WHAT THIS BILL REGULATES · 7 REQUIREMENT TYPES
How Is This Bill Enforced
Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.
The following words shall, unless the context clearly requires otherwise, have the following meanings:— "Algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1" means any condition in which the use of an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1" does not include: (1) the offer, license, or use of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 by a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 or deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 for the sole purpose of: (i) the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1's or deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended. "Artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments. "Consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service. "ConsumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1" means an individual who is a Massachusetts resident. "DeployDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1" means to use a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1. "DeployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1" means a person doing business in this state that deploysDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1 a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1. "DeveloperDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1. "Health-care services" has the same meaning as provided in 42 U.S.C. Sec. 234 (d)(2). "High-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1" means any artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 that, when deployed, makes, or is a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1. "High-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1" does not include: (1) an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 if the artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumersConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful. "Intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" or "intentionally and substantially modifies" does not include a change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if: (1) the high-risk artificial intelligence system continues to learn after the high-risk artificial intelligence system is: (i) offered, sold, leased, licensed, given, or otherwise made available to a deployer; or (ii) deployed; (2) the change is made to the high-risk artificial intelligence system as a result of any learning described in paragraph (1)(i) of this subsection; (3) the change was predetermined by the deployer, or a third party contracted by the deployer, when the deployer or third party completed an initial impact assessment of such high-risk artificial intelligence system pursuant to section 3 (c) (1); and (4) the change is included in technical documentation for the high-risk artificial intelligence system.Ch. 93M § 1" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 that results in any new reasonably foreseeable risk of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1. "Intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" or "intentionally and substantially modifies" does not include a change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if: (1) the high-risk artificial intelligence system continues to learn after the high-risk artificial intelligence system is: (i) offered, sold, leased, licensed, given, or otherwise made available to a deployer; or (ii) deployed; (2) the change is made to the high-risk artificial intelligence system as a result of any learning described in paragraph (1)(i) of this subsection; (3) the change was predetermined by the deployer, or a third party contracted by the deployer, when the deployer or third party completed an initial impact assessment of such high-risk artificial intelligence system pursuant to section 3 (c) (1); and (4) the change is included in technical documentation for the high-risk artificial intelligence system.Ch. 93M § 1" or "intentionally and substantially modifies" does not include a change made to a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, or the performance of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, if: (1) the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 continues to learn after the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is: (i) offered, sold, leased, licensed, given, or otherwise made available to a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1; or (ii) deployed; (2) the change is made to the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 as a result of any learning described in paragraph (1)(i) of this subsection; (3) the change was predetermined by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or a third party contracted by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, when the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or third party completed an initial impact assessment of such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 pursuant to section 3 (c) (1); and (4) the change is included in technical documentation for the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1. "Substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1" means a factor that: (1) assists in making a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1; (2) is capable of altering the outcome of a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1; and (3) is generated by an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1. "Substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1" includes any use of an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 to generate any content, decision, prediction, or recommendation concerning a consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 that is used as a basis to make a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1 concerning the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1. "Trade secretTrade secret"Trade secret" has the meaning set forth in section 42 (4) of chapter 93 of the General Laws, as appearing in the 2022 Official Edition.Ch. 93M § 1" has the meaning set forth in section 42 (4) of chapter 93 of the General Laws, as appearing in the 2022 Official Edition.
Section 1 establishes the definitional framework for the chapter. Key defined terms include high-risk artificial intelligence system (any AI system that makes or is a substantial factor in making a consequential decision), consequential decision (a decision with material legal or similarly significant effect across eight enumerated domains), developer, deployer, algorithmic discrimination, and substantial factor. The high-risk AI definition includes extensive carve-outs for narrow procedural tasks, pattern-detection tools subject to human review, and a long list of routine technologies (anti-fraud, anti-malware, cybersecurity, games, calculators, etc.) unless those technologies in fact make consequential decisions.
(a) 1 Not later than 6 months after the effective date of this act, a developer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 shall use reasonable care to protect consumersConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 from any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 arising from the intended and contracted uses of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1. In any enforcement action brought not later than 6 months after the effective date of this act, by the attorney general pursuant to section 6, there is a rebuttable presumption that a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 used reasonable care as required under this section if the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 complied with this section and any additional requirements or obligations as set forth in rules promulgated by the attorney general pursuant to section 7.
