Home › Topics › AI disclosure and transparency
U.S. AI Laws: AI disclosure and transparency
As of 2026-08-12, AI Laws USA tracks 357 U.S. AI rules on AI disclosure and transparency across federal, state, county, and city government. Each entry links to its official source.
Federal AI disclosure and transparency rules (68)
-
In effect
COPPA + 2025 Rule (childrens data)
United States · Effective 2025-06-23 · 15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312
COPPA requires online services aimed at children under 13 to get verifiable parental consent before collecting kids' personal data. The 2025 rule update — fully in effect since April 22, 2026 — adds biometric identifiers (like face templates and voiceprints, which matter for AI tools), requires separate parental consent before sharing children's data for targeted advertising, and tightens data retention limits.
-
Blocked / in litigation
NetChoice v. Yost (Ohio)
S.D. Ohio · Effective 2025-04-16 · NetChoice, LLC v. Yost, No. 2:24-cv-00047 (S.D. Ohio Apr. 16, 2025)
Ohio's Social Media Parental Notification Act — requiring parental consent for minors' social-media use, including algorithmic feeds — was preliminarily enjoined on February 12, 2024, then permanently enjoined on April 16, 2025 when the district court granted summary judgment for NetChoice. The state appealed to the Sixth Circuit, which vacated the district court's injunction in 2026.
-
In effect
Thaler v. Perlmutter (Copyright)
D.C. Cir. · Effective 2025-03-18 · Thaler v. Perlmutter, 130 F.4th 1039 (D.C. Cir. 2025)
The companion copyright case: Stephen Thaler sought to register a copyright with 'Creativity Machine' (his AI) as the author. The D.C. Circuit affirmed in March 2025 that the Copyright Act's human-authorship requirement is dispositive as a matter of statutory law. AI cannot be a copyright author under U.S. law.
-
In effect
Thaler v. Vidal (DABUS)
Fed. Cir. · Effective 2022-08-05 · Thaler v. Vidal, 43 F.4th 1207 (Fed. Cir. 2022), cert. denied, 143 S. Ct. 1783 (2023)
Stephen Thaler, inventor of the 'DABUS' AI system, sought to list DABUS as the inventor on two patent applications. The Federal Circuit ruled in August 2022 that under the Patent Act 'inventor' must be a natural person. The Supreme Court denied certiorari in April 2023, settling U.S. law: AI systems cannot be inventors of record.
-
In effect
ECOA / Regulation B (AI credit discrimination)
United States · Effective 1975-10-28 · 15 U.S.C. § 1691; 12 C.F.R. Part 1002
Lenders cannot discriminate in credit decisions and must give you specific, accurate reasons when they deny or worsen your credit — even if the decision was made by an AI model. Earlier CFPB guidance said lenders can't hide behind 'black box' algorithms; that guidance was withdrawn in May 2025, but the underlying statute and regulation still require accurate adverse-action notices.
-
In effect
FCRA (AI in credit & background checks)
United States · Effective 1971-04-25 · 15 U.S.C. § 1681 et seq.
When a company uses a consumer report or score — including AI-generated risk scores from background-check and tenant/employment screening firms — to deny you credit, insurance, housing, or a job, it must tell you and identify the agency that supplied the report. You have the right to a free copy of your file and to dispute inaccurate information, no matter how algorithmic the scoring was.
-
In effect
Title VII / ADA (AI hiring)
United States · Effective 1965-07-02 · 42 U.S.C. § 2000e et seq.; 42 U.S.C. § 12101 et seq.
Federal anti-discrimination law applies when employers use AI tools to screen resumes, score interviews, or rank candidates: if an AI tool disproportionately screens out people by race, sex, disability, or other protected traits, the employer can be liable. The EEOC's specific AI guidance documents from 2023 were removed in January 2025, but the underlying laws are unchanged and still enforceable.
-
In effect
FTC Act Section 5 (unfair/deceptive AI)
United States · Effective 1914-09-26 · 15 U.S.C. § 45
The FTC's basic consumer-protection law bans unfair or deceptive business practices, and the agency applies it directly to AI. Companies cannot lie about what their AI can do, use AI to deceive people, or sell AI tools designed for fraud. The FTC's 'Operation AI Comply' sweep has brought numerous cases since 2024.
-
Blocked / in litigation
Hachette v. Google (Gemini AI copyright)
United States · Effective 2026-07-10 · Hachette Book Group Inc. et al. v. Google LLC, No. 1:26-cv-05870 (S.D.N.Y., filed July 10, 2026)
Hachette Book Group, Cengage Learning, Elsevier, and author Scott Turow filed a copyright class action against Google in the Southern District of New York on July 10, 2026 (No. 1:26-cv-05870), alleging Google used millions of copyrighted books and academic journal articles without authorization to train its Gemini AI models. The complaint alleges Google misused works supplied for Google Books 'snippet' access to copy full texts for AI training, also sourcing material from pirate websites. An internal Google document cited in the complaint estimates potential copyright exposure of $10 billion to $100 billion. The case is distinct from (and does not overlap with) the existing NYT v. OpenAI and Authors Guild v. OpenAI suits.
-
Blocked / in litigation
NetChoice v. Bonta (SB 976)
N.D. Cal. · Effective 2024-12-31 · NetChoice, LLC v. Bonta, No. 5:24-cv-07885 (N.D. Cal.)
NetChoice (the tech-industry trade group) challenged California's SB 976 — which would have restricted addictive algorithmic feeds for minors — and won a preliminary injunction blocking key portions on First Amendment grounds in December 2024. The 9th Circuit is reviewing.
-
In effect
FTC v. IntelliVision
FTC · Effective 2024-12-19 · In re IntelliVision Techs. Corp., FTC No. C-4813 (Dec. 19, 2024)
The FTC settled with IntelliVision in December 2024, alleging the company falsely claimed its facial-recognition product had 'zero gender or racial bias' without testing-data to support that — and that its accuracy claims were unsubstantiated. Builds on the FTC's Rite Aid theory.
-
In effect
FDA PCCP Guidance (AI/ML devices)
United States · Effective 2024-12-04 · FDA Guidance (Dec. 4, 2024); 21 U.S.C. § 360e-4
FDA finalized a framework that lets manufacturers update an AI-enabled medical device after clearance without filing a new submission for each change — but only if they pre-specify what changes are allowed, how they'll be validated, and how transparency to clinicians and patients will be preserved.
-
In effect
FTC v. Evolv
FTC · Effective 2024-11-26 · Federal Trade Commission v. Evolv Technologies Holdings, Inc., No. 1:24-cv-12940 (D. Mass. Nov. 26, 2024)
The FTC settled with Evolv Technology in November 2024 over claims it falsely marketed its AI-powered scanners as accurately detecting weapons in schools and venues, when in fact the systems missed weapons (including the knife in the Utica, NY school stabbing) and flagged everyday objects. Customers can cancel contracts.
-
In effect
FTC v. DoNotPay
FTC · Effective 2024-09-25 · In re DoNotPay, Inc., FTC No. C-4796 (Sept. 25, 2024)
The FTC settled with 'AI lawyer' DoNotPay in September 2024 over claims the company falsely marketed an AI chatbot as a substitute for a human lawyer, without ever testing whether its outputs matched a competent attorney's work. Part of the FTC's 'Operation AI Comply' sweep.
-
In effect
FTC v. Rytr
FTC · Effective 2024-09-25 · In re Rytr LLC, FTC No. C-4795 (Sept. 25, 2024)
Part of Operation AI Comply: the FTC ordered AI writing service Rytr to stop offering a 'testimonial and review' generator that produced fake consumer reviews on demand. The first FTC action against an AI product specifically designed to generate deceptive content.
-
In effect
FTC Operation AI Comply (Sept. 2024)
FTC · Effective 2024-09-25 · FTC Press Release, Operation AI Comply (Sept. 25, 2024)
On September 25, 2024 the FTC announced 'Operation AI Comply' — a coordinated sweep against five companies (DoNotPay, Rytr, Ascend Ecom, Ecommerce Empire Builders, FBA Machine) accused of using AI claims to defraud consumers. Marked the FTC's first systemic AI enforcement sweep.
-
Blocked / in litigation
CCIA v. Paxton (TX SCOPE)
W.D. Tex. · Effective 2024-08-30 · CCIA v. Paxton, No. 1:24-cv-00849 (W.D. Tex.)
The Computer & Communications Industry Association and NetChoice partially enjoined Texas's SCOPE Act (HB 18), which restricts targeted advertising and algorithmic content curation for minors, before its September 2024 effective date.
-
In effect
FTC v. NGL Labs
FTC · Effective 2024-07-09 · United States v. NGL Labs, LLC, No. 2:24-cv-05753 (C.D. Cal. July 9, 2024)
The FTC and the Los Angeles DA settled with anonymous-messaging app NGL Labs for $5M in July 2024, alleging the company used fake AI-generated 'anonymous' messages to manipulate teen users into paying for premium features that wouldn't actually reveal sender identities. NGL is banned from marketing to under-18 users.
-
In effect
OFCCP AI Selection Guidance
United States · Effective 2024-04-29 · OFCCP AI EEO Guidance (Apr. 29, 2024)
Federal contractors using AI in hiring must comply with OFCCP nondiscrimination requirements: vendor due diligence, recordkeeping, validation under the Uniform Guidelines on Employee Selection Procedures, and accommodations for applicants with disabilities. OFCCP makes clear contractors cannot outsource liability to AI vendors.
-
In effect
SEC AI-washing settlement
United States · Effective 2024-03-18 · In re Delphia (USA) Inc., Securities Act Rel. No. 11264 (Mar. 18, 2024); In re Global Predictions Inc., Securities Act Rel. No. 11265 (Mar. 18, 2024)
The SEC charged two investment advisers — Delphia (USA) and Global Predictions — with making false and misleading statements about using AI and machine learning. The firms paid $400,000 combined in civil penalties. It was the SEC's first 'AI-washing' enforcement action and signals scrutiny of overstated AI capability claims in financial services.
-
Blocked / in litigation
NYT v. OpenAI / Microsoft
S.D.N.Y. · Effective 2023-12-27 · The New York Times Co. v. Microsoft Corp., No. 1:23-cv-11195 (S.D.N.Y.)
The New York Times sued OpenAI and Microsoft in December 2023, alleging the companies copied millions of Times articles to train GPT models and that ChatGPT regurgitates Times content verbatim. The case is the most consequential of the news-publisher AI training-data suits and is in discovery; in March 2025 Judge Sidney Stein largely denied OpenAI's motion to dismiss, allowing the direct, contributory, and DMCA claims to proceed. On July 9, 2026, the NYT and Daily News filed a motion to sanction OpenAI, alleging OpenAI concealed evidence. On August 6, 2026, Judge Stein denied the NYT's motion to amend its complaint to add Microsoft-specific contributory infringement claims, ruling the motion was untimely given the US Supreme Court's March 2026 ruling raising the bar for platform liability.
-
In effect
Drone Remote ID Rule
United States · Effective 2023-09-16 · 14 C.F.R. Part 89; 86 Fed. Reg. 4390 (Jan. 15, 2021)
Most drones flying in U.S. airspace must broadcast a digital 'license plate' — Remote ID — that includes the drone's ID, location, altitude, and the control station's location, so law enforcement and the public can identify drones in the sky.
-
In effect
CFPB § 1071 Rule (small-biz AI lending)
United States · Effective 2023-08-29 · 12 C.F.R. Part 1002 Subpart B; 88 Fed. Reg. 35150
Lenders covered by the rule must collect and report demographic and transactional data on small-business credit applications — including data needed to detect algorithmic discrimination by AI underwriting models.
-
In effect
Mata v. Avianca (ChatGPT fake cites)
S.D.N.Y. · Effective 2023-06-22 · Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023)
Two New York attorneys submitted a brief containing six fictitious case citations generated by ChatGPT. In June 2023 Judge P. Kevin Castel sanctioned them $5,000 each — the first formal federal sanction for AI-hallucinated legal citations, and the most-cited case in subsequent bar opinions on attorney AI use.
-
In effect
DoD Directive 3000.09 (LAWS)
United States · Effective 2023-01-25 · DoDD 3000.09 (2023)
The Defense Department's policy on autonomous and semi-autonomous weapons. Updated in January 2023, it requires every autonomous or semi-autonomous weapon system to allow 'appropriate levels of human judgment over the use of force,' undergo a multi-phase senior review before development and fielding, and comply with DoD AI ethical principles.
-
In effect
NHTSA SGO 2021-01 (AV/ADAS reporting)
United States · Effective 2021-06-29 · NHTSA SGO 2021-01
Manufacturers and operators of vehicles equipped with SAE Level 2 driver-assistance (Tesla Autopilot, GM Super Cruise) or Level 3-5 automated driving systems must report crashes to NHTSA on a strict timeline — within one day for serious crashes. The data drives recall actions including Tesla's Dec. 2023 over-the-air Autopilot recall.
-
In effect
Robles v. Domino's
9th Cir. · Effective 2019-10-07 · Robles v. Domino's Pizza, LLC, 913 F.3d 898 (9th Cir. 2019), cert. denied, 140 S. Ct. 122
While predating modern generative AI, the Ninth Circuit's 2019 Robles v. Domino's ruling — followed by Supreme Court cert. denial — established that ADA Title III applies to web and mobile apps that interact with brick-and-mortar services. The decision is now the doctrinal anchor for AI chatbot and voice-assistant accessibility claims.
-
In effect
Trump AI Innovation & Security EO (June 2026)
United States · Effective 2026-06-02 · E.O. (June 2, 2026) — Promoting Advanced Artificial Intelligence Innovation and Security
President Trump signed an executive order on June 2, 2026, directing frontier AI developers to voluntarily share new models with the federal government 30 days before public release for national-security review. The order also directs CISA to build an AI cybersecurity framework and tasks DOJ with prioritizing criminal enforcement of AI-enabled fraud. No binding requirements apply to private AI developers — the framework is voluntary.
-
Proposed / pending
NAIC AI Evaluation Tool Pilot (12 states, 2026)
United States · Effective 2026-03-02 · NAIC Big Data and AI (H) Working Group — AI Systems Evaluation Tool Pilot (launched March 2, 2026)
The National Association of Insurance Commissioners launched a 12-state pilot program in March 2026 to test a new 'AI Systems Evaluation Tool' — a standardized framework giving insurance examiners a structured method to assess how insurance companies govern their AI systems during market conduct and financial examinations. The 12 participating states are California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. The tool requires insurers to complete four exhibits: one quantifying AI usage, one assessing governance risk, one detailing high-risk AI systems, and one documenting AI data practices. The pilot runs through September 2026, with tool updates through October 2026 and formal NAIC adoption expected at the Fall National Meeting in November 2026.
-
In effect
EPA AI Strategic Plan
United States · Effective 2025-10-30 · EPA AI Strategy (Oct. 30, 2025)
EPA's AI Strategic Plan governs the use of AI for environmental enforcement, pollution monitoring, satellite imagery analysis, and permit review — establishing risk classifications and human-review requirements for AI in enforcement decisions.
-
In effect
Federal AI Executive Orders
United States · Effective 2025-01-23 · Exec. Order 14179 (Jan. 23, 2025); Exec. Order of Dec. 11, 2025
The current federal posture is deregulatory: EO 14179 (January 2025) revoked the prior AI safety order and directed agencies to remove AI rules seen as barriers to innovation, leading agencies like the EEOC and CFPB to pull AI guidance. A December 11, 2025 executive order directs the DOJ to challenge state AI laws and pushes for a uniform federal framework — but it does not itself preempt state laws, which remain in force absent congressional action or court rulings.
-
Repealed / replaced
OMB M-24-18 (superseded by M-25-22)
United States · Effective 2024-10-03 · OMB M-24-18 (Oct. 3, 2024)
OMB's original federal AI acquisition memo set rules for how agencies buy AI, including performance testing, vendor competition, and IP protections for federal AI use cases. Superseded by M-25-22 in April 2025 but established the federal baseline for AI procurement still in effect through M-25-22.
-
In effect
GSA AI Procurement Guide
United States · Effective 2024-09-24 · GSA AI Guide for Government (2024)
GSA's AI procurement guide gives federal contracting officers a step-by-step playbook for buying AI — including risk classification, vendor due diligence, evaluation criteria, and contract clauses that comply with OMB M-25-22.
-
Repealed / replaced
Battle v. Microsoft
D. Md. · Effective 2024-08-22 · Battle v. Microsoft Corp., No. 1:23-cv-01822 (D. Md.)
Aerospace consultant Jeffery Battle sued Microsoft alleging Bing/Copilot conflated him with a convicted terrorist of the same name. The case was dismissed in 2024 — among the early dismissals signaling that AI hallucination defamation suits face uphill battles on actual malice and statement-of-fact grounds.
-
In effect
NTIA Open Weights Report
United States · Effective 2024-07-30 · NTIA Open Weights Report (July 30, 2024)
NTIA's open-weights report concluded that the federal government should monitor — but not currently restrict — the public release of advanced AI model weights. It established the federal policy baseline that open AI models offer competitive and research benefits that outweigh current risks.
-
In effect
NIST GenAI Profile (AI 600-1)
United States · Effective 2024-07-26 · NIST AI 600-1
NIST's voluntary GenAI Profile is the leading federal playbook for managing risks unique to generative AI: hallucinations, harmful content, intellectual property leakage, data poisoning, and CBRN misuse. Federal contractors and many enterprises adopt it as the de facto AI risk-management baseline.
-
In effect
FINRA AI Notice 24-09
United States · Effective 2024-06-27 · FINRA Reg. Notice 24-09 (June 27, 2024)
FINRA reminded broker-dealers that existing rules — supervision, recordkeeping, advertising, and anti-fraud — apply fully to AI tools, including generative AI used for customer communications, surveillance, and trading. Firms misrepresenting AI capabilities or failing to supervise AI outputs face enforcement.
-
In effect
NTIA AI Accountability Report
United States · Effective 2024-03-27 · NTIA AI Accountability Report (Mar. 27, 2024)
The Commerce Department's NTIA released the federal government's flagship policy report on AI accountability — concluding that independent AI audits, evaluations, and disclosure mechanisms are essential and recommending federal investment in the AI accountability ecosystem.
-
In effect
NIST AISI / AISIC
United States · Effective 2024-02-08 · NIST AISI Charter (Feb. 8, 2024)
NIST stood up the U.S. AI Safety Institute and a consortium of AI developers, civil-society groups, and academic labs to develop technical guidance, test methodologies, and safety evaluations for advanced AI models — including red-teaming and dual-use foundation model evaluation.
-
In effect
CFTC AI trading-scam advisory
United States · Effective 2024-01-25 · CFTC OCEO Customer Advisory (Jan. 25, 2024)
The Commodity Futures Trading Commission warned consumers about AI-related investment scams — fraudsters promising guaranteed returns from AI trading bots, AI-generated celebrity endorsements, and AI-themed pump-and-dump schemes in crypto and forex markets. The advisory laid the groundwork for CFTC enforcement against AI-touted commodity fraud.
-
In effect
NSF NAIRR Pilot
United States · Effective 2024-01-24 · NSF NAIRR Pilot (Jan. 24, 2024)
NSF's NAIRR pilot is a two-year initiative providing U.S. academic researchers with shared access to compute, data, and AI models — establishing federal terms for responsible AI research, including bias evaluation, model documentation, and access guardrails.
-
In effect
NAIC AI Model Bulletin (Insurance)
United States · Effective 2023-12-04 · NAIC Model Bulletin: Use of AI Systems (Dec. 4, 2023); NAIC Impl. Map (Apr. 2025)
The National Association of Insurance Commissioners adopted a Model Bulletin in December 2023 directing insurers to govern their AI responsibly — documenting AI systems, testing for bias, and overseeing third-party AI vendors. As of early 2026, over half of U.S. states and D.C. have adopted the bulletin through their own state insurance departments, making it the broadest AI governance standard in the insurance sector. It is not a federal law and has no penalties on its own, but state commissioners use it as a market-conduct examination standard.
