policy prohibits submitting fully AI-generated work as one's own, generating deceptive content or imagery, harassment or misrepresentation via AI, and entering personally identifiable information — names, addresses, Social Security numbers, financial data, IEPs, photos or video — into public AI models.
-
In effect
LAPD lets Flock contract expire (Jul. 11, 2026)
Los Angeles, CA · Effective 2026-07-11 · LAPD Flock Safety contract expiration, July 11, 2026 (138 cameras; largest US department to end a Flock contract)
The Los Angeles Police Department let its contract with Flock Safety expire on July 11, 2026, shutting down its network of 138 Flock license plate reader cameras. Chief information officer Gialamas cited civil-liberties concerns and worries about immigration authorities' access to Flock data. LAPD is the largest US police department to break with Flock. The move caps a national trend: 82 Flock contracts were terminated nationwide between August 2021 and May 2026, 39 of them in the first five months of 2026 alone.
-
In effect
Kaukauna WI Flock non-renewal (announced Jul. 8, 2026)
Kaukauna, WI · Effective 2026-07-08 · Kaukauna, WI Flock Safety contract non-renewal, announced July 8, 2026 (contract expired June 2026)
The city of Kaukauna, Wisconsin announced on July 8, 2026 that it will not renew its contract with Flock Safety; the contract had expired in June. The police chief gave five reasons: fiscal responsibility, the loss of regional partner agencies that had shared the network, the department's inability to audit the system, security concerns, and reported misuse of Flock systems in other jurisdictions. The decision removes Flock license plate reader surveillance from the city and is indexed as a protective decision.
-
In effect
Blanchester OH schools AI policy EDEC (Jun. 29, 2026)
Blanchester, OH · Effective 2026-06-29 · Blanchester Local Schools (OH) Board of Education, policy EDEC adoption, June 29, 2026, under Ohio HB 96 mandate
The Blanchester Local Schools board in Clinton County, Ohio adopted a district artificial intelligence policy (policy EDEC) on June 29, 2026, meeting the July 1, 2026 deadline set by Ohio House Bill 96. HB 96 made Ohio the first state in the nation to require every school district to adopt an AI policy — the statewide mandate is the context that makes this small-district adoption notable. The policy governs AI use in the district under the state-mandated framework.
-
In effect
Portland Public Schools genAI pause (Jun. 23, 2026)
Portland, OR · Effective 2026-06-23 · Portland Public Schools (OR) Board of Education unanimous resolution via budget amendment, June 23, 2026, pausing generative AI expansion
The Portland Public Schools board in Oregon voted unanimously on June 23, 2026 to pause the expansion of generative AI in the district. Adopted as a budget amendment championed by board member La Forte, the resolution requires district staff to report back within 120 days on the district's inventory of generative AI tools, its contracts, and how vendors handle student data — and requires advance board authorization before the district signs any generative AI contract. The pause puts elected-board oversight between AI vendors and Oregon's largest school district while the data practices are examined.
-
In effect
Berkeley CA "The Berkeley Rule" AI Policy (2026)
Berkeley, CA · Effective 2026-03-10 · City of Berkeley, "The Berkeley Rule" and AI Use Framework for City Government (City Council action March 10, 2026)
On March 10, 2026, the Berkeley City Council adopted "The Berkeley Rule" — a ten-principle framework authored by Councilmember Ben Bartlett to guide ethical, human-centered use of AI in all city operations. Companion AI guidelines from Councilmember Shoshana O'Keefe require departments to apply bias safeguards, maintain data privacy compliance, and ensure human oversight of automated decisions before deployment. The City Manager's office subsequently drafted a formal AI Administrative Regulation implementing these principles.
-
In effect
San Jose ALPR 30-day retention safeguards (2026)
San Jose, CA · Effective 2026-03-10 · City of San Jose ALPR Use Policy Amendment (City Council unanimous vote, March 10, 2026)
On March 10, 2026, San Jose City Council voted unanimously to tighten safeguards on the city's network of 474 Flock Safety license-plate-reader cameras. The new rules cut the data retention period from one year to 30 days, restrict where cameras can be placed, and limit data-sharing with outside law enforcement agencies to documented criminal investigations. San Jose is the largest U.S. city to have adopted a Government AI Coalition framework, and this vote aligned its ALPR rules with its broader digital-privacy principles.
-
In effect
DPD FR Policy (2023 update)
Detroit, MI · Effective 2024-05-30 · DPD Directive 307.5 (2023, as updated)
Updated Detroit Police Department policy directive on facial recognition technology issued after the Robert Williams settlement, restricting FR matches as the sole basis for arrest and requiring corroborating evidence and supervisory review.
-
In effect
DC AI Values Mayor's Order
Washington, DC · Effective 2024-02-08 · D.C. Mayor's Order 2024-028 (Feb. 8, 2024)
Mayor Bowser's order requires DC government agencies to check any AI deployment against six AI Values: clear benefit to the people, safety and equity, accountability, transparency, sustainability, and privacy and cybersecurity. It created an AI Taskforce, set deadlines including a mandatory AI procurement handbook, and requires every agency to submit an AI strategic plan in cohorts through October 2026.
-
In effect
San Diego Surveillance Tech Ordinance
San Diego, CA · Effective 2022-08-23 · San Diego Mun. Code ch. 2, art. 10, div. 41 (Ord. O-21492, O-21493) (2022)
San Diego ordinance requiring City Council approval and a published use policy for any city surveillance technology, including the Smart Streetlights and ALPR programs, with a Privacy Advisory Board overseeing impact reports.
-
In effect
Portland City-Government FR Ban
Portland, OR · Effective 2020-09-09 · Portland, Or., city-bureau face recognition ban ordinance (Sept. 9, 2020)
Portland bans all city bureaus, including the Portland Police Bureau, from acquiring or using facial recognition technology. Adopted the same day as the separate private-sector ban; remains in effect as of June 2026.
-
In effect
Orlando Ends Rekognition Pilot
Orlando, FL · Effective 2019-07-18 · City of Orlando memo to City Council, July 18, 2019
City of Orlando and Orlando Police Department formally ended their pilot of Amazon Rekognition real-time facial recognition in 2018 after public backlash; OPD has not redeployed live FR since.
-
In effect
Tacoma Surveillance Ordinance
Tacoma, WA · Effective 2017-09-12 · Tacoma Mun. Code ch. 1.42 (Ord. 28427) (2017)
Tacoma ordinance requiring City Council approval and a public use policy before any city department acquires or uses surveillance equipment.
-
In effect
Seattle Surveillance Ordinance
Seattle, WA · Effective 2017-09-01 · Seattle Ordinance 125376 (2017), SMC ch. 14.18, as amended 2018
Seattle requires city departments to get City Council approval before acquiring or using surveillance technologies, supported by public Surveillance Impact Reports and review by a community working group. One of the earliest and most comprehensive municipal surveillance-oversight laws in the country.
-
In effect
Cambridge Surveillance Ordinance & FR Ban
Cambridge, MA · Cambridge, Mass., Mun. Code ch. 2.128, FR ban amendment (Jan. 13, 2020)
Cambridge requires City Council approval and impact reports before city departments use surveillance technology, and a unanimous January 2020 amendment banned city use of face surveillance. Surveillance impact reports were still being filed with the council in 2024–2025.