(b)(1)–(4) 2 Not later than 6 months after the effective date of this act, and except as provided in subsection (f) of this section, a developer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 shall make available to the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or other developer of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1: (1) a general statement describing the reasonably foreseeable uses and known harmful or inappropriate uses of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (2) documentation disclosing: (i) high-level summaries of the type of data used to train the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (ii) known or reasonably foreseeable limitations of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, including known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 arising from the intended uses of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (iii) the purpose of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (iv) the intended benefits and uses of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; and (v) all other information necessary to allow the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 to comply with the requirements of section 3; (3) documentation describing: (i) how the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 was evaluated for performance and mitigation of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 before the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 was offered, sold, leased, licensed, given, or otherwise made available to the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1; (ii) the data governance measures used to cover the training datasets and the measures used to examine the suitability of data sources, possible biases, and appropriate mitigation; (iii) the intended outputs of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (iv) the measures the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 has taken to mitigate known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 that may arise from the reasonably foreseeable deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; and (v) how the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 should be used, not be used, and be monitored by an individual when the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is used to make, or is a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1; and (4) any additional documentation that is reasonably necessary to assist the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 in understanding the outputs and monitor the performance of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 for risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1.
(c) 2 except as provided in subsection (f) of this section, a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 that offers, sells, leases, licenses, gives, or otherwise makes available to a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or other developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 not later than 6 months after the effective date of this act, shall make available to the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or other developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, to the extent feasible, the documentation and information, through artifacts such as model cards, dataset cards, or other impact assessments, necessary for a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or for a third party contracted by a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, to complete an impact assessment pursuant to section 3 (c). (2) a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 that also serves as a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 for a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is not required to generate the documentation required by this section unless the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is provided to an unaffiliated entity acting as a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1.
(d) 3 Not later than 6 months after the effective date of this act, a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 shall make available, in a manner that is clear and readily available on the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1's website or in a public use case inventory, a statement summarizing: (i) the types of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 that the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 has developed or intentionally and substantially modified and currently makes available to a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or other developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1; and (ii) how the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 manages known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 that may arise from the development or intentional and substantial modification of the types of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 described in accordance with subsection (d)(1)(i) of this section. (2) a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 shall update the statement described in subsection (d)(1) of this section: (i) as necessary to ensure that the statement remains accurate; and (ii) no later than ninety days after the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 intentionally and substantially modifies any high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 described in subsection (d)(1)(i) of this section.
(e) 4 Not later than 6 months after the effective date of this act, a developer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 shall disclose to the attorney general, in a form and manner prescribed by the attorney general, and to all known deployersDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or other developers of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 arising from the intended uses of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 without unreasonable delay but no later than ninety days after the date on which: (1) the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 discovers through the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1's ongoing testing and analysis that the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1's high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 has been deployed and has caused or is reasonably likely to have caused algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1; or (2) the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 receives from a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 a credible report that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 has been deployed and has caused algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1.
(f) nothing in subsections (b) to (e) of this section requires a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 to disclose a trade secretTrade secret"Trade secret" has the meaning set forth in section 42 (4) of chapter 93 of the General Laws, as appearing in the 2022 Official Edition.Ch. 93M § 1, information protected from disclosure by state or federal law, or information that would create a security risk to the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1.
(g) 5 Not later than 6 months after the effective date of this act, the attorney general may require that a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 disclose to the attorney general, no later than ninety days after the request and in a form and manner prescribed by the attorney general, the statement or documentation described in subsection (b) of this section. The attorney general may evaluate such statement or documentation to ensure compliance with this chapter, and the statement or documentation is not subject to disclosure under the "Massachusetts Public Records Law", chapter 66, section 10 of the General Laws. In a disclosure pursuant to this subsection (g), a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 may designate the statement or documentation as including proprietary information or a trade secretTrade secret"Trade secret" has the meaning set forth in section 42 (4) of chapter 93 of the General Laws, as appearing in the 2022 Official Edition.Ch. 93M § 1. To the extent that any information contained in the statement or documentation includes information subject to attorney-client privilege or work-product protection, the disclosure does not constitute a waiver of the privilege or protection.
Section 2 imposes four primary obligations on developers of high-risk AI systems: (a) a general duty of reasonable care to prevent algorithmic discrimination, with a rebuttable presumption of compliance if the developer satisfies the section's requirements; (b) detailed documentation that must be provided to deployers, covering foreseeable uses, training data summaries, discrimination risks, evaluation methods, data governance measures, and monitoring guidance; (c) provision of model cards, dataset cards, or impact assessments to enable deployers to complete their own impact assessments; (d) public website disclosure summarizing high-risk AI system types offered and discrimination risk management; and (e) mandatory disclosure to the attorney general and all known deployers within 90 days of discovering or receiving a credible report that a deployed system has caused algorithmic discrimination.