-
In effect
ED AI in Education Report
United States · Effective 2023-05-24 · ED OET Report (May 24, 2023)
The Education Department's first major AI report set federal policy direction for AI in K-12 and higher education — calling for human-centered design, educator oversight, equity safeguards, and a moratorium on high-stakes uses of AI to evaluate students or teachers without strong evidence and oversight.
-
In effect
FDA AI Drug/Bio Guidance
United States · Effective 2023-05-10 · FDA Discussion Paper (May 2023); CDER/CBER Draft Guidance (Jan. 2025)
FDA published a framework setting expectations for how drug and biologics companies use AI/ML across drug discovery, clinical trials, postmarket safety surveillance, and manufacturing. The framework signals that AI used in regulatory submissions must be transparent, validated, and reproducible.
-
In effect
NIST AI RMF (voluntary AI risk framework)
United States · Effective 2023-01-26 · NIST AI 100-1 (AI RMF 1.0); NIST AI 600-1
A voluntary federal framework that helps organizations identify, measure, and manage risks from AI systems — including bias, safety, and security issues. It creates no legal rights for individuals, but it has become the de facto standard referenced by regulators, several state AI laws, and federal contractors.
-
In effect
TSA Facial Comparison Technology (CAT-2 / Traveler Verificat
United States · Effective 2023-01-01 · TSA Facial Comparison Technology (CAT-2 / Traveler Verification Service)
TSA uses CAT-2 camera units at 350+ airport checkpoints to compare a live photo of a traveler to their ID photo (or to a CBP TVS gallery), with signage stating participation is voluntary and travelers may decline.
-
In effect
FY23 NDAA §7224B (civilian AI inventory)
United States · Effective 2022-12-23 · Pub. L. No. 117-263, §7224B (Dec. 23, 2022)
Section 7224B of the FY23 NDAA (Pub. L. 117-263, the James M. Inhofe NDAA for FY23) extended the federal AI use case inventory requirement from EO 13960 to non-CFO Act civilian agencies and required updated procurement guidance from GSA. Quiet but significant — broadened federal AI transparency baseline beyond defense and major civilian agencies.
-
In effect
OSTP AI Bill of Rights Blueprint
United States · Effective 2022-10-04 · OSTP Blueprint (October 2022)
The Blueprint laid out five non-binding principles for protecting Americans from automated systems: safe and effective systems, algorithmic discrimination protections, data privacy, notice and explanation, and human alternatives. It remains the most widely cited federal articulation of AI rights and is referenced by state AI laws.
-
In effect
Interagency AI/ML Risk Mgmt (OCC/Fed/FDIC)
United States · Effective 2021-03-31 · 86 Fed. Reg. 16837; SR 11-7; OCC Bulletin 2011-12
Banking regulators issued a joint request for information setting their supervisory expectations for banks using AI and machine learning — covering model risk, fair lending, third-party AI vendors, and consumer-protection compliance. The 2011 model-risk-management guidance (SR 11-7) governs AI underwriting models.
-
In effect
AI in Government Act (2020)
United States · Effective 2020-12-27 · Pub. L. No. 116-260, Div. U, Title I, §104 (Dec. 27, 2020); 40 U.S.C. §11301 note
Enacted as part of the Consolidated Appropriations Act 2021 (Dec. 27, 2020), the AI in Government Act of 2020 created the GSA AI Center of Excellence, directed OMB to issue federal AI use guidance, and required OPM to establish federal AI workforce occupational series. One of three enacted pre-2024 federal AI statutes — foundational federal procurement and workforce architecture.
-
Enacted (not yet in effect)
FERC order directing PJM and other grid operators to reform
United States · FERC order directing PJM and other grid operators to reform tariffs on large-load (data center) transmission cost allocation (Docket RM26-4-000)
FERC ordered PJM and other regional grid operators to revise or defend their tariffs within 60 days to prevent existing ratepayers from being unlawfully charged for transmission upgrades required to serve large new loads such as AI data centers.
-
Proposed / pending
FTC Proposed Policy Statement — AI Accuracy (July 2026)
United States · FTC Proposed Policy Statement on Suppression of Accuracy in AI Systems, 91 Fed. Reg. ___ (July 7, 2026) (Docket 2026-13628)
The Federal Trade Commission published a proposed policy statement in the Federal Register on July 7, 2026 warning that AI companies that steer outputs toward undisclosed ideological objectives (rather than user-requested accuracy) may be engaging in deceptive practices under Section 5 of the FTC Act. The statement was issued pursuant to a Trump Executive Order directing the FTC to clarify how Section 5 applies to AI. Notably, the proposed statement also suggests that state laws requiring AI systems to alter outputs — including some state AI bias and accuracy mandates — may conflict with federal consumer protection law, raising preemption concerns. Public comments are due July 31, 2026. The statement is proposed, not final, and does not itself impose any legal obligations.
-
Enacted (not yet in effect)
2026-16371
United States · NIST 2026-16371
The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.
-
In effect
Copyright Office AI Guidance
United States · 17 U.S.C. § 102; U.S. Copyright Office, Copyright and AI Reports (2024–2025)
The U.S. Copyright Office has ruled that purely AI-generated works cannot be copyrighted — human creativity is required, and typing prompts alone is not enough. Its multi-part AI report covers digital replicas (2024), copyrightability of AI outputs (Jan 2025), and AI training on copyrighted works (May 2025 pre-publication). Whether AI training is fair use is being decided in ongoing litigation.
-
Proposed / pending
Traveler Privacy Protection Act of 2025 (S.1691)
United States · Traveler Privacy Protection Act of 2025 (S.1691)
This pending bipartisan Senate bill would guarantee travelers the right to opt out of TSA facial recognition at airports, bar worse treatment for opting out, and limit retention and secondary use of face data.
-
Proposed / pending
FTC CARS Rule (AI auto)
United States · 16 C.F.R. Part 463; 89 Fed. Reg. 590
The FTC rule targets deceptive auto-dealer practices, including AI-powered tools used in financing offers and add-on sales. The rule's compliance date is stayed pending Fifth Circuit litigation, but core deception standards still apply under FTC Act Section 5.
-
Proposed / pending
FCC AI robocall disclosure NPRM
United States · FCC 24-84, NPRM, CG Docket 23-362 (Aug. 8, 2024)
The FCC's August 2024 proposed rule would require callers using AI-generated voices or AI-written texts to disclose that fact at the start of the call or in the text, and would let consumers refuse AI calls even when prerecorded consent was given. The proposal is pending as of June 2026 — track its status before relying on it.
-
Proposed / pending
QUIET Act
United States · H.R.1027, 119th Congress (2025–2026)
Requires any robocall that uses artificial intelligence to emulate a human voice to include a clear disclosure at the start of the message stating that AI is being used. Also doubles the maximum forfeiture penalty and criminal fines under the TCPA for violations involving AI voice or text impersonation. Seniors are not specifically named but are a primary intended beneficiary — AARP surveys show 95% of adults 50+ received a scam or illegal robocall in 2025.
-
Proposed / pending
QUIET Act (Senate)
United States · S.3354, 119th Congress (2025–2026)
Senate companion to H.R.1027; requires AI-generated robocalls to disclose AI use at the start of the call and enhances TCPA penalties for AI voice or text impersonation violations. Directly addresses a primary vector for elder fraud — AI voice robocalls. Bipartisan press materials cited protection of older Americans from scam calls as a key goal.
-
Repealed / replaced
EO 14110 (revoked)
United States · Effective 2023-10-30 · Exec. Order No. 14110, 88 Fed. Reg. 75191 (Nov. 1, 2023) — revoked by EO 14148 (Jan. 20, 2025)
President Biden's EO 14110 was the foundational federal AI executive order, requiring safety reporting from frontier AI developers under the Defense Production Act and directing federal agencies to develop AI policies. Revoked by President Trump's EO 14148 on January 20, 2025.
-
Repealed / replaced
EO 13960 (federal AI use)
United States · Effective 2020-12-03 · Exec. Order No. 13960, 85 Fed. Reg. 78939 (Dec. 8, 2020)
President Trump's December 2020 executive order set nine principles for federal agency AI use (lawful, accurate, safe, understandable, accountable, etc.) and required each agency to publish an annual public inventory of its AI use cases. The annual AI use case inventories continued under EO 14110 (Biden) and EO 14179 (Trump-II) — making EO 13960 the foundational federal-AI-transparency baseline.
-
Repealed / replaced
EO 13859 (American AI Initiative)
United States · Effective 2019-02-11 · Exec. Order No. 13859, 84 Fed. Reg. 3967 (Feb. 14, 2019)
President Trump's February 2019 executive order launched the 'American AI Initiative' — the first federal whole-of-government AI strategy. It directed federal agencies to prioritize AI R&D investment, open government data for AI training, set technical standards (via NIST), and develop the AI workforce. The framework was preserved but reorganized under EO 13960 (2020) and EO 14110 (2023), then carried over into EO 14179 (2025).
-
Expired
Algorithmic Accountability Act (2019, died)
United States · H.R. 2231 / S. 1108, 116th Cong. (2019) — died in committee
Sens. Wyden and Booker and Rep. Clarke introduced the first federal Algorithmic Accountability Act on April 10, 2019. It would have empowered the FTC to require large companies to assess and address bias, discrimination, and privacy risks in 'automated decision systems.' Never received a committee vote — but it set the template for every subsequent federal and state algorithmic-accountability bill.
-
Expired
Algorithmic Accountability Act (2022, died)
United States · S. 3572 / H.R. 6580, 117th Cong. (2022) — died in committee
Sens. Wyden and Booker and Rep. Clarke reintroduced an expanded Algorithmic Accountability Act on Feb. 3, 2022. It would have required impact assessments for 'augmented critical decision processes' across employment, housing, credit, education, and healthcare. Died in committee but became the most-cited federal AI bill of the 117th Congress.
-
Expired
Algorithmic Accountability Act (2023, died)
United States · S. 2892 / H.R. 5628, 118th Cong. (2023) — died in committee
The third iteration of the Algorithmic Accountability Act, reintroduced on Sept. 21, 2023 with refined definitions and FTC rulemaking authority. Like its predecessors it never received committee action — but it remains the leading federal ADS-impact-assessment template.
-
Expired
Bot Disclosure Act (Feinstein, died)
United States · S. 3127, 115th Cong. (2018) — died in committee
Sen. Dianne Feinstein's June 2018 bill would have required social media platforms to mandate disclosure of automated bots and would have banned political campaigns from using bots in disguised political ads. The first federal bot-disclosure proposal — never received committee action but inspired CA SB 1001 (2018, enacted) and NJ Bot Disclosure Act (2019, enacted).
-
Expired
Algorithmic Justice Act (Markey/Matsui, died)
United States · S. 1896 / H.R. 3611, 117th Cong. (2021) — died in committee
Sen. Markey and Rep. Matsui's May 2021 bill would have banned discriminatory algorithmic processes on online platforms, required plain-language algorithm disclosure to users, and created a cross-agency task force on algorithmic discrimination. Died in committee but became a citation anchor for later FTC trade-rule petitions.
-
Expired
OBBBA §43201 (stripped)
United States · OBBBA §43201 — stripped July 1, 2025 (99-1); OBBBA enacted July 4, 2025
Section 43201 of the One Big Beautiful Bill Act (H.R. 1, 2025) would have imposed a 10-year moratorium on state AI laws. The Senate stripped it on a 99-1 vote on July 1, 2025 — the most significant failed federal preemption attempt against state AI regulation. The OBBBA was signed into law on July 4, 2025 without the AI moratorium.
State AI disclosure and transparency rules (173)
-
In effect
CA CPPA ADMT Regs
CA · Effective 2026-01-01 · 11 Cal. Code Regs. §§ 7200-7232
California's privacy agency finalized binding regulations governing automated decision-making and AI used to make significant decisions about Californians — including hiring, housing, education, healthcare, financial services, and ads to minors. Consumers gain rights to pre-use notice, opt-out, and access to information about how AI made the decision.
-
In effect
CCPA/CPRA + ADMT Regulations
California · Effective 2026-01-01 · Cal. Civ. Code § 1798.100 et seq.; Cal. Code Regs. tit. 11, div. 6
California's main privacy law gives consumers rights to know, delete, correct, and opt out of the sale or sharing of their personal information. New regulations finalized in 2025 add rights around automated decision-making technology (ADMT): businesses using ADMT for significant decisions (jobs, housing, credit, healthcare) must give pre-use notice, let people opt out, and provide access to how decisions were made.
-
In effect
HB 3773 (AI Employment Discrimination)
Illinois · Effective 2026-01-01 · P.A. 103-0804, amending 775 ILCS 5
Illinois employers may not use AI in ways that discriminate against protected classes in recruitment, hiring, promotion, discipline, discharge, or other employment terms, and may not use zip codes as a proxy for protected characteristics. Employers must notify workers and applicants when AI is used in employment decisions.
-
In effect
Tohono O'odham Research Code
Tohono O'odham Nation · Effective 2013-05-23 · 17 Tohono O'odham Code ch. 8 (Resolution No. 13-165, May 23, 2013)
Tohono O'odham Nation's research code establishes a tribal IRB with sole authority to control publication of all research, disclosures, and findings on tribal land. Vests ownership of all research-derived work product and copyrights — including AI/data products — with the Nation.
-
Vetoed
Arizona HB 2311 AI chatbot safety for minors — vetoed 2026
Arizona · Ariz. H.B. 2311, 57th Leg., 2d Reg. Sess. (2026) — vetoed June 19, 2026
Arizona HB 2311 would have required AI chatbot operators to disclose to minor users that they are interacting with artificial intelligence, connect minor users displaying crisis signals to mental health resources, and prohibit gamification techniques designed to maximize time-on-platform for minors. The bill also barred sexual content generation when the AI knew or should have known the user was a minor. The Arizona House passed the bill 35-20 and the Senate passed it 16-12. Governor Katie Hobbs vetoed HB 2311 on June 19, 2026, as part of her veto of all three AI bills that reached her desk in the 2026 legislative session.
-
Enacted (not yet in effect)
NJ Fair Pricing and Transparency Act S3952 (2026)
NJ · Effective 2027-07-23 · N.J. S3952 / A3929 (222nd Legislature, 2026) — signed July 23, 2026; effective July 23, 2027
Governor Meredith Sherrill signed New Jersey S3952/A3929, the Fair Pricing and Transparency Act, on July 23, 2026, making New Jersey the third state to ban surveillance-based grocery pricing, following Maryland and Connecticut. The law prohibits retail food stores from setting individualized prices based on a customer's personal data, purchasing history, or tracked attributes. It also imposes a one-year moratorium on electronic shelf labels (ESLs). Effective July 23, 2027. Notably, the law includes a private right of action for injured consumers — the first state surveillance-pricing law to do so.
-
Enacted (not yet in effect)
Utah SB 319 (health insurer AI)
Utah · Effective 2027-01-01 · Utah SB 319 (2026), enacted March 19, 2026, eff. Jan. 1, 2027
Utah's SB 319, enacted March 19, 2026 and effective January 1, 2027, requires health insurers to disclose to the Utah Insurance Department, to providers, and to enrollees whether AI is used to review prior-authorization requests. It also requires that a health professional's adverse determination be based on their own independent medical judgment — not dictated by an AI recommendation.
-
Enacted (not yet in effect)
AI Safety Measures Act (frontier model audits)
Illinois · Effective 2027-01-01 · IL SB315 (104th General Assembly, 2025-2026)
Illinois is the first state to require independent third-party safety audits of the largest 'frontier' AI developers (companies like OpenAI, Anthropic, and Google DeepMind). Covered developers — those with >$500M annual gross revenue whose models meet defined compute thresholds — must publish and annually update a frontier AI safety framework addressing catastrophic risks (defined as incidents threatening 50+ deaths, serious injuries, or $1B+ in damages), file transparency reports before deploying new or substantially modified models, report critical safety incidents within 72 hours (24 hours for imminent harm), and protect whistleblowers. Enforced by the Illinois Emergency Management Agency and Office of Homeland Security with the Attorney General; civil penalties; no private right of action. Law takes effect January 1, 2027; audit requirements operative January 1, 2028.
-
Enacted (not yet in effect)
MD HB 1339 (Automated Decision Systems, 2026)
Maryland · Effective 2026-10-01 · Md. HB 1339 (2026 Reg. Sess.)
Maryland employers that use automated decision systems in hiring, promotion, or termination decisions must disclose to applicants and employees that an automated system is being used. Employers must also conduct and retain impact assessments evaluating whether their ADS produces disparate outcomes by race, sex, or other protected characteristics. Penalties run up to $10,000 per violation. Takes effect October 1, 2026.
-
Blocked / in litigation
CA SB 942 (challenged)
CA · Effective 2026-08-02 · Cal. SB 942 (2024) — pending First Amendment challenge
California SB 942 mandates AI-content disclosures and watermarking by large generative AI providers, effective August 2, 2026. A First Amendment challenge was filed by industry plaintiffs in late 2025 and is pending preliminary injunction motion.
-
In effect
PR Ley 116-2026 (AI Bot Disclosure in Gov. Services)
Puerto Rico · Effective 2026-06-18 · Ley Núm. 116-2026 (P. del S. 622, 19th Leg. Assembly); signed June 18, 2026
Puerto Rico's Ley 116-2026 (P. del S. 622) requires PR Executive Branch agencies to notify citizens when they are interacting with an AI system, chatbot, or automated system instead of a human, and guarantees citizens the right to request human intervention at any time. Senate approved June 24, 2025; House approved June 1, 2026; signed into law by Governor Jenniffer González Colón on June 18, 2026. Puerto Rico's second enacted AI-specific law in 2026.
-
In effect
FL Rule 2.515 amendment — AI citation certification (eff. Jun. 15, 2026)
Florida · Effective 2026-06-15 · In re: Amendments to Fla. R. Gen. Prac. & Jud. Admin. 2.515, No. SC2026-0673 (Fla. May 28, 2026; eff. June 15, 2026)
The Florida Supreme Court amended Rule 2.515 so that every person who signs a court filing certifies that the legal authorities cited in it actually exist and are accurately cited — a direct response to AI-hallucinated case citations appearing in filings. Violations can bring sanctions including reprimand, contempt, dismissal of the filing, and fee awards. The statewide rule replaces a patchwork of individual circuit-level AI orders. The amendment does not prohibit using AI; it makes the human signer responsible for verifying whatever AI produces. Opinion issued May 28, 2026; effective June 15, 2026 at 12:01 a.m.
-
In effect
PR Ley 105-2026 (AI Elections)
Puerto Rico · Effective 2026-06-10 · Ley Núm. 105-2026 (P. del S. 101)
Puerto Rico's Law 105-2026 amends the Electoral Code to require clear disclosure on any political ad created or materially modified by AI — text, image, audio, or video. Signed by Governor Jenniffer González on June 10, 2026. First standalone AI law on the books in PR.
-
In effect
SC H 3431 Age-Appropriate Design Code Act (2026)
SC · Effective 2026-03-01 · S.C. H 3431 (126th G.A., 2026) — signed Feb. 5, 2026; eff. March 1, 2026
South Carolina H 3431, the Age-Appropriate Design Code Act, requires online platforms and services likely to be accessed by children under 18 to prioritize children's best interests. Covered companies must conduct data protection impact assessments before launching features accessible to minors, set privacy controls to their highest protective level by default for child users, minimize data collection, prohibit profiling children for commercial purposes without verifiable parental consent, and disclose how algorithms affect what content children see. Signed by Governor McMaster February 5, 2026; operational March 1, 2026.