-
In effect
Brookline Face Surveillance Ban
Brookline, MA · Town of Brookline, Mass., General By-Laws (Warrant Art. 25, 2019)
Brookline's Town Meeting voted 179–8 in December 2019 to ban town government use of face surveillance, making it the fifth US municipality to do so. The by-law bars town departments, including police, from obtaining or using face surveillance systems.
-
In effect
Minneapolis FR Ban
Minneapolis, MN · Minneapolis, Minn., FR Ban Ordinance (Feb. 12, 2021)
Minneapolis bans city departments, including the police department, from procuring facial recognition technology or using data derived from it, with a council-approved exceptions process and annual reporting. No repeal or weakening amendment was found — the ordinance appears to remain in effect as of June 2026.
-
In effect
Madison Face Surveillance Ban
Madison, WI · Madison, Wis., Gen. Ordinances §§ 23.63–23.64
Madison bans city agencies, including police, from acquiring or using facial recognition technology, with narrow exceptions for identifying victims of human trafficking, child sexual exploitation, and missing children. Works alongside the city's surveillance technology ordinance requiring annual compliance reports.
-
In effect
Cleveland OH Flock 6-month renewal w/ data-sharing restrictions (Jul. 15, 2026)
Cleveland, OH · Effective 2026-07-15 · Cleveland, OH City Council 9-6 vote, July 15, 2026, six-month Flock Safety renewal with no-data-sharing and no-fusion-center conditions
Cleveland City Council voted 9-6 on July 15, 2026 to keep the city's Flock Safety license plate reader cameras for another six months — but attached new restrictions the prior contract lacked. Under the renewal, Flock data may not be shared with other governments or third parties, and access by the regional fusion center is cut off. The short six-month term functions as a probationary period. This entry indexes a surveillance deployment renewal; the new data-sharing restrictions are the operative oversight conditions.
-
In effect
Huntington WV Flock contract approved 6-4 (Jul. 14, 2026)
Huntington, WV · Effective 2026-07-14 · Huntington, WV City Council 6-4 vote, July 14, 2026, approving $2.1M Flock Safety surveillance contract
The Huntington, West Virginia City Council voted 6-4 on July 14, 2026 to approve a $2.1 million contract with Flock Safety for a citywide surveillance package: 40 automated license plate readers, 17 cameras, 2 drones, 2 gunshot detectors, and audio detection capability. The vote came after a council meeting that ran more than 8 hours, at which more than 50 residents spoke in opposition. This entry indexes a government AI surveillance deployment, not a protection; available coverage describes no independent oversight, audit requirement, or data-sharing restrictions attached to the approval. Two days later the ACLU of West Virginia filed a mandamus petition challenging the contract (see litig-aclu-wv-v-huntington-flock-2026).
-
In effect
Warren MI Flock renewal 4-3 ($132k/2yr, Jul. 14, 2026)
Warren, MI · Effective 2026-07-14 · Warren, MI City Council 4-3 vote, July 14, 2026, renewing Flock Safety contract (~$132,000 / 2 years) after reconsideration
The Warren, Michigan City Council renewed the city's Flock Safety license plate reader contract by a narrow 4-3 vote on July 14, 2026, after a reconsideration of an earlier vote. The renewal is worth about $132,000 over two years. Councilwoman Magee, who had previously supported the contract, flipped her vote to no on reconsideration — leaving the renewal to pass by a single vote. This entry indexes a surveillance deployment renewal; no new oversight conditions were reported with the renewal.
-
In effect
Fredericksburg VA Axon AI package w/ Draft One carve-out (Jul. 14, 2026)
Fredericksburg, VA · Effective 2026-07-14 · Fredericksburg, VA City Council authorization, July 14, 2026, of $1.9M/5-year Axon AI package (Draft One with critical-incident bar, translation, transcription, in-car cameras, mobile ALPR)
The Fredericksburg, Virginia City Council authorized a $1.9 million, five-year package with Axon on July 14, 2026 that adds AI capabilities across the police department: Draft One (Axon's generative AI police-report drafting tool), AI translation, transcription, in-car cameras, and mobile license plate readers. The package carries one notable guardrail: Draft One is optional for officers and is barred from use in critical incidents — meaning reports on the most serious events must be written by humans. Otherwise this entry indexes a government AI deployment.
-
In effect
Stanton CA authorizes OC Sheriff DFR 3-0-2 (Jul. 13, 2026)
Stanton, CA · Effective 2026-07-13 · Stanton, CA City Council 3-0-2 vote, July 13, 2026, authorizing OC Sheriff drone-as-first-responder program
The Stanton, California City Council voted 3-0 (with two abstentions) on July 13, 2026 to authorize the Orange County Sheriff's Department — which provides Stanton's police services — to run a drone-as-first-responder program in the city. Councilmember Torres abstained, citing surveillance and data-sharing concerns. Stanton and Cypress advanced police drone programs the same week. This entry indexes a government drone deployment; coverage reports no oversight or data-handling conditions attached to the authorization.
-
In effect
Metro Nashville Police Drones as First Responder Trial Progr
Nashville, TN (Metro Nashville Police Department) · Effective 2026-05-22 · Metro Nashville Police Drones as First Responder Trial Program
Metro Nashville Police runs a DFR trial using three Skydio drones dispatched only to specific emergency calls, with no facial recognition or routine patrol and non-evidentiary footage deleted after 7 days.
-
In effect
Board of Aldermen cancels Flock automated license-plate read
Weston, MO · Effective 2026-05-01 · Board of Aldermen cancels Flock automated license-plate reader (ALPR) camera contract after resident opposition
The Weston Board of Aldermen canceled a $45,000 contract for two Flock ALPR cameras roughly five months after approving it, following sustained resident privacy opposition, with no money paid.
-
In effect
Austin Transparent and Responsible Use of Surveillance Techn
Austin, TX · Effective 2026-04-23 · Austin Transparent and Responsible Use of Surveillance Technology (TRUST) Act
After letting its Flock ALPR contract expire in 2025, the Austin City Council passed the TRUST Act requiring council approval and public review before departments can acquire, use, or share data from surveillance technology like license plate readers and drones.
-
In effect
Tampa Police Department Drone as First Responder Program
Tampa, FL · Effective 2026-03-01 · Tampa Police Department Drone as First Responder Program
Tampa PD operates a Skydio-based DFR pilot in the Ybor and Downtown areas governed by Florida Statute 934.50, prohibiting facial recognition, weaponization, and warrantless surveillance of private areas.
-
In effect
Orlando Police Department Drone as First Responder Program (
Orlando, FL · Effective 2026-02-24 · Orlando Police Department Drone as First Responder Program (Axon contract approved by City Council)
Orlando City Council approved a $6.83M Axon DFR program on February 24, 2026, deploying 11 drones across 9 rooftop docking stations for automated 911-call response, governed by state law and limited to specific calls rather than mass surveillance.
-
In effect
Milwaukee Police Department self-imposed moratorium on facia
Milwaukee, WI · Effective 2026-02-06 · Milwaukee Police Department self-imposed moratorium on facial recognition technology
After sustained public opposition, the Milwaukee Police Department announced it would not use or acquire facial recognition technology pending a formal policy, a moratorium the Common Council can modify or reject.