Subsection (f) provides a trade-secret carve-out for documentation obligations. Subsection (g) authorizes the attorney general to request developer documentation within 90 days, with public records exemptions and privilege protections.
(a) 6 Not later than 6 months after the effective date of this act, a deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 shall use reasonable care to protect consumersConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 from any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1. In any enforcement action brought not later than 6 months after the effective date of this act, by the attorney general pursuant to section 6, there is a rebuttable presumption that a deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 used reasonable care as required under this section if the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 complied with this section and any additional requirements or obligations as set forth in rules promulgated by the attorney general pursuant to section 7.
(b)(1)–(2) 7 Not later than 6 months after the effective date of this act, and except as provided in subsection (f) of this section, a deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 shall implement a risk management policy and program to govern the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1. The risk management policy and program must specify and incorporate the principles, processes, and personnel that the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1. The risk management policy and program must be an iterative process planned, implemented, and regularly and systematically reviewed and updated over the life cycle of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, requiring regular, systematic review and updates. A risk management policy and program implemented and maintained pursuant to this subsection (b) must be reasonable considering: (i) (A) the guidance and standards set forth in the latest version of the "Artificial Intelligence Risk Management Framework" published by the National Institute of Standards and Technology in the United States Department of Commerce, standard ISO/IEC 42001 of the International Organization for Standardization, or another nationally or internationally recognized risk management framework for artificial intelligence systemsArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1, if the standards are substantially equivalent to or more stringent than the requirements of this chapter; or (B) any risk management framework for artificial intelligence systemsArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 that the attorney general, in the attorney general's discretion, may designate; (ii) the size and complexity of the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1; (iii) the nature and scope of the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 deployed by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, including the intended uses of the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; and (iv) the sensitivity and volume of data processed in connection with the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 deployed by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1. (2) a risk management policy and program implemented pursuant to subsection (b)(1) of this section may cover multiple high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 deployed by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1.
(c)(1)–(3) 8 except as provided in subsections (c)(4), (c)(5), and (f) of this section: (i) a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or a third party contracted by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, that deploysDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1 a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 not later than 6 months after the effective date of this act, shall complete an impact assessment for the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; and (ii) Not later than 6 months after the effective date of this act, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or a third party contracted by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, shall complete an impact assessment for a deployed high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 at least annually and within ninety days after any intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" or "intentionally and substantially modifies" does not include a change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if: (1) the high-risk artificial intelligence system continues to learn after the high-risk artificial intelligence system is: (i) offered, sold, leased, licensed, given, or otherwise made available to a deployer; or (ii) deployed; (2) the change is made to the high-risk artificial intelligence system as a result of any learning described in paragraph (1)(i) of this subsection; (3) the change was predetermined by the deployer, or a third party contracted by the deployer, when the deployer or third party completed an initial impact assessment of such high-risk artificial intelligence system pursuant to section 3 (c) (1); and (4) the change is included in technical documentation for the high-risk artificial intelligence system.Ch. 93M § 1 to the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is made available. (2) an impact assessment completed pursuant to this subsection (c) must include, at a minimum, and to the extent reasonably known by or available to the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1: (i) a statement by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 disclosing the purpose, intended use cases, and deployment context of, and benefits afforded by, the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (ii) an analysis of whether the deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 poses any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 and, if so, the nature of the algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 and the steps that have been taken to mitigate the risks; (iii) a description of the categories of data the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 processes as inputs and the outputs the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 produces; (iv) if the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 used data to customize the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, an overview of the categories of data the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 used to customize the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (v) any metrics used to evaluate the performance and known limitations of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (vi) a description of any transparency measures taken concerning the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, including any measures taken to disclose to a consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is in use when the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is in use; and (vii) a description of the post-deployment monitoring and user safeguards provided concerning the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, including the oversight, use, and learning process established by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 to address issues arising from the deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1. (3) in addition to the information required under subsection (3)(b) of this section, an impact assessment completed pursuant to this subsection (c) following an intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" or "intentionally and substantially modifies" does not include a change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if: (1) the high-risk artificial intelligence system continues to learn after the high-risk artificial intelligence system is: (i) offered, sold, leased, licensed, given, or otherwise made available to a deployer; or (ii) deployed; (2) the change is made to the high-risk artificial intelligence system as a result of any learning described in paragraph (1)(i) of this subsection; (3) the change was predetermined by the deployer, or a third party contracted by the deployer, when the deployer or third party completed an initial impact assessment of such high-risk artificial intelligence system pursuant to section 3 (c) (1); and (4) the change is included in technical documentation for the high-risk artificial intelligence system.Ch. 93M § 1 to a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 not later than 6 months after the effective date of this act, must include a statement disclosing the extent to which the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 was used in a manner that was consistent with, or varied from, the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1's intended uses of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1.