-
Blocked / in litigation
X.AI v. Bonta (AB 2013 training-data disclosure)
California · Effective 2025-12-29 · X.AI LLC v. Bonta, No. 2:25-cv-12295 (C.D. Cal., filed Dec. 29, 2025), appeal pending, No. 26-1591 (9th Cir.); oral argument July 16, 2026
X.AI LLC (Elon Musk's AI company) sued California Attorney General Rob Bonta to strike down AB 2013, California's law requiring developers of generative AI systems to publicly disclose documentation about the data used to train them. The suit was filed December 29, 2025 in the Central District of California, arguing the disclosure mandate violates the First, Fifth, and Fourteenth Amendments. Judge Bernal denied X.AI's request for a preliminary injunction on March 4, 2026, and X.AI appealed to the Ninth Circuit, where the case is pending. AB 2013 took effect January 1, 2026 and remains enforceable while the appeal proceeds. The Attorney General defends the law as a regulation of commercial speech.
-
In effect
Cherokee Nation AI Policy
Cherokee Nation (OK) · Effective 2025-08-21 · Cherokee Nation IT AI Policy (Aug. 21, 2025); companion to Cherokee Nation EO 2024-07-CTH
Cherokee Nation's first AI policy. Governs responsible and ethical AI use across tribal government, protects Cherokee language and cultural content, and requires AI vendor questionnaires before deployment in tribal systems. Signed by Principal Chief Chuck Hoskin Jr.
-
Blocked / in litigation
CA AB 1836 (challenged)
CA · Effective 2025-01-01 · Cal. Civ. Code §3344.1 (as amended by AB 1836); MPA v. Bonta (E.D. Cal., pending)
California AB 1836 extended postmortem right of publicity to AI digital replicas of deceased personalities. A First Amendment challenge filed by the Motion Picture Association is pending in federal court.
-
In effect
NCAI Res. NC-24-008 (Digital Sovereignty)
National Congress of American Indians · Effective 2024-11-15 · NCAI Resolution #NC-24-008 (2024)
Defines tribal digital sovereignty as tribes' sovereign authority over physical and virtual network infrastructure and data — acquisition, storage, transmission, access, use. Explicitly notes that AI tools can circumvent tribal data collection protocols.
-
In effect
FL HB 919 AI political/commercial disclosure
FL · Effective 2024-07-01 · Ch. 2024-126, Laws of Fla.; Fla. Stat. § 106.143
Florida requires any political ad using AI-generated content to carry a clear disclaimer; failing to disclose AI use in a political or paid ad — or using AI to materially deceive — is a first-degree misdemeanor. Enforcement is via the Florida Elections Commission and the Department of State.
-
In effect
Cherokee Nation EO 2024-07-CTH
Cherokee Nation (OK) · Effective 2024-07-01 · Cherokee Nation Executive Order 2024-07-CTH
Executive order from Principal Chief Hoskin establishing the Data Sovereignty and Governance Task Force. Charged with anticipating emerging technologies, safeguarding citizens' sensitive personal data, and defining Cherokee Nation data sovereignty. Produced the AI/data sovereignty/cybersecurity report that led to the 2025 AI policy.
-
In effect
UT AI Policy Act (SB 149)
UT · Effective 2024-05-01 · Utah Code §§ 13-2-12, 13-72-101 et seq.; SB 149 (2024)
Utah was the first state to require regulated professionals (e.g., doctors, lawyers, accountants) to clearly disclose when consumers are interacting with generative AI, and to make companies liable under existing consumer-protection law for any deception their GenAI commits. It also created the Office of AI Policy and a regulatory sandbox.
-
In effect
NCAI Res. SAC-22-026 (Emerging Tech)
National Congress of American Indians · Effective 2022-11-04 · NCAI Resolution #SAC-22-026 (2022)
NCAI resolution addressing how emerging technologies including AI can circumvent tribal data collection protocols without proper consent. Reinforces tribal authority over data flowing through AI systems.
-
In effect
MN drone-warrant law (2020)
Minnesota · Effective 2020-08-01 · Minn. Stat. § 626.19
Minnesota requires police to get a search warrant before using a drone, with narrow exceptions, and to publish an annual public report listing every drone deployment, purpose, and cost. The annual transparency requirement is among the strongest in any state drone law.
-
In effect
IL AI Video Interview Act (2019, first-in-nation)
IL · Effective 2020-01-01 · 820 ILCS 42/1 et seq. (P.A. 101-0260, 2019; P.A. 102-0407, 2021)
Signed by Governor Pritzker on August 9, 2019, the Illinois AI Video Interview Act was the first U.S. state law specifically regulating AI in hiring. It requires employer notice, applicant consent, and explanation of how AI works before using AI to analyze a video interview. 2022 amendment (P.A. 102-0407) added demographic data collection. Still in effect 2026 at 820 ILCS 42/1 et seq.
-
In effect
CARE Principles (Indigenous Data)
Global Indigenous Data Alliance · Effective 2019-09-01 · Carroll et al., Data Science Journal 19:43 (2020); GIDA (2019)
Indigenous-authored complement to the FAIR data principles. Establishes that Indigenous data must be governed under Indigenous authority, used for Collective benefit, and handled with Responsibility and Ethics. Widely referenced in U.S. tribal research codes and increasingly in federal agency guidance.
-
In effect
NCAI Res. KAN-18-011 (IDS)
National Congress of American Indians · Effective 2018-06-04 · NCAI Resolution #KAN-18-011 (2018)
First collective NCAI resolution supporting U.S. tribes' exercise of Indigenous data sovereignty — the principle that tribes have inherent authority over data about their citizens, lands, and resources. Foundation document for tribal restrictions on AI training data and government data sharing.
-
In effect
Plateau Peoples TK/BC Labels
Plateau Peoples' Web Portal (Multi-Tribal) · Effective 2015-01-01 · Plateau Peoples' Web Portal — multi-tribal TK/BC Labels initiative
Six Plateau tribes — Colville, Umatilla, Warm Springs, Yakama, Spokane, and Coeur d'Alene — jointly implement Local Contexts Traditional Knowledge and Biocultural Labels on digital cultural-heritage collections. A working Indigenous data sovereignty mechanism applicable to AI training data: labels travel with the data and assert community-defined access and use rules.
-
In effect
Local Contexts TK/BC Labels
Local Contexts · Effective 2010-01-01 · Local Contexts TK Labels (2010); BC Labels (2018)
Indigenous-authored digital provenance labels that travel with cultural data to enforce community-set rules on access, attribution, and reuse. Foundational tool for asserting Indigenous data sovereignty against extractive AI training datasets. TK Labels launched 2010; BC Labels 2018. Adopted by 200+ Indigenous communities globally.
-
In effect
Navajo Nation Privacy Act
Navajo Nation · Effective 2005-01-01 · 2 N.N.C. § 81 et seq.
Navajo Nation's foundational privacy law. Regulates access to records held by Navajo government offices, enumerates 22 categories of public records, and establishes privacy protections governing release of citizen and government data — the legal backbone for any AI system processing Navajo citizen data.
-
In effect
Navajo NNHRRB
Navajo Nation · Effective 1996-01-01 · Navajo Nation Human Research Review Board (est. 1996)
Navajo Nation's IRB. All human-subjects research on the Navajo Nation — including any AI or data-driven studies — must be approved by NNHRRB and certify compliance with the Navajo Nation Privacy Act before data collection or publication.
-
Enacted (not yet in effect)
PA HB 1924 data center water/energy reporting (signed July 12, 2026)
PA · Pennsylvania HB 1924 (signed July 12, 2026, FY2026-27 budget), annual data center water/energy reporting mandate
Pennsylvania now requires data centers to report their water and energy use every year. The mandate — House Bill 1924, signed July 12, 2026 as part of the state's 2026-27 budget — carries fines of $10,000 per day for facilities that fail to report. The Department of Environmental Protection will publish an annual aggregate report, and the data is expected to improve grid-demand forecasting in the PJM region.
-
In effect
AZ Ct. App. — AI fake citations sanctionable regardless of intent
Arizona · Arizona Court of Appeals published opinion (Judge Brian Furuya), first published AZ opinion on generative AI in court filings; reported July 16, 2026
The Arizona Court of Appeals issued its first published opinion addressing generative AI in court filings, holding that submitting AI-hallucinated (fake) case citations is sanctionable regardless of the filer's intent — an innocent mistake is no defense. The rule applies to lawyers and self-represented (pro se) litigants alike. The court imposed a fee sanction in the underlying case. As a published opinion, it binds Arizona trial courts statewide, putting every filer on notice that AI-generated citations must be verified against real authorities before filing.
-
Enacted (not yet in effect)
Hawaii AI Companion Safety Act (Act 248)
Hawaii · HI SB 3001 CD1 (2026)
Hawaii enacted a law (Act 248, signed July 14, 2026) requiring AI companion chatbot operators to clearly disclose users are talking to AI, implement self-harm and suicidal-ideation protocols, protect minors from manipulative engagement techniques and sexually explicit content, provide parental tools, and file annual reports with the state Behavioral Health Administration.
-
Enacted (not yet in effect)
SB 540 (GA Chatbot Safety)
Georgia · Effective 2027-07-01 · Ga. SB 540 (2025-2026 Reg. Sess.), signed May 15, 2026; effective July 1, 2027
Georgia — the first Republican-led state to do so — enacted a chatbot safety law. Operators must tell users they're talking to AI, verify ages, give parents controls, and follow crisis protocols (like referring to the 988 lifeline) when users express suicidal thoughts. Chatbots talking to minors can't claim to be sentient, produce sexual content, simulate romance, encourage secrets from adults, or fake distress when a child ends the chat. No carve-out for chatbots inside big platforms. Effective July 1, 2027.
-
Enacted (not yet in effect)
Washington HB 1170 (AI content watermarking & provenance metadata)
Washington · Effective 2027-02-01 · Washington HB 1170 (2026), effective February 1, 2027
Washington's HB 1170, signed March 24, 2026, requires covered AI providers — those with more than one million monthly active users — to embed metadata or watermarks (provenance data) in AI-generated or materially altered images, video, and audio content. The law is enforced by the Washington Attorney General under the state's Consumer Protection Act. It takes effect February 1, 2027. Strength is rated 'limited' because the one-million-user threshold exempts many smaller AI providers, and enforcement relies on the AG rather than providing a direct private right of action.
-
Enacted (not yet in effect)
HB 1170 (WA AI Content Disclosure)
Washington · Effective 2027-02-01 · Wash. E2SHB 1170 (2026); Ch. 167, 2026 Laws
Large AI image, video, and audio generators must embed hard-to-remove provenance data — watermarks or tamper-resistant metadata — in every piece of synthetic content they create. This lets journalists, courts, and the public identify AI-generated media. Applies to services with over 1 million monthly users. Enforced by the Washington Attorney General under the Consumer Protection Act. Effective February 1, 2027.
-
Enacted (not yet in effect)
CO ADMT Act (SB 26-189, 2026)
Colorado · Effective 2027-01-01 · Colo. SB 26-189 (2026), signed May 14, 2026, eff. January 1, 2027
Colorado Governor Jared Polis signed SB 26-189 on May 14, 2026, repealing and replacing the original Colorado AI Act (SB 24-205) before it could take effect. The replacement law creates a disclosure-focused framework for 'Automated Decision-Making Technology' (ADMT) — a narrower category than the prior law's 'high-risk AI' — applicable to consequential decisions in employment, housing, healthcare, credit, education, insurance, and government services. The original Colorado AI Act had been blocked by a federal court on constitutional grounds days before the replacement was passed. The new ADMT Act takes effect January 1, 2027.
-
Enacted (not yet in effect)
Utah HB 276 Provenance Act (AI-content labels + platform provenance duties)
Utah · Effective 2027-01-01 · Utah Code 13-72c-101 to -301, 63A-16-215 (H.B. 276, 2026)
This part of Utah's AI Modifications law requires large generative-AI providers to embed a hidden (latent) disclosure in AI-generated or substantially AI-altered image, audio, and video content. Large online platforms must detect provenance data, let users inspect it, and must not strip compliant provenance or digital signatures. From January 1, 2028, capture-device makers must embed a latent disclosure by default. The law also directs the state CIO to set provenance standards for digital content on public-facing state-agency webpages.
-
Enacted (not yet in effect)
Utah SB 319 (insurers must disclose AI use in prior authorization)
Utah · Effective 2027-01-01 · Utah Code 31A-22-650(2)(d), (3) (S.B. 319, 2026)
Utah requires health insurers that use AI in reviewing prior-authorization requests to be transparent about it. If applicable, an insurer must post a conspicuous notice on its public website that it uses AI in authorization review, and disclose that AI use to the state Insurance Department, each in-network provider, and each enrollee. The rules sit within a broader prior-authorization overhaul.
-
Enacted (not yet in effect)
Wisconsin 452.136(1m) (real estate ads must disclose AI-altered property images)
Wisconsin · Effective 2027-01-01 · Wis. Stat. 452.136(1m); 2025 Wis. Act 69
Wisconsin will require licensed real estate professionals to disclose in their advertising whenever an ad has been altered or modified using technology, including AI, to add, remove, or change elements of a property in a way that creates a false or misleading impression. The rule targets AI-edited listing photos that could mislead buyers or renters. It takes effect January 1, 2027.
-
Enacted (not yet in effect)
SB 26-189 (Colorado ADMT Law)
Colorado · Effective 2027-01-01 · SB 26-189 (Colo. 2026)
Colorado's replacement AI law focuses on transparency rather than broad anti-discrimination duties. Starting January 1, 2027, companies using automated decision-making technology to materially influence consequential decisions (employment, housing, lending, insurance, healthcare) must notify consumers before use and provide post-decision disclosures; developers must give deployers technical documentation.
-
Enacted (not yet in effect)
RAISE Act
New York · Effective 2027-01-01 · RAISE Act, S6953B/A6453B (N.Y. 2025), as amended 2026
New York's frontier AI safety law requires the largest AI developers to publish safety protocols and report serious safety incidents to the state within 72 hours. It creates a new AI oversight office and carries penalties up to $3 million for repeat violations, starting January 1, 2027.
-
Enacted (not yet in effect)
SB 1546 (OR Chatbot Safety)
Oregon · Effective 2027-01-01 · Or. SB 1546 (2026), sponsored by Sen. Lisa Reynolds
Oregon's chatbot safety law — the first major chatbot measure passed in 2026 — requires AI chatbot operators to tell users they're talking to AI, prevent outputs that could cause suicidal thoughts, and refer users expressing suicidal ideation to mental-health resources. Kids get extra protections: hourly AI reminders and break reminders, no sexual content, no addictive reward loops, and no emotional manipulation when a child tries to log off. Users harmed by violations can sue. Effective January 1, 2027.
-
Enacted (not yet in effect)
HB 2225 (WA Chatbot Safety)
Washington · Effective 2027-01-01 · Wash. HB 2225, Ch. 168, 2026 Laws; RCW 19.86.093
Washington requires AI companion chatbots to clearly tell users they are talking to an AI, not a person. Operators must have crisis protocols — connecting distressed users to the 988 Suicide and Crisis Lifeline — and additional safeguards for minors. If a company violates the law, consumers can sue under Washington's Consumer Protection Act and recover actual damages, an injunction, and attorney's fees. Effective January 1, 2027.
-
Enacted (not yet in effect)
CT SB 5 (2026 AI Act)
Connecticut · Effective 2026-10-01 · Conn. Public Act 26-15 (SB 5, 2026)
After years of failed attempts, Connecticut enacted a comprehensive AI law in 2026. It requires employers to disclose AI used in employment decisions, mandates disclosure when layoffs relate to AI, imposes some of the nation's strictest AI companion-chatbot rules (especially for children), and codifies that automated decision-making is no defense to discrimination claims. Most provisions start October 1, 2026.
-
In effect
SB 942 (AI Transparency Act)
California · Effective 2026-08-02 · Cal. Bus. & Prof. Code § 22757 et seq. (SB 942, as amended by AB 853)
Large generative AI providers (over 1 million monthly users) must offer a free AI-detection tool and embed disclosures in AI-generated images, video, and audio, including hidden watermark-style disclosures. A 2025 amendment delayed the start to August 2, 2026 and extended duties to large online platforms and capture-device makers (2027).
-
In effect
PR Ley 140-2026 (Gov AI Cybersecurity Training)
Puerto Rico · Effective 2026-07-23 · Ley Núm. 140-2026 (H.B. 824, 19th Leg. Assembly); signed July 23, 2026
Puerto Rico Law 140-2026 amends the Puerto Rico Government Cybersecurity Law to require that its continuing-education program for government information officers and public servants include artificial intelligence — alongside privacy, systems security, data management, cyberattack prevention, and responsible use of new technologies. Signed by Governor Jenniffer González Colón on July 23, 2026. Puerto Rico's third enacted AI-specific law in 2026.
-
In effect
Virginia IVO AI Safety Study (SB 384/HB 797, 2026)
Virginia · Effective 2026-07-01 · 2026 Va. Acts, SB 384 / HB 797 (JCOTS IVO Study Directive), eff. July 1, 2026
Virginia enacted SB 384 and companion HB 797 on April 13, 2026, directing the Joint Commission on Technology and Science (JCOTS) to study the feasibility of a framework for Independent Verification Organizations (IVOs) — independent bodies that would assess whether AI models and applications meet safety standards designed to prevent personal injury and property damage. This is a study directive only; it does not create any compliance obligations for AI developers or deployers today. If JCOTS recommends a framework, future legislation could require IVO certification before deployment of high-risk AI systems in Virginia.
-
In effect
CT SB 1295 (AI training-data disclosure)
Connecticut · Effective 2026-07-01 · 2025 Conn. Public Acts 25-153 (SB 1295), amending Conn. Gen. Stat. Sec. 42-520
This amendment to Connecticut's Data Privacy Act adds a first-in-the-nation transparency rule about AI training data. Businesses must state in their privacy notice whether they collect, use, or sell personal data to train large language models. The disclosure applies regardless of how the trained model is ultimately used. Like the rest of the privacy act, it is enforced by the Attorney General under Connecticut's consumer protection law.
-
Proposed / pending
Colorado Attorney General Rulemaking for the Automated Decis
Colorado · Effective 2026-06-30 · Colorado Attorney General Rulemaking for the Automated Decision-Making Technology (ADMT) Act and Chatbot Safety Act
The Colorado Attorney General's Office opened pre-rulemaking to write rules implementing the state's Automated Decision-Making Technology Act (algorithmic-discrimination protections for high-risk AI) and the Chatbot Safety Act, taking public comment through July 13, 2026 ahead of the laws' January 1, 2027 effective date.
-
In effect
New York S8420A (ads must disclose AI 'synthetic performers')
New York · Effective 2026-06-09 · N.Y. Gen. Bus. Law 396-b (S8420A, 2025)
When a business creates an advertisement for property or services for a commercial purpose, this law requires it to clearly disclose if the ad uses a 'synthetic performer' — a digitally created asset (made with generative AI or a software algorithm) meant to look like an audiovisual or visual performance by a human, where the figure is not recognizable as any identifiable real person. Penalties are $1,000 for a first violation and $5,000 for each subsequent violation.
-
In effect
Maryland HB 1563 (AI-denial reporting)
Maryland · Effective 2026-06-01 · 2026 Md. Laws ch. 165 (HB 1563); Md. Code, Ins. 15-10A-06
Among other emergency-room and post-acute care provisions, this law expands the quarterly report that carriers must submit to the Maryland Insurance Commissioner. The report must include the number of adverse decisions and whether an artificial intelligence, algorithm, or other software tool was used in making them. The Commissioner may use this information as a basis for examining the carrier.