-
In effect
Generative and Agentic AI in SFUSD (staff guidance)
San Francisco Unified School District, CA · Effective 2026-01-20 · Generative and Agentic AI in SFUSD (staff guidance)
San Francisco Unified published generative and agentic AI guidance for staff covering recommended uses, hallucination and privacy risks, and unreliability of AI plagiarism checkers, noting it is guidance rather than board-approved policy.
-
In effect
Police surveillance technology ordinance requiring annual pu
Columbia, MO · Effective 2025-12-31 · Police surveillance technology ordinance requiring annual public surveillance reports (Code Sec. 21-61)
Columbia's surveillance technology ordinance (Code of Ordinances Article IV, Sec. 21-61) requires the police department to document and publicly report its use of surveillance technology to the City Council each year, including data-sharing, complaints, and audit results.
-
In effect
Cambridge terminates Flock Safety ALPR contract for 'materia
Cambridge, MA · Effective 2025-12-09 · Cambridge terminates Flock Safety ALPR contract for 'material breach of trust'
After suspending its Flock cameras in October 2025 over fears data could reach ICE in violation of the city's sanctuary ordinance, Cambridge terminated the contract when Flock installed cameras without authorization.
-
In effect
San Marcos City Council votes to discontinue Flock Safety AL
San Marcos, TX · Effective 2025-12-02 · San Marcos City Council votes to discontinue Flock Safety ALPR contract
The City Council voted on December 2, 2025 to discontinue its Flock Safety contract, and all city-contracted Flock cameras were deactivated and removed as of February 1, 2026.
-
In effect
Township High School District 211
Palatine, IL · Effective 2025-10-13 · Township High School District 211 — AI Use Guidelines (2025-10-13)
D211 guidelines authorize district-vetted enterprise AI tools, bar student entry of PII into non-approved AI, require teacher disclosure of AI use, and prohibit AI as sole basis for grading or discipline.
-
In effect
Greenwich CT Public Schools
Greenwich, CT · Effective 2025-09-25 · Greenwich CT Public Schools — Generative AI Use Guidelines (2025-09-25)
District-adopted guidelines: enterprise Microsoft Copilot and Google Gemini for Education for staff and grades 9-12; bar on consumer AI with student data; AI disclosure expectation; ban on AI as sole basis for grading or discipline.
-
In effect
Durham NC Public Schools
Durham, NC · Effective 2025-09-25 · Durham NC Public Schools — Generative AI Acceptable Use Guidelines (2025-09-25)
DPS Board-reviewed guidelines authorize district-vetted enterprise AI tools, require teacher disclosure of AI use in instruction, bar non-consensual deepfakes, prohibit AI-only grading or discipline, and require parental consent for student AI accounts under 13. Anchored in Policy 3225/4312/7320 (Technology Responsible Use).
-
In effect
Iowa City Community School District
Iowa City, IA · Effective 2025-09-25 · Iowa City Community School District — Generative AI Use Guidelines and Board Policy 605.8R1 (effective September 2025)
Iowa City Community School District (ICCSD) guidelines authorize Microsoft Copilot enterprise on district devices; bar student entry of PII into non-approved AI; require teacher disclosure of AI use; and prohibit AI as sole basis for grading or discipline. The district also adopted Board Policy 605.8R1 governing student use of technology including AI.
-
In effect
Prince William County VA Public Schools
Manassas, VA · Effective 2025-09-17 · Prince William County VA Public Schools — Generative AI Use Procedures (2025-09-17)
District-wide procedures authorize Microsoft Copilot for staff and grades 9-12; ban use of consumer AI with student data; AI disclosure expected on graded work; AI cannot make special-education or discipline decisions without human review.
-
In effect
Prince George's County MD Public Schools
Upper Marlboro, MD · Effective 2025-09-15 · Prince George's County MD Public Schools — Generative AI Use Procedure (2025-09-15)
Procedure approved alongside Board Policy 0123: limits enterprise AI access to approved systems only, bars input of student PII or confidential employee records into AI tools, requires professional accountability for AI-generated content, and may result in disciplinary action for policy violations. The procedure is AP 0123, not AP 0500.
-
In effect
Newton MA Public Schools
Newton, MA · Effective 2025-09-15 · Newton MA Public Schools — Generative AI Use Guidance (2025-09-15)
Newton Public Schools guidance covers vetted enterprise AI tools, classroom disclosure norms, prohibition on AI-generated discipline or special-education decisions, and AI literacy thread in grades 6-12.
-
In effect
Oakland Unified School District
Oakland, CA · Effective 2025-09-10 · Oakland Unified School District — AI Acceptable Use Guidelines (2025-09-10)
Board-approved guidelines: enterprise tool list, ban on AI tools that train on student inputs, AI disclosure on assignments, AI cannot be sole basis for academic placement or discipline.
-
In effect
Cleveland Metropolitan School District
Cleveland, OH · Effective 2025-09-09 · Cleveland Metropolitan School District — AI Acceptable Use Policy (2025-09-09)
Board-adopted AUP: vetted tool list, ban on uploading student records to generative models, AI literacy added to high-school graduation pathway, AI tool vendors must pass district privacy review.
-
In effect
Baltimore City Public Schools
Baltimore, MD · Effective 2025-09-09 · Baltimore City Public Schools — Generative AI Use Guidance (2025-09-09)
City Schools districtwide guidance authorizes vetted enterprise AI tools, bars student entry of PII into non-approved AI, requires teacher disclosure of AI use in instruction, and prohibits AI as sole basis for grading or discipline. Anchored in Board Policy IIBE (Acceptable Use).
-
In effect
Fresno USD AI Guidance
Fresno, CA · Effective 2025-09-09 · Fresno USD AI Guidance (2025-09-09)
Fresno Unified School District publishes official AI guidance on the district's IT/AI department page: district-vetted GenAI tools authorized, PII entry into non-approved AI barred, teacher disclosure when AI is used in instruction required, AI prohibited as the sole basis for grading or discipline.
-
In effect
AUHSD AI Guidance
Anaheim, CA · Effective 2025-09-03 · AUHSD AI Guidance (2025-09-03)
Anaheim Union High School District board adopted an AI policy on September 3, 2025: authorizes Microsoft Copilot enterprise and Khanmigo in closed-loop configurations, bars PII entry into non-approved AI, requires teacher disclosure of AI use, and prohibits AI-generated impersonation of students or staff.
-
In effect
Volusia County FL Schools
DeLand, FL · Effective 2025-08-26 · Volusia County FL Schools — AI in the Classroom Guidelines (2025-08-26)
School Board Policy 428 and amendments to the Student Code of Conduct (Policy 208E/208S) govern AI use by Volusia County Schools staff and students. Students may use AI as a support tool for brainstorming, clarifying complex texts, or grammar assistance, but must cite AI assistance and may not submit AI-generated work as their own. Teachers may prohibit AI on specific assignments. The policy safeguards student data privacy and fosters equitable access; violations are handled under the district's existing disciplinary code.
-
In effect
Loudoun County VA Public Schools
Ashburn, VA · Effective 2025-08-26 · Loudoun County VA Public Schools — AI Use Guidelines (2025-08-26)
Largest NoVA-suburban district adopted guidelines: vetted enterprise AI tools, parental opt-in for student AI account creation grades 6-8, AI cannot be sole basis for placement or discipline, AI literacy integrated into K-12 ITRT curriculum.