(c)(6) 9 a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 shall maintain the most recently completed impact assessment for a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 as required under this subsection (c), all records concerning each impact assessment, and all prior impact assessments, if any, for at least three years following the final deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1.
(c)(7) 10 Not later than 6 months after the effective date of this act, and at least annually thereafter, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or a third party contracted by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, must review the deployment of each high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 deployed by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 to ensure that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is not causing algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1.
(d)(1) 11 Not later than 6 months after the effective date of this act, and no later than the time that a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 deploysDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1 a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 to make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1 concerning a consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1, the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 shall: (i) notify the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 that the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 has deployed a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 to make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1 before the decision is made; (ii) provide to the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 a statement disclosing the purpose of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 and the nature of the consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1; the contact information for the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1; a description, in plain language, of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; and instructions on how to access the statement required by subsection (5)(a) of this section; and (iii) provide to the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 information, if applicable, regarding the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1's right to opt out of the processing of personal data concerning the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1.
(d)(2) 12 Not later than 6 months after the effective date of this act, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 that has deployed a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 to make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1 concerning a consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 shall, if the consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1 is adverse to the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1, provide to the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1: (i) a statement disclosing the principal reason or reasons for the consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1, including: (A) the degree to which, and manner in which, the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 contributed to the consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1; (B) the type of data that was processed by the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 in making the consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1; and (C) the source or sources of the data described in subsection (d)(2)(i)(B) of this section; (ii) an opportunity to correct any incorrect personal data that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 processed in making, or as a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, the consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1; and (iii) an opportunity to appeal an adverse consequential decisionConsequential decision"Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (1) education enrollment or an education opportunity; (2) employment or an employment opportunity; (3) a financial or lending service; (4) an essential government service; (5) health-care services; (6) housing; (7) insurance; or (8) a legal service.Ch. 93M § 1 concerning the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 arising from the deployment of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1, which appeal must, if technically feasible, allow for human review unless providing the opportunity for appeal is not in the best interest of the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1, including in instances in which any delay might pose a risk to the life or safety of such consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1.
(d)(3) 11 except as provided in subsection (d)(3)(ii) of this section, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 shall provide the notice, statement, contact information, and description required by subsections (c)(1) and (d)(2) of this section: (A) directly to the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1; (B) in plain language; (C) in all languages in which the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, in the ordinary course of the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's business, provides contracts, disclaimers, sale announcements, and other information to consumersConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1; and (D) in a format that is accessible to consumersConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 with disabilities. (ii) if the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 is unable to provide the notice, statement, contact information, and description required by subsections (d)(1) and (d)(2) of this section directly to the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1, the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 shall make the notice, statement, contact information, and description available in a manner that is reasonably calculated to ensure that the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 receives the notice, statement, contact information, and description.
(e) 13 Not later than 6 months after the effective date of this act, and except as provided in subsection (f) of this section, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 shall make available, in a manner that is clear and readily available on the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's website, a statement summarizing: (i) the types of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 that are currently deployed by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1; (ii) how the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 manages known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 that may arise from the deployment of each high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 described pursuant to subsection (e)(1)(i) of this section; and (iii) in detail, the nature, source, and extent of the information collected and used by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1. (2) a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 shall periodically update the statement described in subsection (e)(1) of this section.
(f) subsections (b), (c), and (e) of this section do not apply to a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 if, at the time the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 deploysDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1 a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 and at all times while the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 is deployed: (1) the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1: (i) employs fewer than fifty full-time equivalent employees; and (ii) does not use the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's own data to train the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1; (2) the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1: (i) is used for the intended uses that are disclosed to the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 as required by section 2 (b)(1); and (ii) continues learning based on data derived from sources other than the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's own data; and (3) the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 makes available to consumersConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 any impact assessment that: (i) the developer of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 has completed and provided to the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1; and (ii) includes information that is substantially similar to the information in the impact assessment required under of this section.