-
In effect
Model Tariff Framework for Large Load Customers (Docket M-20
Pennsylvania Public Utility Commission · Effective 2026-04-30 · Model Tariff Framework for Large Load Customers (Docket M-2025-3054271)
The Pennsylvania PUC adopted a first-of-its-kind model tariff framework requiring large load customers exceeding 50 MW individually or 100 MW in aggregate (e.g., data centers) to bear interconnection upgrade costs, post financial assurances, and follow a public application queue so existing ratepayers are not saddled with their costs.
-
In effect
SUNY Systemwide Artificial Intelligence Policy
State University of New York (SUNY) · Effective 2026-04-30 · SUNY Systemwide Artificial Intelligence Policy
SUNY's Board of Trustees approved a systemwide AI policy requiring all 64 campuses to adopt AI governance, bias evaluation, data-privacy safeguards, and heightened oversight of high-risk systems affecting students by December 31, 2026.
-
In effect
We Energies Very Large Customer (VLC) Data Center Tariff Ord
Public Service Commission of Wisconsin (We Energies) · Effective 2026-04-24 · We Energies Very Large Customer (VLC) Data Center Tariff Order
The Wisconsin PSC approved but overhauled We Energies' data center tariff, lowering the eligibility threshold from 500 MW to 100 MW, extending the minimum contract term to 15 years, and removing a capacity-only option so data centers pay their full share and existing customers are not subsidizing them.
-
In effect
Executive Order N-5-26 - Trusted AI Procurement
California · Effective 2026-03-30 · Executive Order N-5-26 - Trusted AI Procurement
This newer California executive order directs DGS and CDT to develop trust-and-safety certifications for state AI contracting (covering CSAM/NCII, harmful bias, and civil-rights violations), reforms to bar contracting with entities that unlawfully undermine privacy or civil liberties, and CDT guidance on watermarking AI-generated media.
-
In effect
Vermont Election Deepfake Law
Vermont · Effective 2026-03-06 · 2026 VT Acts No. 75 (S.23)
Campaign media featuring AI-generated images, audio, or video used within 90 days of a Vermont election must carry a clear disclosure — on video for the full duration, in audio at the beginning, end, and every two minutes. Fines up to $1,000 first offense, $15,000 for repeats.
-
In effect
GenAI Tools and Acceptable Use Policy
Maine · Effective 2026-03-06 · GenAI Tools and Acceptable Use Policy
The Maine Office of Information Technology's generative AI policy (superseding the earlier GenAI moratorium) guides responsible use of GenAI on state IT infrastructure, requiring compliance with data classification standards, prohibiting confidential data inputs to public AI systems, and holding users accountable for AI outputs.
-
In effect
AI Systems Code of Ethics and Minimum Risk Management and Go
Texas · Effective 2026-03-01 · AI Systems Code of Ethics and Minimum Risk Management and Governance Standards (1 TAC Chapter 219)
Under Government Code 2054.702 and SB 1964, the Texas Department of Information Resources adopted a statewide AI code of ethics built on seven principles (human oversight, fairness, accuracy, redress, transparency, privacy, security) plus minimum risk-management standards for heightened-scrutiny AI systems.
-
In effect
Cherokee Nation EO 2026-02-CTH (Data Center Task Force)
Cherokee Nation (OK) · Effective 2026-02-24 · Cherokee Nation Executive Order 2026-02-CTH (Feb. 24, 2026)
Cherokee Nation Principal Chief Chuck Hoskin Jr. signed Executive Order 2026-02-CTH on February 24, 2026, establishing a nine-member task force to study the environmental and economic impacts of data center development on the Cherokee Nation Reservation. The task force — formally titled the 'Principal Chief's Task Force to Study the Impact of Data Centers on the Economy and Natural Environment of the Cherokee Nation Reservation' — is led by Secretary of Natural Resources Christina Justice, with Chief of Staff Dr. Corey Bunch serving as co-chair and CIO Paula Starr as a member. The task force was charged with assessing the current and projected scope of data center construction on the 7,000-square-mile reservation, environmental concerns (including water and energy impacts), economic opportunities and detriments for citizens, and tribal and state/federal policy advocacy options. The report was due to Principal Chief Hoskin by June 30, 2026; its public release has not been confirmed as of July 11, 2026.
-
In effect
Attorneys General Derek Brown and Jeff Jackson Launch Nation
Utah · Effective 2026-01-17 · Attorneys General Derek Brown and Jeff Jackson Launch Nationwide Bipartisan AI Task Force
Utah's Attorney General co-launched a nationwide bipartisan attorneys-general task force to identify emerging AI harms and develop safeguards AI developers should follow to protect the public, especially children.
-
In effect
Executive Order 26-02 (Strategic Framework for Integration o
Missouri · Effective 2026-01-13 · Executive Order 26-02 (Strategic Framework for Integration of Artificial Intelligence within State Government Operations)
Governor Mike Kehoe ordered the Office of Administration to develop a strategic framework for integrating AI into Missouri state government, prioritizing data privacy and security, human decision-making, transparency, accountability, and data quality.
-
In effect
NV AI Election Ad Disclosure
Nevada · Effective 2026-01-01 · 2025 Nev. Laws Ch. 224 (AB 73); NRS ch. 294A
Nevada political ads containing AI-generated or digitally manipulated images, audio, or video must disclose it clearly, effective January 1, 2026. Wrongly depicted candidates can seek legal relief; satire and entertainment content is exempt.
-
In effect
California SB 524 (AI-written police reports must be disclosed + audited)
California · Effective 2026-01-01 · Cal. Penal Code 13663 (SB 524, 2025)
This law brings transparency to the use of AI in police reports. When a law enforcement report is generated wholly or partly by AI, the report must carry a per-page disclosure identifying the AI program used, along with the officer's signature verifying they reviewed it and that the facts are true. Agencies must keep the first AI-generated draft and an audit trail showing the user, data, and media involved, and vendors are barred from sharing or selling agency data except for the agency's own purposes.
-
In effect
California SB 361 (data brokers must report sharing data with GenAI developers)
California · Effective 2026-01-01 · Cal. Civ. Code 1798.99.82 (SB 361, 2025)
This law expands what data brokers must reveal when they register each year with the California Privacy Protection Agency. Among the new disclosures, brokers must state whether, during the prior year, they sold or shared consumers' personal information with developers of generative AI systems. The aim is to give the public and regulators visibility into how personal data flows into AI training and development.
-
In effect
AB 2013 (Training Data Transparency)
California · Effective 2026-01-01 · Cal. Civ. Code §§ 3110–3111 (AB 2013, Stats. 2024)
Developers of generative AI systems made available to Californians must publicly post documentation about the datasets used to train their models, including sources, whether they contain personal information or copyrighted material, and time periods of collection. Applies to systems released or substantially modified since January 1, 2022.
-
In effect
SB 53 (Frontier AI Safety)
California · Effective 2026-01-01 · SB 53 (Stats. 2025)
The first US frontier-AI safety law in effect: the largest AI model developers must publish safety frameworks and transparency reports, report critical safety incidents to the state, and protect whistleblowers who raise catastrophic-risk concerns.
-
In effect
TRAIGA
Texas · Effective 2026-01-01 · Tex. Bus. & Com. Code Ch. 552; Tex. HB 149 (89th Leg., R.S., 2025), TRAIGA
Texas's AI law bans specific harmful uses of AI — intentional discrimination, behavioral manipulation encouraging self-harm or crime, social scoring by government, and certain biometric identification without consent — and requires government agencies to disclose AI interactions to consumers. It includes a regulatory sandbox and preempts local AI ordinances.
-
In effect
Guam P.L. 38-77 (AI Task Force)
Guam · Effective 2025-12-16 · P.L. 38-77 (Bill 64-38 (COR)), 38th Guam Leg. (Dec. 16, 2025)
Guam's first AI law. Creates the Guam AI Regulatory Task Force charged with developing an ethical and accountable framework for AI across government, education, public safety, and the economy. Signed by Acting Governor Joshua Tenorio December 16, 2025.
-
In effect
AG Sunday Leads Coalition of 42 Attorneys General in Letter
Pennsylvania · Effective 2025-12-10 · AG Sunday Leads Coalition of 42 Attorneys General in Letter to A.I. Software Companies Demanding Safeguards to Protect Vulnerable Residents from Harmful Interactions with Bots
Pennsylvania AG Dave Sunday led a coalition of 42 state attorneys general demanding that major AI chatbot companies implement testing, recall procedures, and consumer warnings to protect vulnerable users, especially children, from harmful bot interactions.
-
In effect
2025 State of Connecticut Artificial Intelligence Inventory
Connecticut · Effective 2025-12-08 · 2025 State of Connecticut Artificial Intelligence Inventory
The Department of Administrative Services Bureau of Information Technology Solutions publishes the state's annual, statutorily mandated inventory of AI systems used by state agencies, cataloging each system's vendor, capabilities, whether it informs decisions, and whether an impact assessment was done.
-
In effect
Acceptable Use Policy for Artificial Intelligence
Mississippi · Effective 2025-11-25 · Acceptable Use Policy for Artificial Intelligence
Mississippi ITS adopted an AI acceptable-use policy (implementing EO 1584) setting ten guiding principles including human oversight of AI decisions, bias testing, data-protection restrictions, and a prohibition on deepfakes and using AI for final sensitive decisions.
-
In effect
AI Companion Safeguards Law
New York · Effective 2025-11-05 · N.Y. Gen. Bus. Law §§ 1700–1704
The first state law regulating emotionally responsive 'AI companion' chatbots. Operators must clearly tell users they are talking to an AI (with reminders at least every three hours in ongoing sessions) and must detect signs of suicidal ideation or self-harm and refer users to crisis services.
-
In effect
Commonwealth Office of Technology Enterprise Policy CIO-126:
Kentucky · Effective 2025-10-06 · Commonwealth Office of Technology Enterprise Policy CIO-126: Artificial Intelligence Policy
Kentucky's Commonwealth Office of Technology enterprise AI policy bans state agency use of high-risk AI systems, mandates human review before any consequential decision, and requires transparency disclaimers, bias controls, privacy protections, training, and vendor AI-use disclosure.
-
In effect
Artificial Intelligence Acceptable Use Policy
Louisiana · Effective 2025-09-29 · Artificial Intelligence Acceptable Use Policy
Louisiana's Office of Technology Services policy governs employee AI use, prohibiting entry of confidential/restricted state data into commercial AI, barring AI from making independent consequential decisions, and requiring human verification, AI-content labeling, and use of only state-approved systems.
-
In effect
Maine AI Chatbot Disclosure Law
Maine · Effective 2025-09-16 · 10 M.R.S. ch. 239, Sec. 1500-Y (reallocated to Sec. 1500-DD); P.L. 2025, ch. 294 (L.D. 1727)
Maine prohibits businesses from using an AI chatbot or other computer technology in commercial dealings with a consumer in a way that could mislead a reasonable person into thinking they are interacting with a human, unless the consumer is clearly and conspicuously told they are not. A violation is treated as a violation of the Maine Unfair Trade Practices Act.
-
In effect
Attorney General Labrador Joins Bipartisan Coalition Urging
Idaho · Effective 2025-09-08 · Attorney General Labrador Joins Bipartisan Coalition Urging Tech Companies to Stop the Spread of Deepfake Nonconsensual Intimate Imagery
The Idaho Attorney General joined a 47-state coalition demanding that search engines and payment platforms adopt safeguards to curb AI-generated deepfake nonconsensual intimate imagery.
-
In effect
Executive Order No. 24: Advancing Trustworthy Artificial Int
North Carolina · Effective 2025-09-02 · Executive Order No. 24: Advancing Trustworthy Artificial Intelligence That Benefits All North Carolinians
Governor Josh Stein's order establishes an AI Leadership Council and an AI Accelerator within NCDIT and requires each Cabinet agency to form an AI Oversight Team and submit AI use cases for risk assessment.
-
In effect
TX Government AI Governance (Subchapter S / SB 1964)
Texas · Effective 2025-09-01 · Tex. S.B. 1964, 89th Leg., R.S. (2025); Tex. Gov't Code ch. 2054, subch. S
Texas now requires state agencies to catalog the artificial intelligence systems they use and to give extra review to higher-risk systems that influence consequential decisions about people. The state's Department of Information Resources must publish a statewide AI code of ethics and set baseline rules for managing AI risk and governance, and agencies must run assessments on their highest-scrutiny systems. When a member of the public interacts with a government AI system, the agency has to tell them they are dealing with AI. If an agency or its vendor breaks these rules, the attorney general can go to court to stop the violation and can void a vendor's contract that caused it.
-
In effect
TX SB 1188 (AI in Health Records)
Texas · Effective 2025-09-01 · Tex. S.B. 1188, 89th Leg., R.S. (2025); Tex. Health & Safety Code ch. 183, Secs. 183.005, 183.011
Texas allows health care practitioners to use artificial intelligence for diagnostic purposes, including treatment recommendations, as long as they stay within the scope of their license and follow applicable law. When a practitioner uses AI in that diagnostic role, they must tell the patient they are doing so. The attorney general can sue to stop violations and seek civil penalties, which increase sharply for knowing or intentional conduct and for misusing protected health information for financial gain. The broader law also adds security, access, and U.S. data-storage requirements for electronic health records.
-
In effect
Attorney General Raoul Urges Tech Companies to Stop the Spre
Illinois · Effective 2025-08-26 · Attorney General Raoul Urges Tech Companies to Stop the Spread of Deepfake Nonconsensual Intimate Imagery
The Illinois Attorney General joined a bipartisan coalition of attorneys general pressing search engines and payment platforms to curb AI-generated deepfake nonconsensual intimate imagery, referencing Illinois's AI-generated CSAM and NCII law.
-
In effect
Attorney General Skrmetti Leads 44 States in Demanding Compa
Tennessee · Effective 2025-08-25 · Attorney General Skrmetti Leads 44 States in Demanding Companies End Predatory AI Interactions with Kids
Tennessee's Attorney General led a bipartisan coalition of 44 states in a demand letter to 12 major AI companies to implement safeguards against sexualized AI chatbot interactions with minors, applying consumer-protection authority to AI harms.
-
In effect
Attorney General Brenna Bird Warns of Deepfake Dangers as St
Iowa · Effective 2025-08-19 · Attorney General Brenna Bird Warns of Deepfake Dangers as Students Head Back to School
The Iowa Attorney General issued a consumer alert warning parents and schools that AI-generated deepfake images used to harass or bully students are criminal acts under state and federal law.
-
In effect
Attorney General Ken Paxton Investigates Meta and Character.
Texas · Effective 2025-08-18 · Attorney General Ken Paxton Investigates Meta and Character.AI for Misleading Children with Deceptive AI-Generated Mental Health Services
The Texas Attorney General issued Civil Investigative Demands to Meta AI Studio and Character.AI to determine whether their AI chatbots deceptively marketed themselves as mental-health tools to children in violation of Texas consumer-protection law.
-
In effect
Adoption and Usage of Artificial Intelligence: Guidelines an
Michigan · Effective 2025-08-09 · Adoption and Usage of Artificial Intelligence: Guidelines and Responsibilities
Michigan's Department of Technology, Management and Budget issued guidelines establishing responsibilities for ethical AI use across state agencies, requiring data-classification awareness and human-in-the-loop review of AI-generated content.
-
In effect
ND HB 1167 (political ads using AI to impersonate must say so)
North Dakota · Effective 2025-08-01 · N.D. Cent. Code ch. 16.1-10; 2025 N.D. Laws (HB 1167)
North Dakota now requires a clear disclaimer on political advertising or communications that use artificial intelligence to visually or audibly impersonate a real person. Covered content must display the statement 'THIS CONTENT GENERATED BY ARTIFICIAL INTELLIGENCE.' The requirement targets AI impersonations in political video, audio, and images, and does not apply to ordinary tools like spell-check, grammar correction, or stylistic editing.
-
In effect
Artificial Intelligence (AI) Governance Policy, Standard, an
Idaho · Effective 2025-08-01 · Artificial Intelligence (AI) Governance Policy, Standard, and Guideline
Idaho ITS's enterprise AI governance policy establishes a risk-classification framework, oversight responsibilities, and implementation requirements for AI use across state agencies and departments.
-
In effect
Executive Order 51 (2025): First-In-The-Nation Agentic Artif
Virginia · Effective 2025-07-11 · Executive Order 51 (2025): First-In-The-Nation Agentic Artificial Intelligence (AI) Empowered Statewide Regulatory Review
Governor Youngkin's order launches a pilot using agentic AI to scan the Commonwealth's regulations and guidance documents for redundant or outdated requirements and directs executive-branch agencies to incorporate AI into their periodic regulatory reviews.
-
In effect
SD Election Deepfake Law
South Dakota · Effective 2025-07-01 · SD SB 164 (2025); signed Mar. 31, 2025; eff. July 1, 2025
South Dakota requires that intentionally harmful, unlabeled AI deepfakes of politicians distributed within 90 days of an election carry an AI-manipulation disclosure; violators face civil and criminal liability. Broadcasters, newspapers, websites, and radio stations are exempt, as are satire and parody.
-
In effect
Minnesota SF 4097 (social-media algorithm disclosure)
Minnesota · Effective 2025-07-01 · Minn. Stat. 325M.30-325M.34; Laws 2024, ch. 114, art. 3, sec. 63 (SF 4097)
Minnesota requires large social media platforms to publicly explain how their algorithmic ranking systems decide what users see. Among other things, a platform must disclose how its own content-quality judgments and a user's stated content preferences are weighted against other ranking signals. The rules apply to platforms doing business in or targeting Minnesotans that have more than 10,000 monthly active users.
-
In effect
Generative AI Responsible Use (SS-25-001)
Georgia · Effective 2025-07-01 · Generative AI Responsible Use (SS-25-001)
The Georgia Technology Authority's enterprise standard requires executive-branch agencies to obtain GTA approval before procuring or using generative AI, keep humans in the loop reviewing GenAI output, disclose GenAI use, bar entry of PII/PHI without approval, maintain a GenAI inventory, and report incidents within 48 hours.
-
In effect
New AI Features for State of Alaska Employees - OIT Guidance
Alaska · Effective 2025-06-18 · New AI Features for State of Alaska Employees - OIT Guidance
Alaska's Office of Information Technology issued guidance for state employees using Microsoft 365 Copilot and Teams AI features, requiring them to review AI-generated content for accuracy and privacy, follow the ISP-172 acceptable-use policy, and recognize that Copilot-generated records may be subject to disclosure.
-
In effect
State of New Mexico: Generative AI Use Guidelines Policy (Ve
New Mexico · Effective 2025-06-01 · State of New Mexico: Generative AI Use Guidelines Policy (Version 1.0)
New Mexico's Department of Information Technology issued a signed policy leveraging the NIST AI Risk Management Framework to govern how executive agencies plan, develop, and deploy generative AI, including protection of non-public data.
-
In effect
Walters v. OpenAI
GA · Effective 2025-05-19 · Walters v. OpenAI, L.L.C., No. 23-A-04860-2 (Gwinnett Cty. Super. Ct., Ga.)
Georgia radio host Mark Walters sued OpenAI after ChatGPT fabricated a story that he had embezzled from a gun-rights nonprofit. In May 2025, Judge Tracie Cason granted summary judgment to OpenAI, holding that no reasonable reader would treat ChatGPT output as a statement of fact and that OpenAI's disclaimers about hallucinations defeated 'actual malice.' The first U.S. AI defamation case to reach a merits ruling.
-
In effect
Utah S.B. 226 (must disclose you're talking to AI on request; AI use no excuse)
Utah · Effective 2025-05-07 · Utah Laws 2025, S.B. 226; Utah Code 13-75-101 to 13-75-106
Utah requires businesses using generative AI in consumer interactions to come clean about it. If a consumer clearly asks whether they are dealing with AI, a supplier must disclose they are interacting with generative AI and not a human. People in licensed occupations must prominently disclose AI use up front in 'high-risk' interactions (health, financial, legal, mental-health advice or sensitive data). A safe harbor applies for clear self-identification, and it is no defense that the AI made the offending statement.