-
In effect
Evanston deactivates 19 ALPR cameras and terminates Flock Sa
Evanston, IL · Effective 2025-08-26 · Evanston deactivates 19 ALPR cameras and terminates Flock Safety contract
Evanston deactivated all 19 of its Flock cameras and issued a termination notice effective September 26, 2025 after a state audit found Flock illegally shared Illinois data with U.S. Customs and Border Protection.
-
In effect
Naperville Community Unit School District 203
Naperville, IL · Effective 2025-08-25 · Naperville Community Unit School District 203 — AI Use Guidance (2025-08-25)
Affluent Chicago suburban district adopted AI guidance: enterprise tools authorized, ban on student AI account creation under 13, AI disclosure expected on graded work, AI cannot be sole basis for placement or discipline.
-
In effect
Public Schools of Brookline
Brookline, MA · Effective 2025-08-19 · Public Schools of Brookline — AI Acceptable Use & Data Privacy Procedure (2025-08-19)
Town of Brookline municipal policy governing use of generative AI tools by all Town Technology Resources users. Distinguishes constrained (contractually approved, confidentiality guaranteed) from unconstrained (consumer, no guarantees) tools. Prohibits inputting PII or protected health information into any generative AI tool. Requires IT Cybersecurity Team approval before use of any generative AI tool. Adopted by the Select Board and also approved by the School Committee.
-
In effect
Mesa Public Schools AZ
Mesa, AZ · Effective 2025-08-19 · Mesa Public Schools AZ — Generative AI Use Guidelines (2025-08-19)
Mesa Public Schools (Arizona's largest district) adopted districtwide GenAI guidelines: authorizes Microsoft Copilot enterprise and Khanmigo for grades 9-12; requires teacher disclosure of AI use; bars student entry of PII into non-approved AI; and ties violations to Governing Board Policy IJNDB (Acceptable Use).
-
In effect
Cherokee County GA School District
Canton, GA · Effective 2025-07-24 · Cherokee County GA School District — AI Use Procedure (2025-07-24)
Procedure approved with Board Policy IFBG update: enterprise AI authorized for staff and grades 9-12, no AI use for early-grade summative assessment, AI tools must be FERPA/COPPA compliant, AI use must be cited in graded work.
-
In effect
CTA ZeroEyes AI Gun-Detection Contract Expansion (250 to 1,5
Chicago Transit Authority (CTA) · Effective 2025-07-24 · CTA ZeroEyes AI Gun-Detection Contract Expansion (250 to 1,500 cameras)
The CTA board approved a $1.2M contract to expand ZeroEyes AI gun-detection software from 250 to 1,500 platform cameras by mid-2026, over civil-liberties objections about public input and effectiveness.
-
In effect
Lee's Summit MO
Lees Summit, MO · Effective 2025-06-17 · Lee's Summit MO — Generative AI Use Resolution (2025-06-17)
Council resolution establishes citywide AI use principles: human review, bar on PII entry into consumer AI, IT/legal vetting before procurement, and disclosure of AI assistance in resident-facing communications.
-
In effect
Resolution to expand surveillance cameras in public parks (o
City and County of Honolulu, HI · Effective 2025-06-04 · Resolution to expand surveillance cameras in public parks (one-year pilot)
The Honolulu City Council approved Resolution 3332 on June 4, 2025 launching a one-year pilot to expand public-park surveillance cameras from about 16 to roughly 45 parks, with 30-day footage retention and a required HPD effectiveness report to the Council.
-
In effect
Honolulu Police Department Automated License Plate Reader (A
City and County of Honolulu (Honolulu Police Department), HI · Effective 2025-06-01 · Honolulu Police Department Automated License Plate Reader (ALPR) Policy
The Honolulu Police Department maintains an official ALPR policy limiting use to law enforcement purposes, requiring a 90-day data purge, FBI-certified offsite storage, logged access, and Chief-of-Police approval for any non-law-enforcement sharing.
-
In effect
Culver City CA
Culver City, CA · Effective 2025-04-28 · Culver City CA — Generative AI Use Policy for City Staff (2025-04-28)
Council-adopted staff policy: enterprise Microsoft Copilot only; bar on entry of confidential/PII data into consumer AI; disclosure of AI assistance in public communications; review by IT/HR before deploying AI in personnel decisions.
-
In effect
Howard County MD Public School System
Ellicott City, MD · Effective 2025-03-03 · Howard County MD Public School System — AI Use Policy Statement & Policy 8080 Update (2025-03-03)
Board approved (January 30, 2025, effective March 3, 2025) modifications to Policy 8080 — Responsible Use of Technology, Digital Tools, and Social Media — restricting student personal device (cell phone) use during the school day for all PreK-12 students, with limited exceptions for documented IEP/504/health needs. The policy does not contain an explicit AI section; AI use is addressed only implicitly through broad digital-tools and academic-integrity language.
-
In effect
Olathe KS
Olathe, KS · Effective 2025-02-18 · Olathe KS — Generative AI Acceptable Use Policy (Council Adoption) (2025-02-18)
Council-adopted citywide AI acceptable use policy: bar on entry of confidential/PII data into consumer AI, required disclosure of AI assistance in public communications, IT review for any new AI procurement, and prohibition on AI as sole basis for personnel decisions.
-
In effect
San Diego Unified School District
San Diego, CA · Effective 2024-12-10 · San Diego Unified School District — Generative AI Use Guidelines (2024-12-10)
District guidelines: enterprise AI authorized for staff and grades 9-12, bar on consumer AI for student-data tasks, AI disclosure expectations, AI literacy integrated into K-12 educational technology standards.
-
In effect
Overland Park KS
Overland Park, KS · Effective 2024-12-02 · Overland Park KS — AI Acceptable Use Policy (2024-12-02)
Council adoption of citywide AI use policy with vetted-tool list, ban on PII entry into public AI, disclosure for AI-assisted public communications, and mandatory training before staff AI use.
-
In effect
Frederick MD
Frederick, MD · Effective 2024-11-21 · Frederick MD — City Generative AI Use Policy (2024-11-21)
Mayor & Board of Aldermen adoption: citywide AI policy with vetted-tool list, bar on PII entry into consumer AI, disclosure expectations for AI-assisted public communications, and IT review of AI procurement.
-
In effect
San Francisco Unified School District
San Francisco, CA · Effective 2024-11-12 · San Francisco Unified School District — Generative AI Use Guidelines (2024-11-12)
District guidelines authorize Microsoft Copilot enterprise for staff; bar student AI accounts under 13; require teacher disclosure when AI is used for instructional design; bar AI use to make discipline or placement decisions without human review.
-
In effect
Houston ISD Generative AI Guidebook
Houston Independent School District, TX · Effective 2024-11-01 · Houston ISD Generative AI Guidebook
Houston ISD released a comprehensive generative-AI guidebook with age-based access rules (supervised pre-approved tools under 14; 14+ with parental consent and teacher permission) plus data-privacy and academic-integrity guidance for students and staff.
-
In effect
Arlington VA Public Schools
Arlington, VA · Effective 2024-10-24 · Arlington VA Public Schools — Guidance on AI Use in APS (2024-10-24)
Districtwide guidance authorizes vetted enterprise tools (Microsoft Copilot, Google Gemini for Education), bars student PII entry into consumer AI, requires teacher disclosure to families when AI is used in instructional design, and prohibits AI as sole basis for grading or discipline.