-
In effect
Utah S.B. 180 (AI-written police reports need a disclaimer + officer sign-off)
Utah · Effective 2025-05-07 · Utah Laws 2025, S.B. 180; Utah Code 53-25-601, 53-25-602
Utah requires every law enforcement agency to adopt a written policy governing employee use of generative AI. Any police report or law enforcement record created wholly or partly with generative AI must contain a disclaimer that it includes AI-generated content, and the author must certify they personally read and reviewed it for accuracy.
-
In effect
HB 452 (Mental Health Chatbots)
Utah · Effective 2025-05-07 · Utah Code § 13-2c-101 et seq. (HB 452, 2025)
Utah regulates AI chatbots that act like therapists: suppliers must clearly disclose the chatbot is not human, may not advertise products mid-conversation without disclosure, and may not sell or share users' individually identifiable health information.
-
In effect
The State of Maryland's Responsible AI Policy Implementation
Maryland · Effective 2025-05-01 · The State of Maryland's Responsible AI Policy Implementation Guidance (Version 1.0)
Maryland's Department of Information Technology guidance operationalizes the state's Responsible AI Policy, requiring agencies to designate an AI Lead, submit AI use cases through a risk-based intake process, complete Algorithmic Impact Assessments for high-risk systems, and document AI systems in a public inventory.
-
In effect
Board of Regents Policy 6.28, Use of Artificial Intelligence
University System of Georgia (USG) · Effective 2025-04-16 · Board of Regents Policy 6.28, Use of Artificial Intelligence (AI) in Academic Contexts
The USG Board of Regents adopted a policy requiring all 26 institutions to establish ethical, responsible, and secure AI-use policies integrated into their academic-integrity codes.
-
In effect
Policy on the Acceptable and Responsible Use of Artificial I
Illinois · Effective 2025-04-01 · Policy on the Acceptable and Responsible Use of Artificial Intelligence
The Illinois DoIT policy governs how state agencies under the Governor's jurisdiction may develop, deploy, and use AI systems, requiring each utilizing agency to designate an AI point of contact and inventory deployed AI systems within 30 days.
-
In effect
Generative Artificial Intelligence (AI) Policy (ENTERPRISE P
Iowa · Effective 2025-03-31 · Generative Artificial Intelligence (AI) Policy (ENTERPRISE PY-AI)
Iowa's enterprise generative-AI policy, issued under Iowa Administrative Code 129-8.4(8B), sets minimum requirements and prohibited uses for generative AI, mandating human review of AI outputs and disclosure of AI-generated code.
-
In effect
Kentucky SB 4 (AI Governance)
Kentucky · Effective 2025-03-24 · 2025 Ky. Acts (SB 4)
Kentucky SB 4 establishes an AI governance framework for state government — agencies need approval before deploying AI, must conduct risk assessments, disclose AI use in decisions, and keep human oversight for consequential decisions. It also bans undisclosed AI-generated content falsely depicting people in political communications, with a civil remedy for those depicted.
-
In effect
UT System Policy IT0002 / procedure, Acceptable Use of Gener
University of Tennessee System · Effective 2025-03-01 · UT System Policy IT0002 / procedure, Acceptable Use of Generative AI
The University of Tennessee System's acceptable-use policy for generative AI bars entering FERPA/HIPAA-protected and confidential data into AI tools and requires independent verification and disclosure of AI-generated content.
-
In effect
Responsible AI Usage Policy (107-004-190)
Oregon · Effective 2025-02-11 · Responsible AI Usage Policy (107-004-190)
Oregon Enterprise Information Services establishes enterprise-wide governance for generative and agentic AI across executive-branch agencies, requiring AI adoption plans, human review of outputs, approval of new AI uses, and use of only approved tools.
-
In effect
Initial Report - Arkansas Artificial Intelligence and Analyt
Arkansas · Effective 2025-02-07 · Initial Report - Arkansas Artificial Intelligence and Analytics Center of Excellence
The Arkansas AI and Analytics Center of Excellence (Department of Shared Administrative Services) delivered the governor an initial report recommending statewide AI governance, a Chief AI Officer, NIST-based evaluation of AI systems, updated procurement policies to safeguard citizen data, and AI-literacy training for state employees.
-
In effect
Alabama Generative AI Acceptable Use Policy (AI-GV-P2)
Alabama · Effective 2025-01-31 · Alabama Generative AI Acceptable Use Policy (AI-GV-P2)
Alabama's Office of Information Technology issued a NIST AI RMF-based acceptable-use policy requiring human review of GenAI output, annotation of AI-generated code/output, prohibition of confidential-data inputs, and OIT authorization before contractors use GenAI in state systems.
-
In effect
Rule Establishing Special Contract Terms for Large-Load Cust
Georgia Public Service Commission (Georgia Power) · Effective 2025-01-23 · Rule Establishing Special Contract Terms for Large-Load Customers Over 100 MW
The Georgia PSC unanimously approved a rule allowing Georgia Power to bill new customers using more than 100 MW under special terms, requiring them to cover transmission and distribution construction costs, permitting contracts up to 15 years, and mandating PSC review of each large-load contract.
-
In effect
Attorney General Bonta Legal Advisories on the Application o
California · Effective 2025-01-13 · Attorney General Bonta Legal Advisories on the Application of California Law to AI
California Attorney General Rob Bonta issued two legal advisories clarifying that entities developing, selling, or using AI must comply with existing California consumer-protection, civil-rights, competition, data-privacy, and election-misinformation laws, plus new AI laws effective January 1, 2025, with a second advisory targeting healthcare entities.
-
In effect
Executive Order No. 1584 (Fostering Stakeholder Collaboratio
Mississippi · Effective 2025-01-08 · Executive Order No. 1584 (Fostering Stakeholder Collaboration and Harnessing Artificial Intelligence)
Governor Tate Reeves directed the Department of Information Technology Services to inventory all state-agency AI, evaluate existing AI processes and procurement guidelines, and develop statewide responsible-AI policy recommendations.
-
In effect
IL Bar AI Standing Committee
IL · Effective 2025-01-01 · Ill. Sup. Ct. Policy on AI (eff. Jan. 1, 2025)
Illinois Supreme Court adopted a Policy on Artificial Intelligence (effective January 1, 2025) authorizing AI use by attorneys, judges, and court staff provided it complies with legal and ethical standards. The policy explicitly states that disclosure of AI use should not be required in a pleading, and does not impose mandatory CLE requirements; instead it supports ongoing education on AI and holds all users accountable for thoroughly reviewing AI-generated content before submission.
-
Blocked / in litigation
CA AB 2655 (deepfake takedown)
CA · Effective 2025-01-01 · Cal. Elec. Code §§ 20510–20517; AB 2655, Ch. 261, Stats. 2024
California passed a law requiring large online platforms to label or remove materially deceptive AI-generated content related to elections, and authorized candidates and election officials to sue for injunctive relief and damages. A federal court has blocked enforcement of key provisions while First Amendment litigation proceeds.
-
In effect
California AB 2905 (robocalls must disclose an AI-generated voice)
California · Effective 2025-01-01 · Cal. Pub. Util. Code 2874 (AB 2905, Stats. 2024)
When a caller uses an automatic dialing-announcing device to play a prerecorded message, California already requires a live-voice introduction. This law adds that the introduction must also tell the person if the prerecorded message uses an artificial voice, meaning a voice generated or significantly altered using AI. The point is to keep people from being deceived by synthetic voices in automated calls.
-
In effect
California AB 3030 (GenAI patient messages must carry an AI disclaimer)
California · Effective 2025-01-01 · Cal. Health & Safety Code 1339.75 (AB 3030, Stats. 2024)
If a hospital, clinic, or doctor's office uses generative AI to write or speak messages to patients about their clinical care, those messages must clearly tell the patient that AI generated the content and explain how to reach a human health care provider. The rule does not apply when a licensed provider reads and reviews the AI-generated message before it goes out.
-
In effect
California SB 896 (state AI risk analysis + AI disclaimers on gov communications)
California · Effective 2025-01-01 · SB 896, Stats. 2024 (Generative Artificial Intelligence Accountability Act)
This law directs California's Office of Emergency Services to study the threats that generative AI could pose to the state's critical infrastructure, including mass-casualty risks, and report a summary to the Legislature each year. It also requires any state agency that uses generative AI to communicate with people about government services to add a disclaimer that AI generated the message and explain how to reach a human state employee.
-
In effect
California AB 2355 (AI-generated political ads must disclose the AI use)
California · Effective 2025-01-01 · AB 2355, Stats. 2024 (amending the Political Reform Act of 1974)
A political committee that creates, publishes, or distributes a campaign ad whose images, audio, or video were generated or substantially altered using AI must include a clear disclosure stating that AI was used. The disclosure follows specific formatting rules depending on whether the ad is print, audio, or video. The state campaign-finance regulator can enforce it, with penalties up to $5,000 per violation.
-
In effect
Texas A&M System Regulation 29.01.05, Artificial Intelligenc
Texas A&M University System · Effective 2024-12-10 · Texas A&M System Regulation 29.01.05, Artificial Intelligence
The Texas A&M University System's AI regulation governs all AI activities system-wide, requiring AI inventories, data classification, bias audits, safeguards against algorithmic discrimination, and academic-integrity citation rules.
-
In effect
Policy on the Responsible and Ethical Use of Artificial Inte
Nevada · Effective 2024-11-27 · Policy on the Responsible and Ethical Use of Artificial Intelligence in Nevada State Government Executive Branch
The Nevada CIO-signed policy sets minimum standards for responsible, ethical, and transparent AI use across executive-branch agencies, requiring risk-based assessments, procurement/contract controls, and continuous monitoring of AI tools.
-
In effect
Alabama Election Deepfake Law
Alabama · Effective 2024-10-01 · 2024 Ala. Acts (HB 172)
Alabama criminalizes distributing materially false AI-generated media intended to harm a candidate or mislead voters within 90 days of an election. First violation is a misdemeanor; repeats within five years are felonies. Clearly disclaimed synthetic media is exempt.
-
In effect
North Carolina State Government Responsible Use of Artificia
North Carolina · Effective 2024-08-01 · North Carolina State Government Responsible Use of Artificial Intelligence Framework
NCDIT published a NIST-based framework of principles, practices, and guidance for state agencies deploying AI while reducing privacy and data-protection risks to residents.
-
In effect
Delaware AI Commission Act (government AI inventory)
Delaware · Effective 2024-07-17 · Del. H.B. 333, 152nd Gen. Assemb. (2024); 29 Del. C. ch. 90C
This law creates the Delaware Artificial Intelligence Commission, a state body charged with studying how artificial intelligence is used in Delaware government and recommending policies for its safe and responsible use. One of the Commission's required tasks is to take a full inventory of every generative-AI tool in use across the state's executive, legislative, and judicial agencies and to flag high-risk applications. The Commission issues recommendations but does not itself regulate private companies or impose penalties. It is scheduled to sunset ten years after enactment unless lawmakers extend it.
-
In effect
HB 919 (AI Political Ad Disclaimers)
Florida · Effective 2024-07-01 · Fla. Stat. § 106.145 (CS/HB 919, 2024)
Florida political ads that use generative AI to depict a real person doing something they never did — with intent to injure a candidate or deceive voters — must carry a clear disclaimer that the content was created with generative AI. Failing to include the disclaimer is a first-degree misdemeanor.
-
In effect
South Carolina State Agencies' Artificial Intelligence (AI)
South Carolina · Effective 2024-06-19 · South Carolina State Agencies' Artificial Intelligence (AI) Strategy
The South Carolina Department of Administration published a statewide AI strategy rooted in 'protect, promote, pursue' that establishes a Center of Excellence and AI Advisory Group and directs development of statewide acceptable-use, procurement, and data-protection policies for agencies.
-
In effect
AZ Election Deepfake Disclosure Law
Arizona · Effective 2024-05-29 · 2024 Ariz. Sess. Laws (SB 1359); A.R.S. tit. 16
Arizona requires creators and sponsors of AI-generated synthetic media in election communications to include a clear disclosure within 90 days before an election. News, satire, and parody are exempt; candidates can seek injunctions.
-
In effect
New Mexico Political Deepfake Law
New Mexico · Effective 2024-05-15 · 2024 N.M. Laws (HB 182), amending NMSA 1978 Campaign Reporting Act
New Mexico requires political campaigns to include a prominent disclaimer — 'This has been manipulated or generated by artificial intelligence' — on any campaign ad containing materially deceptive AI content, and criminalizes distributing materially deceptive political media.
-
In effect
Utah S.B. 131 (AI-generated political ads must say 'generated by AI')
Utah · Effective 2024-05-01 · Utah Laws 2024, S.B. 131; Utah Code 20A-11-1104, 76-3-203.18
Utah requires political audio and video communications that contain AI-generated 'synthetic media' to carry a clear disclosure that the content was made with AI. The rule covers paid communications meant to influence voting for or against a candidate or ballot proposition, and specifies the exact disclosure wording for audio, image, and video. A person can sue the creator or sponsor, and a court may impose a civil penalty of up to $1,000 per violation.
-
In effect
Utah AI Policy Act
Utah · Effective 2024-05-01 · Utah Code § 13-72-101 et seq. (SB 149, 2024; amended 2025)
The first state generative-AI consumer law: businesses can't hide behind AI — they remain liable under consumer protection law for what their chatbots say. People in regulated occupations (like healthcare providers) must proactively disclose AI use in high-risk interactions, and any business must disclose AI use when clearly asked.
-
In effect
DC Bar Op. 388 (GenAI)
DC · Effective 2024-04-24 · D.C. Bar Op. 388 (Apr. 24, 2024)
DC lawyers using generative AI must understand the tools they use, supervise AI output, protect client confidentiality, communicate with clients about AI, comply with billing rules, and avoid the unauthorized practice of law by AI chatbots.
-
In effect
NY Bar AI Report
NY · Effective 2024-04-06 · NYSBA AI Task Force Report (Apr. 6, 2024)
The New York State Bar adopted recommendations on AI in legal practice covering competence, confidentiality, supervision, candor to the court, and advertising — explicitly noting that 'hallucination' sanctions in Mata v. Avianca apply to all New York lawyers using AI.
-
In effect
Oregon SB 1571 (campaign ads must disclose AI/synthetic media)
Oregon · Effective 2024-03-27 · 2024 Or. Laws ch. 62 (SB 1571)
Oregon requires campaign communications that use synthetic media (an AI-generated or AI-manipulated image, audio, or video depicting a person's voice or likeness) to carry a disclosure telling viewers the content was altered or created with artificial intelligence. The Secretary of State (or the Attorney General when the Secretary of State race is involved) can go to court to stop a non-compliant communication. Violators can face a civil penalty.
-
In effect
WI AI Election Disclosure Law
Wisconsin · Effective 2024-03-22 · 2023 Wis. Act 123; Wis. Stat. ch. 11
Wisconsin requires political communications paid for by campaigns, PACs, or parties to carry a clear 'Contains content generated by AI' disclosure if they include synthetic media. Violations carry up to $1,000 per offense via the Ethics Commission.
-
In effect
California GenAI Procurement Guidelines and Toolkit
California · Effective 2024-03-21 · California GenAI Procurement Guidelines and Toolkit
California's Government Operations Agency and Department of Technology issued procurement guidelines and a toolkit requiring state entities to complete a SIMM 5305-F GenAI risk assessment, use written solicitations with a GenAI Disclosure & Fact Sheet, engage the CIO/AIO, and report GenAI contracts before procuring generative AI.
-
In effect
State of Arizona Statewide Policy P2000 - Generative AI Poli
Arizona · Effective 2024-03-01 · State of Arizona Statewide Policy P2000 - Generative AI Policy
The Arizona Department of Administration issued statewide policy P2000 governing responsible generative-AI use, requiring careful review of AI output, prohibiting feeding proprietary or sensitive information to public models, and emphasizing data governance, transparency, security, and privacy.
-
In effect
Executive Order No. 738 - Alabama Generative Artificial Inte
Alabama · Effective 2024-02-28 · Executive Order No. 738 - Alabama Generative Artificial Intelligence Task Force
Governor Kay Ivey created a Generative AI Task Force to study current GenAI use in executive-branch agencies and recommend policies for responsible and effective adoption within a governance structure ensuring transparency, bias testing, and privacy.
-
In effect
Michigan Election Deepfake Law
Michigan · Effective 2024-02-13 · 2023 Mich. Pub. Acts 263–266; MCL 169.259
Michigan requires clear AI-disclosure disclaimers on political ads created substantially with AI, and separately bans distributing materially deceptive media to influence an election within 90 days of a vote. Distributing election deepfakes without disclosure is a felony punishable by up to five years.
-
In effect
Michigan HB 5141 (AI political-ad disclaimer)
Michigan · Effective 2024-02-13 · 2023 Mich. Pub. Act 263 (HB 5141), amending the Michigan Campaign Finance Act
Michigan amended its Campaign Finance Act so that a political advertisement created in whole or substantially through artificial intelligence must carry a clear statement disclosing that AI was used. The rule reaches print, audio, and video messages relating to candidates, elections, or ballot questions in the state. The Secretary of State sets the size and placement standards for the required disclaimer, with limited exemptions for items too small to label.
-
In effect
Mayor's Order 2024-028: Articulating DC's Artificial Intelli
District of Columbia · Effective 2024-02-08 · Mayor's Order 2024-028: Articulating DC's Artificial Intelligence Values and Establishing Artificial Intelligence Strategic Benchmarks
Mayor Bowser's order defines six AI values (clear benefit to the people, safety & equity, accountability, transparency, sustainability, and privacy & cybersecurity), establishes an AI Advisory Group and AI Taskforce, and requires District agencies to verify AI-values alignment before deploying any AI tool.
-
In effect
Cease-and-Desist Order to Life Corporation over AI voice-clo
New Hampshire · Effective 2024-02-06 · Cease-and-Desist Order to Life Corporation over AI voice-clone voter-suppression robocalls
The NH Attorney General's Election Law Unit issued a cease-and-desist order to Life Corporation for AI-generated robocalls that cloned President Biden's voice to suppress votes in the 2024 primary, applying existing state voter-suppression law to deepfake audio.
-
In effect
NJ Supreme Court GenAI Notice
NJ · Effective 2024-01-25 · NJ Supreme Court Notice (Jan. 25, 2024)
The New Jersey Supreme Court issued a binding notice requiring lawyers using generative AI to comply with the Rules of Professional Conduct, including verifying citations, protecting client confidentiality, and supervising AI output. Sanctions follow citation hallucination.
-
In effect
FL Bar Op. 24-1 (GenAI)
FL · Effective 2024-01-19 · Fla. Bar Ethics Op. 24-1
Florida lawyers using generative AI must obtain informed client consent before using AI to handle client information, supervise AI like nonlawyer staff, verify factual and legal accuracy, comply with advertising rules for AI chatbots, and follow billing requirements that prevent overcharging.
-
In effect
Acceptable Use of Artificial Intelligence Technologies (NYS-
New York · Effective 2024-01-08 · Acceptable Use of Artificial Intelligence Technologies (NYS-P24-001)
New York's Office of Information Technology Services set enterprise rules requiring state agencies to conduct NIST-based risk assessments, maintain human oversight of AI decisions affecting the public, and disclose AI chatbots as non-human.
-
In effect
State of Indiana Artificial Intelligence Policy
Indiana · Effective 2024-01-01 · State of Indiana Artificial Intelligence Policy
Indiana's state AI policy, issued by the Office of the Chief Data Officer, applies the NIST AI Risk Management Framework and requires agencies to submit an AI Readiness Assessment Questionnaire and report existing AI systems before use.
-
In effect
Public Artificial Intelligence Services Security Standard
Minnesota · Effective 2024-01-01 · Public Artificial Intelligence Services Security Standard
Minnesota IT Services set a security standard governing state employees' use of public AI services (such as ChatGPT), restricting inputs to public/low-classification data and setting guardrails to prevent breaches of private or sensitive information.
-
In effect
Use of AI in Oklahoma State Government Standard
Oklahoma · Effective 2024-01-01 · Use of AI in Oklahoma State Government Standard
Oklahoma's Office of Management and Enterprise Services, under the state CIO, sets a mandatory standard requiring agencies to use only CIO-approved AI tools, complete AI awareness training, verify AI output, and never input sensitive data.
-
In effect
State of South Dakota Generative Artificial Intelligence Gui
South Dakota · Effective 2024-01-01 · State of South Dakota Generative Artificial Intelligence Guidelines & Acceptable State Use
The Bureau of Information and Telecommunications sets acceptable-use guidelines for generative AI in state government, requiring employees to fact-check, edit, and treat AI output as a starting point while managing bias, privacy, and cybersecurity risks.
-
In effect
Enterprise Artificial Intelligence Policy (200-POL-007)
Tennessee · Effective 2024-01-01 · Enterprise Artificial Intelligence Policy (200-POL-007)
Tennessee's Department of Finance and Administration (Strategic Technology Solutions) sets minimum requirements for valid, reliable, transparent, and ethical use of AI across state departments, requiring monitoring of AI design, deployment, and procurement to minimize negative impacts.
-
In effect
CCC systemwide AI guidance and HUMANS responsible-AI framewo
California Community Colleges Chancellor's Office · Effective 2024-01-01 · CCC systemwide AI guidance and HUMANS responsible-AI framework
The California Community Colleges Chancellor's Office issues systemwide AI guidance built on its HUMANS framework (human-centered, privacy, algorithmic-discrimination protections, notice and explanation, safety) governing AI in instruction and student support.
-
In effect
Penn State systemwide Generative AI Guidelines
Pennsylvania State University (Penn State) · Effective 2024-01-01 · Penn State systemwide Generative AI Guidelines
Penn State's systemwide AI guidelines set responsible-use rules covering FERPA/HIPAA compliance, output verification, accessibility review of AI tools, disclosure, and restrictions on AI-assisted grading across its multi-campus system.
-
In effect
Use of Artificial Intelligence (AI) in State of Ohio Solutio
Ohio · Effective 2023-12-04 · Use of Artificial Intelligence (AI) in State of Ohio Solutions (Policy IT-17)
Ohio's Department of Administrative Services adopted Policy IT-17 requiring state AI use to be fair, accountable, transparent, and human-centric, mandating piloting, human verification for consequential decisions, and limiting generative-AI inputs to public-record data.
-
In effect
Policy on Responsible Use of Generative Artificial Intellige
New Jersey · Effective 2023-11-17 · Policy on Responsible Use of Generative Artificial Intelligence by State Employees
New Jersey's policy directs state employees using generative AI to disclose and label AI use, independently fact-check outputs, and refrain from entering confidential or personally identifiable information into AI tools.
-
In effect
CA Bar GenAI Guidance
CA · Effective 2023-11-16 · State Bar of California, COPRAC Practical Guidance (Nov. 16, 2023)
California lawyers using ChatGPT, CoPilot, or other generative AI tools must protect client confidentiality, verify AI-generated work, supervise AI outputs, disclose AI use where required, and avoid billing for time saved by AI. Misuse of generative AI is a discipline-eligible violation.
-
In effect
Interim Guidelines for Purposeful and Responsible Use of Gen
Washington · Effective 2023-08-08 · Interim Guidelines for Purposeful and Responsible Use of Generative Artificial Intelligence (AI) in Washington State Government
WaTech's interim guidelines establish principles and dos-and-don'ts for state employees using generative AI, covering fact-checking, bias reduction, attribution, and protection of sensitive or confidential data.
-
In effect
State of Kansas Generative Artificial Intelligence Policy (P
Kansas · Effective 2023-07-31 · State of Kansas Generative Artificial Intelligence Policy (PPM 8200.00)
The Kansas Office of Information Technology Services enterprise policy sets acceptable-use rules for generative AI, requiring human review of all AI outputs, barring Restricted Use Information from AI tools, and imposing vendor disclosure and data-control requirements.
-
In effect
SB 5152 (Election Synthetic Media)
Washington · Effective 2023-07-23 · RCW ch. 42.62 (SB 5152, 2023)
Election ads in Washington that use AI-manipulated or synthetic depictions of candidates must disclose it. Candidates harmed by undisclosed synthetic media can sue for damages and injunctive relief.
-
In effect
Vermont H.410 / Act 132 (inventory of state AI / automated decision systems)
Vermont · Effective 2022-07-01 · 2022 Vt. Acts & Resolves No. 132 (H.410); 3 V.S.A. 3305
Vermont directed its Agency of Digital Services to review and catalog every automated decision system the state is building, using, or buying. The inventory must document each system's name, vendor, capabilities, data inputs, whether it was tested for bias, its intended purpose, and its costs, covering both systems that decide on their own and those that assist a human. The law also created state AI governance bodies, including a Division of Artificial Intelligence and an AI Advisory Council.
-
In effect
UC Responsible AI Principles and AI Council governance frame
University of California (UC System) · Effective 2021-10-01 · UC Responsible AI Principles and AI Council governance framework
UC was the first US university system to adopt Responsible AI Principles and stand up a systemwide AI Council that issues guidance, training, and risk assessments for AI use across its campuses.
-
In effect
NJ Bot Disclosure Act (bots must identify themselves)
New Jersey · Effective 2020-07-19 · N.J.S.A. 56:18-1 et seq.; P.L. 2019, c.486
New Jersey makes it unlawful to use an online bot to communicate or interact with a person in the state in order to deceive them about the bot's artificial identity, when the goal is to sell or advertise merchandise or real estate, or to solicit support for a candidate, party, or ballot question in an election. The use of the bot is allowed if it is clearly and conspicuously disclosed up front. The Attorney General enforces the law and can pursue civil penalties.
-
In effect
AI Video Interview Act
Illinois · Effective 2020-01-01 · 820 ILCS 42/1 et seq.
Employers using AI to analyze video interviews of Illinois job applicants must tell applicants beforehand, explain how the AI works, get consent, limit video sharing, and delete videos on request within 30 days. Employers relying solely on AI screening must report applicant demographic data to the state.
-
In effect
CA SB 1001 BOT Act (2018, historical framing)
CA · Effective 2019-07-01 · Cal. Bus. & Prof. Code §§ 17940-17943 (SB 1001, 2018)
Signed by Governor Brown on September 28, 2018, California SB 1001 was the first U.S. state law requiring bots to disclose they are not human when used to incentivize a sale or influence a vote. Still in effect 2026 at Cal. Bus. & Prof. Code §17940-17943. The first state bot-disclosure law and direct precursor to NJ Bot Disclosure Act (2019), federal Bot Disclosure Act of 2018 (S. 3127, died), and modern chatbot disclosure laws (UT SB 226, NE LB 525, etc.).
-
In effect
California Bot Disclosure Act (bots must self-identify in sales/election messaging)
California · Effective 2019-07-01 · Cal. Bus. & Prof. Code 17940-17943 (SB 1001, Stats. 2018)
California makes it unlawful to use a bot to communicate with someone in the state while concealing that it is a bot, when the goal is to deceive the person in order to push a commercial sale or influence their vote. There is a safe harbor: there is no liability as long as the operator clearly and conspicuously discloses that a bot is in use. In practice it is a disclosure mandate rather than a ban on automated accounts.
-
In effect
BART Surveillance Technology Ordinance
Bay Area Rapid Transit (BART) · Effective 2018-09-13 · BART Surveillance Technology Ordinance
BART became the first transit district in the country to adopt a CCOPS-style ordinance requiring board approval, a surveillance impact report, a use policy, and annual reports before acquiring surveillance technology.
-
Vetoed
Arizona HB 2592 AI state agencies — vetoed 2026
Arizona · Ariz. H.B. 2592, 57th Leg., 2d Reg. Sess. (2026) — vetoed June 19, 2026
Arizona HB 2592 would have required every state agency to identify opportunities to implement AI systems that reduce administrative burdens, eliminate regulations restricting AI adoption, streamline AI procurement, and establish internal AI governance policies. The bill passed the House 35-20 and the Senate 16-12 with bipartisan support, but Governor Katie Hobbs vetoed it on June 19, 2026, writing that state agencies were already weighing AI adoption and the bill was redundant. It was one of three AI bills — and 88 total bills — vetoed by Hobbs on the same day.
-
Repealed / replaced
Colorado AI Act (repealed)
Colorado · SB 24-205, Colo. Rev. Stat. § 6-1-1701 et seq. (repealed/replaced 2026)
The first comprehensive US state AI law would have required developers and deployers of 'high-risk' AI systems to use reasonable care to prevent algorithmic discrimination in decisions about jobs, housing, lending, insurance, education, and healthcare. After repeated delays, it was repealed and replaced in May 2026 by a narrower transparency-focused law (SB 26-189) before it ever took effect.
-
Proposed / pending
PR P. del S. 731 (AI Public Procurement Law)
Puerto Rico · P. del S. 731 (19th Leg. Assembly); Puerto Rico Senate approval ~May 28–30, 2026
Puerto Rico Senate Bill 731 would create the 'Law of Public Procurement with Artificial Intelligence of Puerto Rico,' centralizing all government purchases and public auctions under the General Services Administration and mandating use of the Joint E-Procurement Digital Intelligence (JEDI) AI platform across all government entities covered by Law 73-2019. JEDI automates procurement workflows, official publications, and incorporates all eight acquisition methods recognized by law. Approved by the Puerto Rico Senate in late May 2026; pending the House of Representatives and governor.
-
Proposed / pending
NJ Kids Code Act A4015 (2026)
NJ · N.J. A4015/S3413 (222nd Legislature, 2026) — cleared both chambers June 30, 2026; enrolled to governor
New Jersey A4015/S3413, the NJ Kids Code Act, is an Age-Appropriate Design Code bill modeled on the UK ICO Children's Code and California AB 2273 (CAADCA). It requires online platforms and services likely to be accessed by children under 18 to conduct data protection impact assessments, default privacy settings to the highest protective level for minor users, prohibit profiling children for commercial purposes without parental consent, and restrict design features that extend children's engagement. The Assembly cleared it 73-5-0; the Senate cleared it; enrolled to Governor Sherrill as of July 1, 2026. Governor Sherrill has not yet signed.
-
Proposed / pending
NY AI Professional Impersonation Liability Bill
New York · S.7263-A, 2025–2026 New York Legislature; adds GBL § 390-f
This pending New York bill would make AI-chatbot operators legally responsible if their chatbot impersonates a licensed professional — like a doctor, lawyer, or nurse — in a way that would be illegal if a person did it. The state Attorney General could sue violators for up to $15,000 per day, and operators would have to clearly tell users they are talking to an AI chatbot. After advancing on the Senate floor it was sent back to the Rules Committee in June 2026.
-
Proposed / pending
PR P. del S. 68 (Gov AI Framework)
Puerto Rico · P. del S. 68 (19th Leg. Assembly)
Senate bill creating a Chief AI Officer position at PR Innovation and Technology Service (PRITS) plus an AI Advisory Committee. Would govern PR government use of AI, require non-discrimination assessments, and mandate annual reports. Cleared Senate; pending House vote.
-
Proposed / pending
PR R.C. del S. 1 (AI Registry)
Puerto Rico · R.C. del S. 1 (19th Leg. Assembly)
Joint Senate Resolution directing PRITS to maintain a public registry of companies developing or deploying AI in Puerto Rico, broken down by sector. First transparency-registry measure of its kind for a US jurisdiction. In Conference Committee.
-
Repealed / replaced
UT SB 149 (superseded)
UT · Effective 2024-05-01 · Utah SB 149 (2024) — substantially superseded by SB 226/SB 332 (2025)
Utah SB 149 was the first-in-nation generative AI disclosure statute (2024), establishing a regulatory sandbox and consumer disclosure requirements. Substantially rewritten and narrowed by SB 226 and SB 332 in 2025.
-
Expired
AK SB 177 — AI deepfakes / cybersecurity / data privacy (dead, 2024)
Alaska · AK SB 177 (33rd Alaska Legislature, 2023-2024)
A 2023-2024 Alaska Senate bill that would have required disclosure of AI-generated deepfakes in campaign communications and addressed state cybersecurity and data privacy. It died without passing: the 33rd Alaska Legislature adjourned on May 15, 2024 with the bill still stuck in Senate committee referrals (Judiciary, then Finance). This entry is kept only as a historical record of a dead bill — it is NOT a law in effect and does not protect anyone today. The same subject matter is being pursued in the current 34th Legislature as AK SB 2.
-
Vetoed
CA SB 1047 (vetoed)
CA · Cal. SB 1047 (2023-24 Reg. Sess.) — vetoed Sept. 29, 2024
California SB 1047 would have required safety testing, kill-switches, and developer liability for frontier AI models trained above compute/cost thresholds. Governor Newsom vetoed it on September 29, 2024 — a landmark veto that reshaped the U.S. frontier-AI policy debate.
-
Expired
CA AB 3211 (died)
CA · Cal. AB 3211 (2023-24 Reg. Sess.) — died on suspense
California AB 3211 would have required watermarking and provenance metadata on generative AI outputs from large model providers. Died on the Senate Appropriations suspense file in August 2024.
-
Expired
OK HB 3577 (died)
OK · Okla. HB 3577 (2024 Reg. Sess.) — died on Senate floor
Oklahoma HB 3577 was a red-state AI rights framework with consumer disclosure requirements. Passed the House in 2024 but never received a Senate floor vote.
-
Vetoed
FL HB 919 (partially vetoed)
FL · Fla. HB 919 (2024) — signed April 26, 2024; effective July 1, 2024
Florida HB 919 requires disclaimers on AI-generated political ads. Governor DeSantis signed the bill on April 26, 2024; it became effective July 1, 2024. It was NOT vetoed.
County AI disclosure and transparency rules (15)
-
In effect
Wasatch County UT AI use policy (Jul. 15, 2026)
Wasatch County, UT · Effective 2026-07-15 · Wasatch County, UT Council unanimous vote, July 15, 2026, adopting county government AI use policy
Wasatch County, Utah unanimously adopted a policy on July 15, 2026 setting guardrails for county government use of artificial intelligence. The policy restricts county employees to approved AI tools only, requires disclosure when AI is used, and requires human verification of AI-generated output before it is relied on. The policy governs internal county government use of AI rather than regulating private-sector AI.
-
In effect
Montgomery County PA Generative AI Governance Policy
Montgomery County, PA · Effective 2025-11-18 · Montgomery County PA Commissioners policy (2025) (2025-11-18)
Montgomery County PA (Norristown) adopted AI governance policy: bars PII/PHI in public LLMs, requires CIO approval for AI procurement, mandates inventory of AI tools, and requires impact review before deployment in benefits or eligibility contexts.
-
In effect
Sonoma County CA AI Use Guidelines for County Government
Sonoma County, CA · Effective 2025-10-14 · Sonoma County Administrator policy (2025) (2025-10-14)
Sonoma County adopted AI use guidelines for county employees prohibiting PII/PHI in public LLMs, requiring departmental approval before AI use, mandating disclosure of AI assistance in resident-facing communications, and barring AI-only consequential decisions.
-
In effect
San Mateo County CA AI Use & Governance Policy
San Mateo County, CA · Effective 2025-06-10 · San Mateo County Manager policy (2025) (2025-06-10)
San Mateo County adopted AI use and governance policy: requires impact assessment before deployment of AI/ADS in resident-facing services, bans facial-recognition use by county departments without Board authorization, requires inventory of AI tools, and mandates annual public reporting.
-
In effect
Boulder County CO Generative AI Use Policy
Boulder County, CO · Effective 2025-05-13 · Boulder County Administrative Policy (2025) (2025-05-13)
Boulder County adopted generative AI use policy: requires staff training, prohibits entry of confidential or PII data into public LLMs, requires disclosure when AI is used in resident-facing communications, and bans AI-only decisions on benefits or enforcement.
-
In effect
Montgomery County MD AI Governance Framework
Montgomery County, MD · Effective 2025-04-30 · Montgomery County Executive Order 2-25 (AI) (2025-04-30)
Montgomery County Executive Order establishing AI governance framework: requires AI inventory, impact assessment before deployment in resident-facing services, mandatory human review of consequential decisions, prohibition on facial-recognition use by county departments without Council authorization, and annual public reporting.
-
In effect
Santa Clara County Surveillance Ordinance
Santa Clara County, CA · Santa Clara County, Cal., Ordinance Code div. A40 (NS-300.897, 2016)
Santa Clara County passed the nation's first county-level surveillance oversight law in 2016. County departments must get Board of Supervisors approval, publish a surveillance use policy, and file an impact report before acquiring surveillance technology, plus annual reports afterward. Still actively administered by the County Privacy Office.
-
In effect
King County GenAI Guidelines
King County, WA · Effective 2024-09-27 · King County, GenAI Guidelines for Employees (Sept. 2024)
King County issued guidelines for employee use of generative AI, developed jointly by King County IT and the Office of Equity, Racial and Social Justice. The guidelines aim to reduce bias and protect sensitive personal data entrusted to the county, with a software review process for GenAI tools.
-
In effect
Montgomery County Police Department Drone as First Responder
Montgomery County, MD · Effective 2023-11-20 · Montgomery County Police Department Drone as First Responder Program
Montgomery County Police launched a DFR program on November 20, 2023, limited to responding to calls for service, with no proactive surveillance, audio recording, or facial recognition and a warrant requirement for private areas.
-
In effect
Santa Cruz County AI Policy
Santa Cruz County, CA · Effective 2023-09-19 · County of Santa Cruz, AI Policy (Sept. 19, 2023)
Santa Cruz County adopted one of the earliest county-level AI policies in the US, approved in September 2023 and incorporated into the county's procedures manual. It governs how county employees may use AI (including generative AI), with safeguards for sensitive data and human accountability for outputs.
-
In effect
Spokane County Real-Time Crime Center (RTCC) surveillance us
Spokane County, WA (Spokane County Sheriff's Office) · Effective 2023-04-01 · Spokane County Real-Time Crime Center (RTCC) surveillance use policy
The Spokane County Sheriff's RTCC fuses surveillance cameras, license plate readers, BriefCam video analytics, 911 and social media data for real-time intelligence while stating it does not use facial recognition biometric software and applies access controls and audits.
-
Enacted (not yet in effect)
Morris County resolution urging state oversight of data cent
Morris County · Morris County resolution urging state oversight of data center power and water use
The Morris County Commissioners Court unanimously adopted a resolution calling on the Governor, Texas Legislature, PUC, and ERCOT to require data center developers to disclose projected power and water use, undergo independent impact reviews, and adopt water-efficient cooling.
-
Proposed / pending
Santa Fe County Sheriff proposed Clearview AI facial recogni
Santa Fe County, NM (Santa Fe County Sheriff's Office) · Santa Fe County Sheriff proposed Clearview AI facial recognition pilot contract
The Santa Fe County Sheriff's Office asked the County Commission to approve a $17,100 one-year Clearview AI facial recognition pilot, but commissioners tabled it and required the office to first present a use policy and vet vendor data-sharing (including with ICE).
-
Blocked / in litigation
Pima County Project Blue
Pima County, AZ · Pima County, Ariz., Project Blue rezoning and development agreement (2025); Pima Cnty. Super. Ct. litigation
Pima County's role in Project Blue is an approval, not a restriction: after Tucson rejected the project in August 2025, the county board voted 3–2 to rezone and sell roughly 290 acres of county land, and on December 16, 2025 approved a development agreement with Beale Infrastructure to move the data center forward in unincorporated Pima County. Opponents sued under Arizona's open meeting law; a judge dismissed that suit in April 2026, with additional litigation filed in January 2026.