-
In effect
Princeton NJ Public Schools
Princeton, NJ · Effective 2024-10-22 · Princeton NJ Public Schools — AI Use Guidelines (2024-10-22)
District guidelines: vetted enterprise AI list, prohibition on student AI chatbot use grades K-5, AI disclosure expectation on graded work, ban on AI as sole basis for academic placement decisions.
-
In effect
Ordinance prohibiting sale or use of algorithmic devices to
San Francisco, CA · Effective 2024-10-14 · Ordinance prohibiting sale or use of algorithmic devices to set rents (Administrative Code / Rent Ordinance Section 37.10C)
San Francisco, the first US city to do so, bans landlords from selling or using algorithmic revenue-management software that uses non-public competitor data to recommend rents or occupancy levels, with civil penalties up to $1,000 per violation plus damages and attorneys' fees.
-
In effect
Santa Clara County CA Office of Education
San Jose, CA · Effective 2024-10-10 · Santa Clara County CA Office of Education — AI Guidance for Member Districts (2024-10-10)
County-office guidance to 31 member districts: AI tool vetting framework, model staff/student use policies, data-privacy addendum template for AI vendors, and shared educator PD on responsible AI use.
-
In effect
Saint Paul Public Schools
Saint Paul, MN · Effective 2024-10-08 · Saint Paul Public Schools — Generative AI Acceptable Use Guidance (2024-10-08)
Guidance designates Google Gemini, NotebookLM, Seesaw, and Schoology PowerBuddy as approved AI tools for staff (offered through district accounts with enterprise protections), bars use of consumer AI tools with student data, requires teacher disclosure to families when AI is used for instructional design, and prohibits AI-generated discipline recommendations without administrator review.
-
In effect
Olympia WA
Olympia, WA · Effective 2024-09-24 · Olympia WA — Artificial Intelligence Use Policy (2024-09-24)
Council-approved AI use policy: enterprise Microsoft Copilot for staff; bar on consumer AI with city data; disclosure on public-facing AI-assisted materials; IT vetting for new AI tools.
-
In effect
Glendale CA
Glendale, CA · Effective 2024-09-17 · Glendale CA — Generative AI Use Policy (City Manager Directive) (2024-09-17)
City Manager directive adopted via Council action: requires departments to use only city-approved AI tools, disclose AI assistance in public communications, and route AI procurement through IT review. Surfaced through Glendale's PrimeGov agenda packet.
-
In effect
Forsyth County GA Schools
Cumming, GA · Effective 2024-09-12 · Forsyth County GA Schools — Generative AI Use Guidelines (Forsyth.AI initiative) (2024-09-12)
District 'Forsyth.AI' initiative pairs adopted use guidelines with a custom secure AI portal for staff and grades 6-12; bars PII entry into external models, requires teacher verification of AI output, and prohibits AI use to make student-discipline or special-education decisions.
-
In effect
Minneapolis Public Schools
Minneapolis, MN · Effective 2024-09-04 · Minneapolis Public Schools — AI Guidance for Educators (2024-09-04)
District-issued educator guidance: vetted tool list, ban on entering student IEP or behavior data into generative AI, AI must not be sole basis for academic placement or discipline, recommended classroom disclosure when AI is used to create materials.
-
In effect
Montgomery County MD Public Schools
Rockville, MD · Effective 2024-08-29 · Montgomery County MD Public Schools — Guidelines for Use of Artificial Intelligence (2024-08-29)
MCPS issued districtwide AI guidelines authorizing teacher use of vetted tools (Google Gemini for Education, Microsoft Copilot), barring student entry of personal data into GenAI, requiring teacher disclosure when AI generates student feedback, and prohibiting AI-only disciplinary or grading decisions. Implemented via Board Policy IGS (Educational Technology) administered through BoardDocs.
-
In effect
Policy 5110 - CCSD Policy on Generative Artificial Intellige
Chappaqua Central School District, NY · Effective 2024-08-29 · Policy 5110 - CCSD Policy on Generative Artificial Intelligence (AI) Integration
Chappaqua CSD's board-adopted GenAI policy prohibits district users from inputting FERPA-protected student data or Education Law 2-d protected information into AI systems, requires use of only Ed Law 2-d compliant approved tools with students, and mandates transparency about how AI is used.
-
In effect
Jefferson County CO Public Schools (Jeffco)
Golden, CO · Effective 2024-08-22 · Jefferson County CO Public Schools (Jeffco) — Guidelines for the Use of Generative AI (2024-08-22)
Districtwide guidelines: enterprise tools (Google Gemini for Education, Microsoft Copilot) authorized; bar on staff entering student data into consumer AI products; AI disclosure expectations for instructional materials; required AI literacy PD for staff.
-
In effect
Miami-Dade County Public Schools
Miami, FL · Effective 2024-08-15 · Miami-Dade County Public Schools — Generative AI Use and District Guidance (2024-08-15)
M-DCPS, the nation's third-largest district, adopted districtwide GenAI guidance directing approved tools (Google Gemini for Education, Microsoft Copilot enterprise), barring entry of student PII into non-approved models, and requiring teacher review of any AI-generated student-facing materials. Paired with M-DCPS Board Policy 7540.03 (Student Use of Technology) administered through BoardDocs.
-
In effect
CPS AI Guidebook (generative AI guidance for students, staff
Chicago Public Schools, IL · Effective 2024-08-01 · CPS AI Guidebook (generative AI guidance for students, staff, families, administrators)
Chicago Public Schools published an AI Guidebook giving human-in-the-loop generative-AI guidance for students, staff, families, and administrators, requiring teacher permission and AI-use citation by students and barring confidential data in AI tools.
-
In effect
Vancouver Public Schools Gaggle Safety Management Student Mo
Vancouver Public Schools, WA · Effective 2024-08-01 · Vancouver Public Schools Gaggle Safety Management Student Monitoring Contract
Vancouver Public Schools (WA) signed a $328,036 three-year Gaggle Safety Management contract to run AI monitoring of 24,000+ students' typing on district devices at school and at home to flag violence, self-harm, and safety concerns.
-
In effect
Detroit FR Policy Directive 307.5
Detroit, MI · Effective 2024-07-15 · Detroit Police Dep't Directive 307.5 (rev. June 28, 2024)
After three wrongful arrests of Black men from faulty facial recognition matches, Detroit settled a lawsuit and updated its policy: police cannot make an arrest based solely on a facial recognition match and must corroborate with independent evidence.
-
In effect
Long Beach CA
Long Beach, CA · Effective 2024-07-09 · Long Beach CA — Generative AI Guidance (Administrative Guidance, not a formal Council Acceptable Use Policy) (2024-07-09)
The City of Long Beach published a Generative AI Interim Guidance (now at version 1.3) as an administrative tool to help staff use generative AI safely and responsibly — covering risks around AI bias, data privacy, and cybersecurity. The guidance explicitly states it is not a policy or ordinance. The Legistar council-file URL in the original entry could not be confirmed via official search results.
-
In effect
MPD Unmanned Aircraft Systems Program (General Order 803.09)
Washington, DC (Metropolitan Police Department) · Effective 2024-06-01 · MPD Unmanned Aircraft Systems Program (General Order 803.09)
The DC Metropolitan Police Department launched its UAS program in June 2024 under General Order 803.09, prohibiting facial recognition and weaponization and barring targeting based on protected characteristics.
-
In effect
SFPD Unmanned Aircraft System (Drone) Program authorized und
San Francisco, CA · Effective 2024-05-16 · SFPD Unmanned Aircraft System (Drone) Program authorized under Proposition E (SF Admin Code 96I.2)
After voters passed Proposition E in March 2024, SFPD began operating drones for criminal investigations, vehicle pursuits, and critical incidents, with publicly available flight logs starting May 16, 2024.
-
In effect
Norfolk Flock ALPR Policy
Norfolk, VA · Effective 2024-05-01 · Norfolk PD Directive, Flock Safety ALPR (2024)
Norfolk Police Department directive governing use of Flock Safety automated license plate reader cameras, including retention, sharing, and audit requirements.
-
In effect
Dallas RTCC / Fusus Policy
Dallas, TX · Effective 2024-03-01 · Dallas PD General Order, Real-Time Crime Center (2024)
Dallas Police Department directive governing operation of the Real-Time Crime Center, including third-party Fusus camera integration and ALPR feeds, with retention and audit requirements.
-
In effect
Providence Police Department General Order 460.01 - Unmanned
Providence, RI · Effective 2024-03-01 · Providence Police Department General Order 460.01 - Unmanned Aircraft Systems (UAS) Operations
The Providence Police Department issued General Order 460.01 governing its UAS operations, a formal written policy setting the rules for drone deployment by the department.
-
In effect
Memphis SkyCop Surveillance Program
Memphis, TN · Effective 2024-01-01 · Memphis PD, SkyCop / RTCC Operational Policy (2023)
Memphis Police Department SkyCop and Real Time Crime Center policy governing operation of city-wide surveillance cameras, integrations, and retention.
-
In effect
SF Generative AI Guidelines
San Francisco, CA · Effective 2023-12-11 · CCSF, Generative AI Guidelines (Dec. 2023, rev. July 2025)
San Francisco's citywide generative AI guidelines apply to employees, contractors, consultants, volunteers, and vendors working for the city. They require human review and disclosure of AI-generated content, prohibit entering non-public information into AI tools, ban concealing AI use, and bar generating deepfake-style images, audio, or video. Most recently revised in July 2025.
-
In effect
Twin Falls Police Department Automated License Plate Reader
City of Twin Falls (Twin Falls Police Department), ID · Effective 2023-12-01 · Twin Falls Police Department Automated License Plate Reader (ALPR) program and policy
Since December 2023 the Twin Falls Police Department has operated 40 ALPR cameras under a published policy that captures only rear plates, purges data after 30 days unless tied to an investigation, restricts and logs access, and limits use to misdemeanor and felony cases.
-
In effect
Seattle Generative AI Policy
Seattle, WA · Effective 2023-11-01 · City of Seattle, GenAI Policy POL-209 (eff. Nov. 1, 2023)
Seattle's generative AI policy governs how city employees use tools like ChatGPT. It requires attribution of AI-generated work, human review of all AI output before release, and limits on feeding personal information into AI systems, built around seven principles including bias reduction, transparency, and explainability.
-
In effect
Peninsula School District AI Guidance (Principles and Belief
Peninsula School District, WA · Effective 2023-07-15 · Peninsula School District AI Guidance (Principles and Beliefs for AI Use)
One of the first US districts to publish AI guidance, Peninsula SD (WA) sets principles requiring staff to be diligent custodians of student data, cautions against unreliable AI detection tools, and mandates transparency and human oversight in all AI use.
-
In effect
SPD FR Policy
Seattle, WA · Effective 2023-07-01 · Seattle Police Manual §12.045 (2023)
Seattle Police Department Manual policy generally prohibiting SPD officers from using facial recognition technology, with no department-issued FR tools and a ban on requesting third-party FR queries.
-
In effect
Boston GenAI Guidelines
Boston, MA · Effective 2023-05-18 · City of Boston, Interim GenAI Guidelines v1.1 (May 18, 2023)
Boston was one of the first major US cities to issue generative AI guidance for its workforce. The interim guidelines tell city employees to never put confidential or personally identifying information into AI prompts, to fact-check all AI-generated content, and to disclose AI use, while encouraging responsible experimentation.
-
In effect
Portland Police Bureau Small UAS (Drone) Program authorized
Portland, OR · Effective 2023-04-05 · Portland Police Bureau Small UAS (Drone) Program authorized by City Council (Ordinance 191882)
Portland City Council authorized the Police Bureau to operate drones on April 5, 2023, expanded them citywide in September 2024, and launched a Drone as First Responder pilot in September 2025, with policy explicitly barring mass surveillance and facial recognition.
-
In effect
Privacy Protection and Technology Transparency Policy govern
Chula Vista, CA · Effective 2022-11-01 · Privacy Protection and Technology Transparency Policy governing the Real-Time Operations Center
Chula Vista's City Council adopted a privacy and technology-transparency policy and oversight commission governing how the police department's Real-Time Operations Center acquires surveillance tools and stores, shares, and profits from data such as drone and license-plate-reader feeds.
-
In effect
City of Warwick ordinance regulating ALPR technology systems
Warwick, RI · Effective 2022-10-01 · City of Warwick ordinance regulating ALPR technology systems (Chapter 52)
Warwick adopted an ordinance restricting automated license plate reader use to official law enforcement purposes, capping data retention at 30 days and barring sale or sharing of ALPR data with non-law-enforcement third parties.
-
In effect
Cheyenne Mountain SD 12 Verkada AI Facial-Recognition Camera
Cheyenne Mountain School District 12, CO · Effective 2022-08-01 · Cheyenne Mountain SD 12 Verkada AI Facial-Recognition Camera Surveillance System
Cheyenne Mountain SD 12 (Colorado Springs) deployed nearly 400 Verkada AI-enabled cameras with facial recognition to identify 'persons of interest,' installed before Colorado's 2022 statewide facial-recognition moratorium and allowed to continue under the grandfather provision.
-
In effect
Ordinance on Surveillance Oversight and Information Sharing
Boston, MA · Effective 2021-10-21 · Ordinance on Surveillance Oversight and Information Sharing
Boston bars police from acquiring, deploying, or newly repurposing surveillance technology without City Council approval and restricts sharing student information with police, complementing its earlier facial-recognition ban.
-
In effect
Ordinance banning city and police department use of facial r
Minneapolis, MN · Effective 2021-02-12 · Ordinance banning city and police department use of facial recognition technology
Minneapolis' City Council voted 13-0 to bar all city agencies, including the police department, from acquiring or using facial recognition technology or data derived from it.
-
In effect
New York Biometric Surveillance in Schools Moratorium (halti
Lockport City School District, NY · Effective 2020-12-22 · New York Biometric Surveillance in Schools Moratorium (halting Lockport CSD facial recognition system)
A first-in-the-nation state moratorium signed December 2020 halted the $2.7 million facial-recognition surveillance system that the Lockport City School District had activated in January 2020, pending a state privacy and demographic-accuracy review.