-
Blocked / in litigation
PW Digital Gateway Litigation
Prince William County, VA · Oak Valley HOA et al. v. Prince William County (Va. Ct. App. Mar. 2026; appeal pending)
Courts voided Prince William County's December 2022 rezoning for the 2,100-acre Digital Gateway corridor of up to 37 data centers near Manassas Battlefield, finding the county violated state public-notice requirements. The Virginia Court of Appeals upheld that ruling on March 31, 2026. Following the ruling, Prince William County voted not to appeal to the Virginia Supreme Court, and developers also dropped their appeals, effectively ending the legal challenge.
City / local AI disclosure and transparency rules (101)
-
In effect
NYC AEDT Bias Audit Law (LL 144)
New York City, NY · Effective 2023-01-01 · NYC Local Law 144 of 2021; NYC Admin. Code §§ 20-870 to 20-874
Employers and employment agencies in New York City may not use AI hiring or promotion tools unless the tool has passed an independent bias audit within the past year. Job candidates must be told an automated tool is being used and can request information about the data it relies on.
-
In effect
Oakland Surveillance Ordinance & FR Ban
Oakland, CA · Oakland, Cal., Mun. Code ch. 9.64
Oakland requires City Council approval and public use policies before city agencies acquire any surveillance technology, and bans city use of facial recognition. In December 2020 the city added first-in-the-nation bans on predictive policing and other biometric surveillance (such as voice and gait recognition). Remains in effect, overseen by Oakland's Privacy Advisory Commission.
-
In effect
Portland Public Schools genAI pause (Jun. 23, 2026)
Portland, OR · Effective 2026-06-23 · Portland Public Schools (OR) Board of Education unanimous resolution via budget amendment, June 23, 2026, pausing generative AI expansion
The Portland Public Schools board in Oregon voted unanimously on June 23, 2026 to pause the expansion of generative AI in the district. Adopted as a budget amendment championed by board member La Forte, the resolution requires district staff to report back within 120 days on the district's inventory of generative AI tools, its contracts, and how vendors handle student data — and requires advance board authorization before the district signs any generative AI contract. The pause puts elected-board oversight between AI vendors and Oregon's largest school district while the data practices are examined.
-
In effect
Berkeley CA "The Berkeley Rule" AI Policy (2026)
Berkeley, CA · Effective 2026-03-10 · City of Berkeley, "The Berkeley Rule" and AI Use Framework for City Government (City Council action March 10, 2026)
On March 10, 2026, the Berkeley City Council adopted "The Berkeley Rule" — a ten-principle framework authored by Councilmember Ben Bartlett to guide ethical, human-centered use of AI in all city operations. Companion AI guidelines from Councilmember Shoshana O'Keefe require departments to apply bias safeguards, maintain data privacy compliance, and ensure human oversight of automated decisions before deployment. The City Manager's office subsequently drafted a formal AI Administrative Regulation implementing these principles.
-
In effect
San Jose ALPR 30-day retention safeguards (2026)
San Jose, CA · Effective 2026-03-10 · City of San Jose ALPR Use Policy Amendment (City Council unanimous vote, March 10, 2026)
On March 10, 2026, San Jose City Council voted unanimously to tighten safeguards on the city's network of 474 Flock Safety license-plate-reader cameras. The new rules cut the data retention period from one year to 30 days, restrict where cameras can be placed, and limit data-sharing with outside law enforcement agencies to documented criminal investigations. San Jose is the largest U.S. city to have adopted a Government AI Coalition framework, and this vote aligned its ALPR rules with its broader digital-privacy principles.
-
In effect
Portland OR GenAI Policy
Portland, OR · Effective 2026-03-06 · City of Portland, BTS GenAI Use Policy (2024)
City of Portland Bureau of Technology Services policy on generative AI use by city employees, with required disclosure and prohibitions on entering sensitive data.
-
In effect
NYC GUARD Act (Gov't AI Accountability)
New York City, NY · Effective 2025-12-26 · NYC Council Int. Nos. 199-A, 926-A, 1024-A (GUARD Act, passed Nov. 25, 2025; lapsed into law Dec. 26, 2025; Intro 1024-A = Local Law 195 of 2025)
The NYC City Council unanimously passed three bills on November 25, 2025 known as the GUARD Act (Guaranteeing Unbiased AI Regulation and Disclosure), creating independent oversight of city government AI use. The package creates an independent Office of Algorithmic Data Accountability, sets mandatory fairness-testing and transparency standards for all agency AI tools, and requires a public registry of every AI system that has undergone a pre-deployment assessment. Because Mayor Adams neither signed nor vetoed the bills within the 30-day window, they lapsed into law on December 26, 2025. Intro 1024-A was assigned Local Law 195 of 2025; the Local Law numbers for Intros 199-A and 926-A still await Legistar confirmation.
-
In effect
Oakland GenAI Policy
Oakland, CA · Effective 2024-12-01 · City of Oakland ITD, Interim Security Guidelines for AI Usage (2024)
City of Oakland Information Technology Department policy on city employee use of generative AI tools, with disclosure rules and prohibitions on entering sensitive data.
-
In effect
Phoenix GenAI AUP
Phoenix, AZ · Effective 2024-03-01 · City of Phoenix, GenAI Acceptable Use Policy (2024)
City of Phoenix Information Technology Services Department policy on city employee use of generative AI tools, with disclosure rules and prohibitions on entering sensitive data.
-
In effect
DC AI Values Mayor's Order
Washington, DC · Effective 2024-02-08 · D.C. Mayor's Order 2024-028 (Feb. 8, 2024)
Mayor Bowser's order requires DC government agencies to check any AI deployment against six AI Values: clear benefit to the people, safety and equity, accountability, transparency, sustainability, and privacy and cybersecurity. It created an AI Taskforce, set deadlines including a mandatory AI procurement handbook, and requires every agency to submit an AI strategic plan in cohorts through October 2026.
-
In effect
San Jose AI Reviews Board
San Jose, CA · Effective 2023-08-01 · City of San Jose, AI Reviews Board (2023)
City of San Jose established an internal AI Reviews Board to review AI tools used by city departments and helped launch the multi-city GovAI Coalition for shared AI procurement standards.
-
In effect
Boston Interim GenAI Guidelines
Boston, MA · Effective 2023-05-18 · City of Boston, Interim Guidelines for Using Generative AI (May 18, 2023)
Boston Mayor's Office interim guidelines authorizing limited use of generative AI tools by city employees with required disclosure and prohibitions on entering sensitive data.
-
In effect
San Diego Surveillance Tech Ordinance
San Diego, CA · Effective 2022-08-23 · San Diego Mun. Code ch. 2, art. 10, div. 41 (Ord. O-21492, O-21493) (2022)
San Diego ordinance requiring City Council approval and a published use policy for any city surveillance technology, including the Smart Streetlights and ALPR programs, with a Privacy Advisory Board overseeing impact reports.
-
In effect
NYC EO 3 / Citywide AI Policy
New York City, NY · Effective 2022-01-19 · N.Y.C. Exec. Order No. 3 (Jan. 19, 2022)
Mayoral executive order consolidating NYC's technology agencies by redesignating the Department of Information Technology and Telecommunications as the Office of Technology and Innovation (OTI), which oversees the Mayor's Office of Data Analytics, the Chief Technology Officer, the Office of Information Privacy, NYC Cyber Command, NYC 311, and the Algorithms Management and Policy office.
-
In effect
NYC Algorithmic Tools Reporting (LL35)
New York City, NY · Effective 2022-01-15 · NYC Admin. Code § 3-119.5 (Local Law 35 of 2022)
Every NYC agency must publicly report, each year, every algorithmic tool it used to make or assist decisions that materially affect the public's rights, benefits, or access to services. Reports must describe each tool's purpose, the data it uses, and any vendor involvement, and are published as an open dataset.
-
In effect
Tacoma Surveillance Ordinance
Tacoma, WA · Effective 2017-09-12 · Tacoma Mun. Code ch. 1.42 (Ord. 28427) (2017)
Tacoma ordinance requiring City Council approval and a public use policy before any city department acquires or uses surveillance equipment.
-
In effect
Seattle Surveillance Ordinance
Seattle, WA · Effective 2017-09-01 · Seattle Ordinance 125376 (2017), SMC ch. 14.18, as amended 2018
Seattle requires city departments to get City Council approval before acquiring or using surveillance technologies, supported by public Surveillance Impact Reports and review by a community working group. One of the earliest and most comprehensive municipal surveillance-oversight laws in the country.
-
In effect
Cambridge Surveillance Ordinance & FR Ban
Cambridge, MA · Cambridge, Mass., Mun. Code ch. 2.128, FR ban amendment (Jan. 13, 2020)
Cambridge requires City Council approval and impact reports before city departments use surveillance technology, and a unanimous January 2020 amendment banned city use of face surveillance. Surveillance impact reports were still being filed with the council in 2024–2025.
-
In effect
Resolution setting Seattle data-center impact-study framework
Seattle · Effective 2026-06-09 · Seattle Res 32204 (2026)
Companion resolution to CB 121214. Calls for impact studies on data centers' effects on electrical grid reliability, water consumption, environmental sustainability, utility rates, land use, employment, public health, and community welfare. Requests coordinated cross-departmental action to develop future policies.
-
In effect
Metro Nashville Police Drones as First Responder Trial Progr
Nashville, TN (Metro Nashville Police Department) · Effective 2026-05-22 · Metro Nashville Police Drones as First Responder Trial Program
Metro Nashville Police runs a DFR trial using three Skydio drones dispatched only to specific emergency calls, with no facial recognition or routine patrol and non-evidentiary footage deleted after 7 days.
-
In effect
Austin Transparent and Responsible Use of Surveillance Techn
Austin, TX · Effective 2026-04-23 · Austin Transparent and Responsible Use of Surveillance Technology (TRUST) Act
After letting its Flock ALPR contract expire in 2025, the Austin City Council passed the TRUST Act requiring council approval and public review before departments can acquire, use, or share data from surveillance technology like license plate readers and drones.
-
In effect
Tampa Police Department Drone as First Responder Program
Tampa, FL · Effective 2026-03-01 · Tampa Police Department Drone as First Responder Program
Tampa PD operates a Skydio-based DFR pilot in the Ybor and Downtown areas governed by Florida Statute 934.50, prohibiting facial recognition, weaponization, and warrantless surveillance of private areas.
-
In effect
Orlando Police Department Drone as First Responder Program (
Orlando, FL · Effective 2026-02-24 · Orlando Police Department Drone as First Responder Program (Axon contract approved by City Council)
Orlando City Council approved a $6.83M Axon DFR program on February 24, 2026, deploying 11 drones across 9 rooftop docking stations for automated 911-call response, governed by state law and limited to specific calls rather than mass surveillance.
-
In effect
Generative and Agentic AI in SFUSD (staff guidance)
San Francisco Unified School District, CA · Effective 2026-01-20 · Generative and Agentic AI in SFUSD (staff guidance)
San Francisco Unified published generative and agentic AI guidance for staff covering recommended uses, hallucination and privacy risks, and unreliability of AI plagiarism checkers, noting it is guidance rather than board-approved policy.
-
In effect
San Marcos City Council votes to discontinue Flock Safety AL
San Marcos, TX · Effective 2025-12-02 · San Marcos City Council votes to discontinue Flock Safety ALPR contract
The City Council voted on December 2, 2025 to discontinue its Flock Safety contract, and all city-contracted Flock cameras were deactivated and removed as of February 1, 2026.
-
In effect
Township High School District 211
Palatine, IL · Effective 2025-10-13 · Township High School District 211 — AI Use Guidelines (2025-10-13)
D211 guidelines authorize district-vetted enterprise AI tools, bar student entry of PII into non-approved AI, require teacher disclosure of AI use, and prohibit AI as sole basis for grading or discipline.
-
In effect
Durham NC Public Schools
Durham, NC · Effective 2025-09-25 · Durham NC Public Schools — Generative AI Acceptable Use Guidelines (2025-09-25)
DPS Board-reviewed guidelines authorize district-vetted enterprise AI tools, require teacher disclosure of AI use in instruction, bar non-consensual deepfakes, prohibit AI-only grading or discipline, and require parental consent for student AI accounts under 13. Anchored in Policy 3225/4312/7320 (Technology Responsible Use).
-
In effect
Iowa City Community School District
Iowa City, IA · Effective 2025-09-25 · Iowa City Community School District — Generative AI Use Guidelines and Board Policy 605.8R1 (effective September 2025)
Iowa City Community School District (ICCSD) guidelines authorize Microsoft Copilot enterprise on district devices; bar student entry of PII into non-approved AI; require teacher disclosure of AI use; and prohibit AI as sole basis for grading or discipline. The district also adopted Board Policy 605.8R1 governing student use of technology including AI.
-
In effect
Baltimore City Public Schools
Baltimore, MD · Effective 2025-09-09 · Baltimore City Public Schools — Generative AI Use Guidance (2025-09-09)
City Schools districtwide guidance authorizes vetted enterprise AI tools, bars student entry of PII into non-approved AI, requires teacher disclosure of AI use in instruction, and prohibits AI as sole basis for grading or discipline. Anchored in Board Policy IIBE (Acceptable Use).
-
In effect
Fresno USD AI Guidance
Fresno, CA · Effective 2025-09-09 · Fresno USD AI Guidance (2025-09-09)
Fresno Unified School District publishes official AI guidance on the district's IT/AI department page: district-vetted GenAI tools authorized, PII entry into non-approved AI barred, teacher disclosure when AI is used in instruction required, AI prohibited as the sole basis for grading or discipline.
-
In effect
AUHSD AI Guidance
Anaheim, CA · Effective 2025-09-03 · AUHSD AI Guidance (2025-09-03)
Anaheim Union High School District board adopted an AI policy on September 3, 2025: authorizes Microsoft Copilot enterprise and Khanmigo in closed-loop configurations, bars PII entry into non-approved AI, requires teacher disclosure of AI use, and prohibits AI-generated impersonation of students or staff.
-
In effect
Evanston deactivates 19 ALPR cameras and terminates Flock Sa
Evanston, IL · Effective 2025-08-26 · Evanston deactivates 19 ALPR cameras and terminates Flock Safety contract
Evanston deactivated all 19 of its Flock cameras and issued a termination notice effective September 26, 2025 after a state audit found Flock illegally shared Illinois data with U.S. Customs and Border Protection.
-
In effect
Mesa Public Schools AZ
Mesa, AZ · Effective 2025-08-19 · Mesa Public Schools AZ — Generative AI Use Guidelines (2025-08-19)
Mesa Public Schools (Arizona's largest district) adopted districtwide GenAI guidelines: authorizes Microsoft Copilot enterprise and Khanmigo for grades 9-12; requires teacher disclosure of AI use; bars student entry of PII into non-approved AI; and ties violations to Governing Board Policy IJNDB (Acceptable Use).
-
In effect
Tucson Project Blue Rejection
Tucson, AZ · Effective 2025-08-06 · Tucson Mayor and Council action, Aug. 6, 2025
On August 6, 2025, the Tucson City Council voted 7-0 to reject annexation and a development agreement for Project Blue, a roughly 290-acre data center campus that would have become the city's largest water user, after intense public opposition over secrecy and water use. The city is now drafting tighter rules for future data center development.
-
In effect
Austin AI Governance Resolution (2025)
Austin, TX · Effective 2025-04-24 · City of Austin, Tex., Resolution 20250424-055 (adopted Apr. 24, 2025)
The Austin City Council voted unanimously on April 24, 2025 to adopt Resolution 20250424-055, establishing an ethical AI governance framework for municipal operations. The resolution prohibits real-time employee surveillance by AI, bans AI-based productivity scoring or behavioral monitoring without human supervisor review and verification, bars AI from automated policing decisions, and creates a 'no displacement without consultation' labor policy guaranteeing that no AI system will significantly alter or eliminate job classifications without prior notice and consultation with affected employees and their unions. It also requires an annual public audit of all city AI use, mandates human review and oversight for all AI-influenced decisions, and directs the City Manager to study the environmental and equity impacts of data centers in the region. Sponsored by Mayor Pro Tem Vanessa Fuentes.
-
In effect
Real-Time Crime Center Surveillance Impact Report and Crime
Seattle, WA · Effective 2024-10-01 · Real-Time Crime Center Surveillance Impact Report and Crime Prevention Technology Pilot legislation
Seattle's Real-Time Crime Center was authorized under the city's surveillance ordinance through a Council-approved Surveillance Impact Report, requiring Council sign-off for material changes and an independent Office of Inspector General evaluation of its analytics.
-
In effect
Dallas GenAI Directive
Dallas, TX · Effective 2024-09-01 · City of Dallas Admin. Directive, Generative AI Use (2024)
City of Dallas administrative directive on generative AI use by employees, with disclosure, prohibited data, and review requirements.
-
In effect
Hartford GenAI Policy
Hartford, CT · Effective 2024-09-01 · City of Hartford MHIS, GenAI Acceptable Use Policy (2024)
City of Hartford administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Greensboro GenAI Policy
Greensboro, NC · Effective 2024-09-01 · City of Greensboro IT Dept., GenAI Acceptable Use Policy (2024)
City of Greensboro administrative policy on employee use of generative AI tools with disclosure, prohibited-data, and human-review requirements.
-
In effect
OKC GenAI Policy
Oklahoma City, OK · Effective 2024-09-01 · City of OKC IT Dept., GenAI Acceptable Use Policy (2024)
City of Oklahoma City administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Salem OR GenAI Policy
Salem, OR · Effective 2024-09-01 · City of Salem OR IT Dept., GenAI Acceptable Use Policy (2024)
City of Salem OR administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Hialeah GenAI Policy
Hialeah, FL · Effective 2024-09-01 · City of Hialeah, Resolution No. 2024-346 (2024)
City of Hialeah administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Policy 5110 - CCSD Policy on Generative Artificial Intellige
Chappaqua Central School District, NY · Effective 2024-08-29 · Policy 5110 - CCSD Policy on Generative Artificial Intelligence (AI) Integration
Chappaqua CSD's board-adopted GenAI policy prohibits district users from inputting FERPA-protected student data or Education Law 2-d protected information into AI systems, requires use of only Ed Law 2-d compliant approved tools with students, and mandates transparency about how AI is used.
-
In effect
KCMO GenAI Policy
Kansas City, MO · Effective 2024-08-01 · City of Kansas City MO, GenAI Use Policy (2024)
City of Kansas City Missouri administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review requirements.
-
In effect
Providence GenAI Policy
Providence, RI · Effective 2024-08-01 · City of Providence IT Dept., GenAI Acceptable Use Policy (2024)
City of Providence administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Tulsa GenAI Policy
Tulsa, OK · Effective 2024-08-01 · City of Tulsa IT Dept., AI Policy No. 1300-COP-AI-POLICY (eff. Feb. 25, 2026)
City of Tulsa administrative policy on employee use of generative AI tools, with disclosure, prohibited-data, and human-review rules.
-
In effect
Birmingham AL GenAI Policy
Birmingham, AL · Effective 2024-08-01 · City of Birmingham AL, Interim Guidelines For Using Generative Artificial Intelligence (2024)
City of Birmingham AL administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Henderson NV GenAI Policy
Henderson, NV · Effective 2024-08-01 · City of Henderson NV IT Dept., GenAI Acceptable Use Policy (2024)
City of Henderson NV administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
CPS AI Guidebook (generative AI guidance for students, staff
Chicago Public Schools, IL · Effective 2024-08-01 · CPS AI Guidebook (generative AI guidance for students, staff, families, administrators)
Chicago Public Schools published an AI Guidebook giving human-in-the-loop generative-AI guidance for students, staff, families, and administrators, requiring teacher permission and AI-use citation by students and barring confidential data in AI tools.