-
In effect
Surveillance Technology and Data Protection ordinance bannin
New Orleans, LA · Effective 2020-12-17 · Surveillance Technology and Data Protection ordinance banning NOPD facial recognition and predictive policing
New Orleans' City Council banned NOPD use of facial recognition, stingrays, and predictive policing in 2020, but the council rolled back the facial recognition ban to permit limited use in 2022.
-
In effect
Oakland City Council Drone Use Policy plus expanded biometri
Oakland, CA · Effective 2020-12-16 · Oakland City Council Drone Use Policy plus expanded biometric-surveillance and predictive-policing bans (amended Surveillance Transparency Ordinance)
On December 16, 2020, the Oakland City Council approved a drone use policy requiring annual reporting and, via revisions to its surveillance transparency ordinance, expanded its facial-recognition ban to other biometric surveillance and barred predictive-policing software.
-
In effect
Ordinance requiring City Council approval before police use
Pittsburgh, PA · Effective 2020-09-22 · Ordinance requiring City Council approval before police use of facial recognition and predictive policing technology
Pittsburgh's City Council barred the police bureau from obtaining or using facial recognition or predictive policing technology without prior City Council approval, functioning as a moratorium on new use.
-
In effect
Ordinance banning use of face recognition technologies by Ci
Portland, OR · Effective 2020-09-09 · Ordinance banning use of face recognition technologies by City of Portland bureaus
Portland's City Council unanimously banned all city bureaus, including police, from using or acquiring face recognition technology, with narrow device-unlock and redaction exceptions.
-
In effect
Portland Municipal Facial Recognition Ban (implicating the P
Portland, ME · Effective 2020-08-04 · Portland Municipal Facial Recognition Ban (implicating the Portland Jetport and ocean port)
Portland barred city use of facial recognition after debate over the city-run Jetport and ocean port, though the ban does not reach federal CBP use required for international-flight processing.
-
In effect
NYPD POST Act
New York City, NY · Effective 2020-07-15 · NYC Local Law 65 of 2020, as amended 2025
The POST Act requires the NYPD to publicly disclose what surveillance technologies it uses and publish impact and use policies for each one. 2025 amendments added facial recognition audits, itemized technology inventories, and disclosure of outside entities that receive NYPD surveillance data.
-
In effect
Ordinance banning face surveillance technology in Boston
Boston, MA · Effective 2020-06-24 · Ordinance banning face surveillance technology in Boston
Boston's City Council voted unanimously to ban city government, including police, from using face surveillance technology and from asking third parties to use it on their behalf.
-
In effect
Five-year moratorium on police and municipal use of face sur
Springfield, MA · Effective 2020-02-24 · Five-year moratorium on police and municipal use of face surveillance technology
Springfield's City Council voted 11-2 to impose a five-year moratorium barring the police department and other municipal agencies from using facial surveillance technology.
-
In effect
Ordinance banning municipal use of face surveillance technol
Cambridge, MA · Effective 2020-01-13 · Ordinance banning municipal use of face surveillance technology
Cambridge's City Council banned all city departments, including police, from using face surveillance technology, joining a wave of Massachusetts municipal bans.
-
In effect
Use of Surveillance Technology Ordinance (Ordinance 59300; M
Madison, WI · Effective 2020-01-01 · Use of Surveillance Technology Ordinance (Ordinance 59300; MGO 23.63)
Madison requires city agencies to notify the Mayor and Common Council and route surveillance-technology acquisitions through Council approval, plus annual public reporting on surveillance technology use.
-
In effect
Amendment to Surveillance and Community Safety Ordinance (Mu
Oakland, CA · Effective 2019-07-16 · Amendment to Surveillance and Community Safety Ordinance (Municipal Code Ch. 9.64) banning city/police face recognition
Oakland's City Council amended its surveillance ordinance to bar all city agencies, including police, from acquiring, using, or accessing facial recognition technology.
-
In effect
Face Surveillance Full Ban Ordinance
Somerville, MA · Effective 2019-06-27 · Face Surveillance Full Ban Ordinance
Somerville, as part of the CCOPS movement, unanimously banned any city department from using face-surveillance technology and barred use of face-recognition-derived data in municipal proceedings.
-
In effect
Face Surveillance Full Ban Ordinance prohibiting municipal u
Somerville, MA · Effective 2019-06-27 · Face Surveillance Full Ban Ordinance prohibiting municipal use of face recognition
Somerville's City Council unanimously banned any city department or agency, including police, from using face surveillance technology, making it the first East Coast city to do so.
-
In effect
San Francisco Acquisition of Surveillance Technology Ordinan
San Francisco Municipal Transportation Agency (SFMTA/Muni) · Effective 2019-05-14 · San Francisco Acquisition of Surveillance Technology Ordinance (facial-recognition ban covering Muni/SFMTA)
San Francisco's Surveillance Technology Ordinance bans city departments including the SFMTA/Muni from using facial recognition and requires surveillance-impact reports and annual use reports for surveillance tech.
-
In effect
Surveillance Technology Ordinance
Cambridge, MA · Effective 2018-12-10 · Surveillance Technology Ordinance
Cambridge bars city departments from funding, acquiring, or using surveillance technology without express City Council approval, requiring public impact reports, a use policy, and ongoing use reporting.
-
In effect
First U.S. Biometric Terminal (Maynard H. Jackson Internatio
City of Atlanta / Delta / CBP (Hartsfield-Jackson Atlanta International Airport, Terminal F) · Effective 2018-12-01 · First U.S. Biometric Terminal (Maynard H. Jackson International Terminal)
Delta, CBP, TSA and Hartsfield-Jackson opened the first end-to-end biometric terminal in the U.S., using facial recognition for check-in, bag drop, TSA screening, boarding, and CBP arrival.
-
In effect
Community Control Over Police Surveillance (CCOPS) Ordinance
Yellow Springs, OH · Effective 2018-11-19 · Community Control Over Police Surveillance (CCOPS) Ordinance
Yellow Springs requires the police or municipal agencies to present new surveillance technology to Village Council for a public-hearing cost-benefit review and a use policy before adoption, with annual reporting.
-
In effect
Chula Vista Police Department Drone as First Responder (DFR)
Chula Vista, CA · Effective 2018-10-01 · Chula Vista Police Department Drone as First Responder (DFR) Program and UAS Policy
Chula Vista PD launched the nation's first Drone as First Responder program in 2018, deploying drones to 911 calls under a policy that bars recording where people have a reasonable expectation of privacy absent a warrant or emergency.
-
In effect
San José AI Policy
San Jose, CA · City of San José Policy Manual § 1.7.12; GenAI Guidelines (2023, as updated)
San José adopted a citywide AI policy and generative AI guidelines governing how city staff use AI tools. Employees must register AI uses with the city's Privacy and AI team, may not let AI make actionable decisions about residents (like approving applications), and must review AI outputs. San José also founded the GovAI Coalition, whose AI policy templates have been adopted by 100+ public agencies.
-
In effect
Long Beach GenAI Guidance
Long Beach, CA · City of Long Beach, GenAI Guidance v1.3; AI Strategy (2025)
Long Beach's Smart City program issued Generative AI Guidance (now v1.3) for city staff, covering AI bias, data privacy, and cybersecurity, and in 2025 published a citywide AI Strategy committing to an AI use-case registry, workforce training, and community engagement. It builds on the city's council-approved 2021 Data Privacy Guidelines.
-
In effect
Pittsburgh GenAI Use Policy
Pittsburgh, PA · City of Pittsburgh internal GenAI policy (2023, updated 2024)
Pittsburgh adopted an internal policy on generative AI use by city staff, informed by the University of Pittsburgh's Task Force on Public Algorithms. It bars staff from entering private city data into tools like ChatGPT, prohibits AI use in applications that affect residents' rights or safety, forbids relying on generative AI for decisions, and requires AI use to be disclosed and logged.
-
In effect
Wake County NC Public School System
Raleigh, NC · Wake County NC Public School System — Generative AI Guidelines & Policy 6446 Revision (undefined)
Board-revised Policy 6446 (Internet/Online Services) plus standalone AI guidelines: district-approved AI tools list, K-5 prohibition on student-facing AI chatbots, required parental consent for student AI accounts grades 6-8, AI literacy requirement for grades 9-12.
-
In effect
New Orleans Surveillance/FR Rules
New Orleans, LA · New Orleans, La., Code ch. 147, as amended July 21, 2022
New Orleans banned facial recognition, predictive policing, and cell-site simulators in December 2020, but the council partially repealed the ban in July 2022, letting police use facial recognition (with human review and reporting) for serious violent crimes. In 2025 it emerged NOPD had received real-time facial recognition alerts from a private camera network in violation of these rules; alerts were paused in April 2025 and a proposal to authorize real-time FR was withdrawn, leaving the 2022 rules in place.
-
Expired
Oak Park Village Board votes 4-3 to terminate Flock Safety A
Oak Park, IL · Oak Park Village Board votes 4-3 to terminate Flock Safety ALPR contract
The Oak Park Village Board voted 4-3 on August 5, 2025 to cancel its Flock contract and deactivate eight ALPR cameras, citing privacy concerns and misuse of data for immigration enforcement in violation of state law and the village's sanctuary ordinance.
-
Expired
Santa Cruz City Council votes 6-1 to terminate Flock Safety
Santa Cruz, CA · Santa Cruz City Council votes 6-1 to terminate Flock Safety ALPR contract
The Santa Cruz City Council voted 6-1 to terminate its Flock contract with 30 days' notice after reports that plate data had been searched by out-of-state agencies on behalf of federal law enforcement including ICE in violation of state law.
-
Expired
Flagstaff City Council votes unanimously to end Flock Safety
Flagstaff, AZ · Flagstaff City Council votes unanimously to end Flock Safety ALPR program
The Flagstaff City Council voted unanimously on December 16, 2025 to terminate its Flock contract and immediately deactivate all 32 cameras, citing privacy, cybersecurity, public-records, and data-sharing concerns.
-
Expired
Eugene ends Flock Safety ALPR contract after council-ordered
Eugene, OR · Eugene ends Flock Safety ALPR contract after council-ordered pause
After the City Council voted 8-0 in October 2025 to pause the cameras over federal-misuse fears, Eugene Police ended the Flock contract on December 5, 2025 citing data-security and community-expectation concerns.
-
Expired
Denver ends Flock Safety ALPR contract and replaces vendor a
Denver, CO · Denver ends Flock Safety ALPR contract and replaces vendor amid data-sharing concerns
After Denver ended its Flock contract over privacy and federal data-sharing concerns, the City Council voted on March 31, 2026 to approve a smaller replacement ALPR contract with Axon, with several members demanding an ALPR-regulating ordinance first.
-
Expired
Hillsborough ends its relationship with Flock Safety ALPR ca
Hillsborough, NC · Hillsborough ends its relationship with Flock Safety ALPR cameras
Town leaders in Hillsborough, North Carolina ended the town's relationship with Flock Safety in October 2025 amid the wave of local governments dropping ALPR contracts over surveillance and immigration data-sharing concerns.
-
Proposed / pending
Guidance on Artificial Intelligence (preliminary 'traffic li
New York City Public Schools, NY · Guidance on Artificial Intelligence (preliminary 'traffic light' framework)
NYC Public Schools issued preliminary AI guidance using a green/yellow/red 'traffic light' framework that permits some staff and student uses, requires human review for others, and prohibits AI in grading, discipline, IEPs and placement decisions, with a fuller playbook to follow.
-
Proposed / pending
Oklahoma City Council to vote on renewing Flock Safety ALPR
Oklahoma City, OK · Oklahoma City Council to vote on renewing Flock Safety ALPR contract
The Oklahoma City Council is set to vote around July 7, 2026 on a third renewal of its Flock Safety automated license-plate-reader contract amid criticism that the department lacks a published ALPR policy.
-
Proposed / pending
Harrisonburg VA Flock termination pledge (vote Jul. 28, 2026)
Harrisonburg, VA · Harrisonburg, VA City Council pledge to end Flock Safety contract; formal vote scheduled July 28, 2026
Harrisonburg, Virginia City Council members, including Mayor Deanna Reed, have pledged to end the city's contract with Flock Safety, whose license plate reader cameras operate in the city. The contract expires in late July 2026, and the council scheduled a formal vote for July 28, 2026. If the council follows through, Harrisonburg joins the 2026 wave of cities dropping Flock. Indexed as proposed until the formal vote occurs.
-
Proposed / pending
Binghamton NY Flock termination legislation (in committee, Jul. 2026)
Binghamton, NY · Binghamton, NY City Council legislation to terminate Flock Safety contract, referred to committee July 13, 2026 (Cnclw. Rathmell)
A Binghamton, New York city councilwoman has introduced legislation to terminate the city's contract with Flock Safety, whose license plate reader cameras operate in the city. The measure, sponsored by Councilwoman Rathmell, was referred to committee on July 13, 2026 and awaits further action. If enacted, Binghamton would join the growing list of cities ending Flock contracts in 2026.
-
Proposed / pending
Ban biometric recognition in public accommodations (Ban The Scan)
New York City · NYC Int 0213-2026
Would make it illegal for places of public accommodation (stores, restaurants, music venues, theaters, etc.) to use biometric recognition systems to verify or identify customers without notice and prior written consent. Requires written policies governing use of collected biometric data and procedures for customers to request erasure of their biometric information.
-
Proposed / pending
Limit facial recognition in residential buildings (Ban The Scan)
New York City · NYC Int 0428-2026
Would prohibit owners of multiple dwellings from installing or using biometric recognition systems that identify tenants or their guests. Modifies existing smart-access regulations and adds new restrictions on facial recognition and related biometric technologies in residential settings.
-
Proposed / pending
DC SDAA (B25-0114)
Washington, DC · D.C. Council B25-0114 (proposed)
A DC Council bill that would ban using algorithms to discriminate based on race, sex, age, or disability in important life decisions such as employment, housing, credit, insurance, and education, and would require notice and audits.
-
Expired
Baltimore FR Ban (Expired)
Baltimore, MD · Effective 2021-09-08 · Baltimore, Md., Council Bill 21-0001 (2021) (expired Dec. 31, 2022)
Baltimore's 2021 ordinance banned private entities and individuals (and most city agencies) from using face surveillance systems, with criminal penalties. It contained a sunset clause and EXPIRED on December 31, 2022 when the City Council did not extend it. As of June 2026 the ban is no longer in effect; 2023 successor bills were not confirmed as enacted.