-
In effect
Detroit FR Policy Directive 307.5
Detroit, MI · Effective 2024-07-15 · Detroit Police Dep't Directive 307.5 (rev. June 28, 2024)
After three wrongful arrests of Black men from faulty facial recognition matches, Detroit settled a lawsuit and updated its policy: police cannot make an arrest based solely on a facial recognition match and must corroborate with independent evidence.
-
In effect
San Diego GenAI Policy
San Diego, CA · Effective 2024-07-01 · City of San Diego Admin. Reg., Generative AI Use (2024)
San Diego administrative policy governing employee use of generative AI tools, with disclosure, data-handling, and prohibited-use rules.
-
In effect
Metro Nashville GenAI Policy
Nashville, TN · Effective 2024-07-01 · Metro Nashville ITS, ISM-20: Artificial Intelligence and Generative Artificial Intelligence Use (Aug 2025)
Metropolitan Government of Nashville and Davidson County administrative policy on generative AI tool use by employees, with disclosure and data-handling rules.
-
In effect
Reno GenAI Policy
Reno, NV · Effective 2024-07-01 · City of Reno IT Dept., GenAI Acceptable Use Policy (2024)
City of Reno administrative policy on employee use of generative AI tools with disclosure, prohibited-data, and human-review rules.
-
In effect
Wilmington DE GenAI Policy
Wilmington, DE · Effective 2024-07-01 · City of Wilmington DE IT Dept., GenAI Acceptable Use Policy (2024)
City of Wilmington DE administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Arlington TX GenAI Policy
Arlington, TX · Effective 2024-07-01 · City of Arlington TX City Manager's Office / Strategic Initiatives, Generative AI Security Policy (approved 11/18/2024)
City of Arlington TX administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Plano GenAI Policy
Plano, TX · Effective 2024-06-01 · City of Plano, Generative AI Employee Use Policy (2024)
City of Plano administrative policy on employee use of generative AI tools, with disclosure, data-handling, and human-review rules.
-
In effect
Louisville Metro GenAI Policy
Louisville, KY · Effective 2024-06-01 · Louisville Metro Office of Technology, GenAI Use Policy (2024)
Louisville Metro administrative policy on employee use of generative AI tools, with prohibited data and disclosure rules.
-
In effect
SLC GenAI Policy
Salt Lake City, UT · Effective 2024-06-01 · Salt Lake City IMS, GenAI Acceptable Use Policy (2024)
Salt Lake City Information Management Services administrative policy on employee use of generative AI tools with disclosure and prohibited-data rules.
-
In effect
St. Louis GenAI Policy
St. Louis, MO · Effective 2024-06-01 · City of St. Louis ITSA, Guidance on Generative AI (Oct. 2023)
City of St. Louis administrative policy on employee use of generative AI tools, with disclosure, data, and human-review rules.
-
In effect
MPD Unmanned Aircraft Systems Program (General Order 803.09)
Washington, DC (Metropolitan Police Department) · Effective 2024-06-01 · MPD Unmanned Aircraft Systems Program (General Order 803.09)
The DC Metropolitan Police Department launched its UAS program in June 2024 under General Order 803.09, prohibiting facial recognition and weaponization and barring targeting based on protected characteristics.
-
In effect
SFPD Unmanned Aircraft System (Drone) Program authorized und
San Francisco, CA · Effective 2024-05-16 · SFPD Unmanned Aircraft System (Drone) Program authorized under Proposition E (SF Admin Code 96I.2)
After voters passed Proposition E in March 2024, SFPD began operating drones for criminal investigations, vehicle pursuits, and critical incidents, with publicly available flight logs starting May 16, 2024.
-
In effect
Fort Worth GenAI Policy
Fort Worth, TX · Effective 2024-05-01 · City of Fort Worth, Generative Artificial Intelligence (AI) Policy (approved Dec. 18, 2023)
Fort Worth administrative policy governing employee use of generative AI, with mandatory disclosure, prohibited data categories, and human review requirements.
-
In effect
Norfolk Flock ALPR Policy
Norfolk, VA · Effective 2024-05-01 · Norfolk PD Directive, Flock Safety ALPR (2024)
Norfolk Police Department directive governing use of Flock Safety automated license plate reader cameras, including retention, sharing, and audit requirements.
-
In effect
San Antonio GenAI Pilot Governance
San Antonio, TX · Effective 2024-04-01 · City of San Antonio ITSD, Administrative Directive 7.4a Attachment A – Acceptable Use of Generative AI Tools (May 2024); CIO Position Statement on AI Standards for COSA (January 2024)
San Antonio Information Technology Services Department governs generative AI through two instruments: a January 2024 CIO Position Statement providing an AI risk framework and playbook for all city employees, and a May 2024 Attachment A to Administrative Directive 7.4a titled 'Acceptable Use of Generative AI Tools' covering responsible use of third-party GenAI tools. AI technologies are tested and validated before procurement via AI FactSheet, Risk Assessment, and Findings Report. The 'SmartSA' branding in the original entry is inaccurate — these are ITSD administrative instruments, not SmartSA program documents.
-
In effect
Dallas RTCC / Fusus Policy
Dallas, TX · Effective 2024-03-01 · Dallas PD General Order, Real-Time Crime Center (2024)
Dallas Police Department directive governing operation of the Real-Time Crime Center, including third-party Fusus camera integration and ALPR feeds, with retention and audit requirements.
-
In effect
Memphis SkyCop Surveillance Program
Memphis, TN · Effective 2024-01-01 · Memphis PD, SkyCop / RTCC Operational Policy (2023)
Memphis Police Department SkyCop and Real Time Crime Center policy governing operation of city-wide surveillance cameras, integrations, and retention.
-
In effect
SF Generative AI Guidelines
San Francisco, CA · Effective 2023-12-11 · CCSF, Generative AI Guidelines (Dec. 2023, rev. July 2025)
San Francisco's citywide generative AI guidelines apply to employees, contractors, consultants, volunteers, and vendors working for the city. They require human review and disclosure of AI-generated content, prohibit entering non-public information into AI tools, ban concealing AI use, and bar generating deepfake-style images, audio, or video. Most recently revised in July 2025.
-
In effect
Seattle Generative AI Policy
Seattle, WA · Effective 2023-11-01 · City of Seattle, GenAI Policy POL-209 (eff. Nov. 1, 2023)
Seattle's generative AI policy governs how city employees use tools like ChatGPT. It requires attribution of AI-generated work, human review of all AI output before release, and limits on feeding personal information into AI systems, built around seven principles including bias reduction, transparency, and explainability.
-
In effect
San Jose GenAI Guidelines
San Jose, CA · Effective 2023-07-25 · City of San Jose, Generative AI Guidelines (June 12, 2023)
San Jose published one of the first US city-government playbooks for generative AI, requiring staff to log every use of tools like ChatGPT, complete training, and refrain from entering confidential information.
-
In effect
Peninsula School District AI Guidance (Principles and Belief
Peninsula School District, WA · Effective 2023-07-15 · Peninsula School District AI Guidance (Principles and Beliefs for AI Use)
One of the first US districts to publish AI guidance, Peninsula SD (WA) sets principles requiring staff to be diligent custodians of student data, cautions against unreliable AI detection tools, and mandates transparency and human oversight in all AI use.
-
In effect
Boston GenAI Guidelines
Boston, MA · Effective 2023-05-18 · City of Boston, Interim GenAI Guidelines v1.1 (May 18, 2023)
Boston was one of the first major US cities to issue generative AI guidance for its workforce. The interim guidelines tell city employees to never put confidential or personally identifying information into AI prompts, to fact-check all AI-generated content, and to disclose AI use, while encouraging responsible experimentation.
-
In effect
Portland Police Bureau Small UAS (Drone) Program authorized
Portland, OR · Effective 2023-04-05 · Portland Police Bureau Small UAS (Drone) Program authorized by City Council (Ordinance 191882)
Portland City Council authorized the Police Bureau to operate drones on April 5, 2023, expanded them citywide in September 2024, and launched a Drone as First Responder pilot in September 2025, with policy explicitly barring mass surveillance and facial recognition.
-
In effect
Privacy Protection and Technology Transparency Policy govern
Chula Vista, CA · Effective 2022-11-01 · Privacy Protection and Technology Transparency Policy governing the Real-Time Operations Center
Chula Vista's City Council adopted a privacy and technology-transparency policy and oversight commission governing how the police department's Real-Time Operations Center acquires surveillance tools and stores, shares, and profits from data such as drone and license-plate-reader feeds.
-
In effect
Ordinance on Surveillance Oversight and Information Sharing
Boston, MA · Effective 2021-10-21 · Ordinance on Surveillance Oversight and Information Sharing
Boston bars police from acquiring, deploying, or newly repurposing surveillance technology without City Council approval and restricts sharing student information with police, complementing its earlier facial-recognition ban.
-
In effect
Oakland City Council Drone Use Policy plus expanded biometri
Oakland, CA · Effective 2020-12-16 · Oakland City Council Drone Use Policy plus expanded biometric-surveillance and predictive-policing bans (amended Surveillance Transparency Ordinance)
On December 16, 2020, the Oakland City Council approved a drone use policy requiring annual reporting and, via revisions to its surveillance transparency ordinance, expanded its facial-recognition ban to other biometric surveillance and barred predictive-policing software.
-
In effect
Amendments to the Surveillance and Community Safety (CCOPS)
Oakland, CA · Effective 2020-12-15 · Amendments to the Surveillance and Community Safety (CCOPS) Ordinance prohibiting predictive policing analytics
Oakland amended its Community Control of Police Surveillance ordinance to expressly prohibit city use of predictive policing analytics (and biometric surveillance) while requiring City Council approval, with resident input, for any other surveillance technology.
-
In effect
NYPD POST Act
New York City, NY · Effective 2020-07-15 · NYC Local Law 65 of 2020, as amended 2025
The POST Act requires the NYPD to publicly disclose what surveillance technologies it uses and publish impact and use policies for each one. 2025 amendments added facial recognition audits, itemized technology inventories, and disclosure of outside entities that receive NYPD surveillance data.
-
In effect
Use of Surveillance Technology Ordinance (Ordinance 59300; M
Madison, WI · Effective 2020-01-01 · Use of Surveillance Technology Ordinance (Ordinance 59300; MGO 23.63)
Madison requires city agencies to notify the Mayor and Common Council and route surveillance-technology acquisitions through Council approval, plus annual public reporting on surveillance technology use.
-
In effect
San Francisco Acquisition of Surveillance Technology Ordinan
San Francisco Municipal Transportation Agency (SFMTA/Muni) · Effective 2019-05-14 · San Francisco Acquisition of Surveillance Technology Ordinance (facial-recognition ban covering Muni/SFMTA)
San Francisco's Surveillance Technology Ordinance bans city departments including the SFMTA/Muni from using facial recognition and requires surveillance-impact reports and annual use reports for surveillance tech.
-
In effect
Surveillance Technology Ordinance
Cambridge, MA · Effective 2018-12-10 · Surveillance Technology Ordinance
Cambridge bars city departments from funding, acquiring, or using surveillance technology without express City Council approval, requiring public impact reports, a use policy, and ongoing use reporting.
-
In effect
Community Control Over Police Surveillance (CCOPS) Ordinance
Yellow Springs, OH · Effective 2018-11-19 · Community Control Over Police Surveillance (CCOPS) Ordinance
Yellow Springs requires the police or municipal agencies to present new surveillance technology to Village Council for a public-hearing cost-benefit review and a use policy before adoption, with annual reporting.
-
In effect
Chula Vista Police Department Drone as First Responder (DFR)
Chula Vista, CA · Effective 2018-10-01 · Chula Vista Police Department Drone as First Responder (DFR) Program and UAS Policy
Chula Vista PD launched the nation's first Drone as First Responder program in 2018, deploying drones to 911 calls under a policy that bars recording where people have a reasonable expectation of privacy absent a warrant or emergency.
-
Proposed / pending
SU-47 Special-Use Data Center Zoning District Ordinance
Indianapolis / Marion County · SU-47 Special-Use Data Center Zoning District Ordinance
The Metropolitan Development Commission voted 5-3 to advance to the City-County Council a proposed SU-47 special-use zoning ordinance setting minimum standards for future data centers, including public hearings, noise limits, setbacks, and water-management and operations plans.
-
In effect
NYC AI Action Plan
New York City, NY · NYC OTI, AI Action Plan (Oct. 2023)
NYC's AI Action Plan is the city's roadmap for responsible government AI use, with 37 action items covering AI principles, agency guidance, procurement standards, risk assessment, and public engagement. It is policy guidance from the mayor's Office of Technology and Innovation rather than binding law; annual progress reports have followed.
-
In effect
San José AI Policy
San Jose, CA · City of San José Policy Manual § 1.7.12; GenAI Guidelines (2023, as updated)
San José adopted a citywide AI policy and generative AI guidelines governing how city staff use AI tools. Employees must register AI uses with the city's Privacy and AI team, may not let AI make actionable decisions about residents (like approving applications), and must review AI outputs. San José also founded the GovAI Coalition, whose AI policy templates have been adopted by 100+ public agencies.
-
In effect
Long Beach GenAI Guidance
Long Beach, CA · City of Long Beach, GenAI Guidance v1.3; AI Strategy (2025)
Long Beach's Smart City program issued Generative AI Guidance (now v1.3) for city staff, covering AI bias, data privacy, and cybersecurity, and in 2025 published a citywide AI Strategy committing to an AI use-case registry, workforce training, and community engagement. It builds on the city's council-approved 2021 Data Privacy Guidelines.
-
In effect
Pittsburgh GenAI Use Policy
Pittsburgh, PA · City of Pittsburgh internal GenAI policy (2023, updated 2024)
Pittsburgh adopted an internal policy on generative AI use by city staff, informed by the University of Pittsburgh's Task Force on Public Algorithms. It bars staff from entering private city data into tools like ChatGPT, prohibits AI use in applications that affect residents' rights or safety, forbids relying on generative AI for decisions, and requires AI use to be disclosed and logged.
-
Blocked / in litigation
Warrenton Amazon Data Center Fight
Warrenton, VA · Town of Warrenton SUP (Feb. 2023); Citizens for Fauquier County v. Town of Warrenton
Warrenton's zoning requires a special use permit for data centers; in February 2023 the Town Council narrowly approved one for an Amazon facility. Citizens for Fauquier County sued over both the zoning approval and related public-records (FOIA) access. In 2024, the Virginia Court of Appeals reversed the trial court and sided with the citizens' group on the FOIA matter, ordering review of over 3,100 withheld emails. The underlying land-use challenge and construction delays continued into 2025–2026.
-
In effect
New Orleans Surveillance/FR Rules
New Orleans, LA · New Orleans, La., Code ch. 147, as amended July 21, 2022
New Orleans banned facial recognition, predictive policing, and cell-site simulators in December 2020, but the council partially repealed the ban in July 2022, letting police use facial recognition (with human review and reporting) for serious violent crimes. In 2025 it emerged NOPD had received real-time facial recognition alerts from a private camera network in violation of these rules; alerts were paused in April 2025 and a proposal to authorize real-time FR was withdrawn, leaving the 2022 rules in place.
-
Proposed / pending
Use of Algorithms in Rental Rates Ordinance
Minneapolis, MN · Use of Algorithms in Rental Rates Ordinance
Minneapolis (third US city, 11-2 vote in March 2025) prohibits owners from using 'algorithmic devices' relying on non-public competitor data to set rents or occupancy, enforced through rental-license self-attestation and a tenant private right of action, effective March 1, 2026.
-
Expired
Flagstaff City Council votes unanimously to end Flock Safety
Flagstaff, AZ · Flagstaff City Council votes unanimously to end Flock Safety ALPR program
The Flagstaff City Council voted unanimously on December 16, 2025 to terminate its Flock contract and immediately deactivate all 32 cameras, citing privacy, cybersecurity, public-records, and data-sharing concerns.
-
Proposed / pending
Office of Artificial Intelligence Oversight
New York City · NYC Int 0919-2026
Would establish an Office of Artificial Intelligence Oversight within the Department of Consumer and Worker Protection. The office would investigate complaints about AI systems violating consumer protection laws, recommend enforcement actions, maintain a public complaint portal, run AI-harm consumer awareness campaigns, and propose rules clarifying how existing consumer protections apply to AI.
-
Proposed / pending
AI Gendered Impact Assessment + Interagency Taskforce
New York City · NYC Int 0287-2026
Requires the Department of Information Technology and Telecommunications to conduct biennial assessments of whether algorithmic tools using gender data may create disparate impacts. Establishes an interagency task force meeting at least twice yearly to evaluate how AI affects city employees' employment outcomes by gender (job displacement, role changes). Task force draws from administrative services, worker protection, human rights, technology, and gender equity agencies.
-
Status unknown
NYC resolution urging NY State to pass Advanced AI Licensing Act (A.3356)
New York City · NYC Res 0175-2026
Resolution urging the NY State Legislature to enact, and Governor Hochul to sign, the Advanced AI Licensing Act (A.3356) — which would establish state oversight through the Department of State, require licensing for high-risk AI systems, and ban particularly dangerous applications like autonomous weapons.
-
Status unknown
Atlanta City Council resolution accepting AI Commission recommendations
Atlanta · Atlanta 26-R-3663 (introduced June 1, 2026)
Resolution accepting the final report and 16 recommendations of the Atlanta AI Commission. Recommendations include equity impact assessments in AI procurement, role-specific staff training, cybersecurity standards for AI vendors, a public registry of all AI systems in use across City departments, and creation of a permanent AI Advisory Board co-chaired by the City's Chief Information Officer and Senior Technology Advisor. Directs the Mayor's office to examine administrative implementation steps while Council considers legislative follow-up.
-
Proposed / pending
NYC Int 1196-2025
New York, NY · NYC Int 1196-2025
NYC Int 1196-2025 proposes to amend the administrative code of the City of New York to prohibit the unauthorized depiction of public officials by artificial intelligence; it is not about additional requirements on city agencies' use of AI tools.
-
Proposed / pending
DC SDAA (B25-0114)
Washington, DC · D.C. Council B25-0114 (proposed)
A DC Council bill that would ban using algorithms to discriminate based on race, sex, age, or disability in important life decisions such as employment, housing, credit, insurance, and education, and would require notice and audits.
-
Proposed / pending
San Antonio DC Water Disclosure
San Antonio, TX · Data Center Frontier, June 2026
San Antonio council members proposed requiring data centers served by San Antonio Water System to publicly disclose annual water consumption.
-
Proposed / pending
Chicago City AI Ordinance (stalled)
Chicago, IL · Chicago, Ill., Ordinance O2024-0008864 (pending in committee)
A pending Chicago ordinance would set citywide guidelines for how city government adopts AI tools in areas like traffic analysis, public safety, and waste management, create a pilot program, and require semi-annual public reports on the city's AI use. It has sat in committee since April 2024 without a vote.
-
Proposed / pending
NYC AI Oversight Office Bill
New York City, NY · N.Y.C. Council Int. No. 0919-2026 (pending)
A pending New York City Council bill would write an office of artificial intelligence oversight into the City Charter and Administrative Code, building on the city's 2025 GUARD Act package on algorithmic accountability for city agencies. Awaiting committee action.
-
Expired
DC Algorithm Bill (not enacted)
Washington, DC · D.C. Council B24-0558 (2021); B25-0114 (2023) (not enacted)
A proposed DC law that would ban businesses from using algorithms that discriminate based on protected traits in decisions about jobs, housing, credit, insurance, and education, and would require annual bias audits and consumer disclosures. Despite multiple introductions since 2021, it has never been enacted — DC residents rely on federal protections.