(g) 14 if a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 deploysDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1 a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 not later than 6 months after the effective date of this act, and subsequently discovers that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 has caused algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1, the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, without unreasonable delay, but no later than ninety days after the date of the discovery, shall send subsection (c)(2) to the attorney general, in a form and manner prescribed by the attorney general, a notice disclosing the discovery.
(h) nothing in subsections (b) to (e) and (g) of this section requires a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 to disclose a trade secretTrade secret"Trade secret" has the meaning set forth in section 42 (4) of chapter 93 of the General Laws, as appearing in the 2022 Official Edition.Ch. 93M § 1 or information protected from disclosure by state or federal law. To the extent that a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 withholds information pursuant to this subsection (h) or section 5 (e), the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 shall notify the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 and provide a basis for the withholding.
(i) 15 Not later than 6 months after the effective date of this act, the attorney general may require that a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or a third party contracted by the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, disclose to the attorney general, no later than ninety days after the request and in a form and manner prescribed by the attorney general, the risk management policy implemented pursuant to subsection (b) of this section, the impact assessment completed pursuant to subsection (c) of this section, or the records maintained pursuant to subsection (c)(6) of this section. The attorney general may evaluate the risk management policy, impact assessment, or records to ensure compliance with this chapter, and the risk management policy, impact assessment, and records are not subject to disclosure under the "Massachusetts Public Records Law", chapter 66, section 10 of the General Laws. In a disclosure pursuant to this subsection (i), a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 may designate the statement or documentation as including proprietary information or a trade secretTrade secret"Trade secret" has the meaning set forth in section 42 (4) of chapter 93 of the General Laws, as appearing in the 2022 Official Edition.Ch. 93M § 1. To the extent that any information contained in the risk management policy, impact assessment, or records include information subject to attorney-client privilege or work-product protection, the disclosure does not constitute a waiver of the privilege or protection.
Section 3 is the longest and most obligation-dense section of the bill. It imposes on deployers: (a) a general duty of reasonable care to prevent algorithmic discrimination, with a rebuttable presumption of compliance; (b) a mandatory risk management policy and program that must be iterative, regularly reviewed, and proportionate to the deployer's size and system complexity, with NIST AI RMF, ISO/IEC 42001, or AG-designated frameworks as safe harbors; (c) mandatory impact assessments — initial and annual, plus within 90 days of any intentional and substantial modification — covering purpose, discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring, with a 3-year retention requirement; (d) consumer notification obligations including pre-decision notice, adverse-decision explanations with data type and source disclosure, data correction rights, and an appeal opportunity with human review; (e) public website disclosure of deployed system types and discrimination risk management; (g) mandatory AG notification within 90 days of discovering algorithmic discrimination; and (i) AG authority to request impact assessments and risk management documentation.
Subsection (f) carves out small deployers (fewer than 50 FTEs that do not use their own data to train the system) from the risk management, impact assessment, and public disclosure obligations, provided they use the system for its intended purposes and pass through the developer's impact assessment to consumers.
(a)–(b) 16 Not later than 6 months after the effective date of this act, and except as provided in subsection (b) of this section, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or other developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 that deploysDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1, offers, sells, leases, licenses, gives, or otherwise makes available an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 that is intended to interact with consumersConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 shall ensure the disclosure to each consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 who interacts with the artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 that the consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 is interacting with an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1. (b) disclosure is not required under subsection (a) of this section under circumstances in which it would be obvious to a reasonable person that the person is interacting with an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1.
Section 4 imposes a general AI identity disclosure obligation applicable to all consumer-facing artificial intelligence systems — not just high-risk systems. Deployers or other developers that make available an AI system intended to interact with consumers must ensure that each consumer is informed they are interacting with an AI system. The obligation is excused where it would be obvious to a reasonable person that the interaction is with an AI system.
(a)–(i) nothing in this chapter restricts a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1's, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's, or other person's ability to: (1) comply with federal, state, or municipal laws, ordinances, or regulations; (2) comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by a federal, a state, a municipal, or other governmental authority; (3) cooperate with a law enforcement agency concerning conduct or activity that the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person reasonably and in good faith believes may violate federal, state, or municipal laws, ordinances, or regulations; (4) investigate, establish, exercise, prepare for, or defend legal claims; (5) take immediate steps to protect an interest that is essential for the life or physical safety of a consumerConsumer"Consumer" means an individual who is a Massachusetts resident.Ch. 93M § 1 or another individual; (6) by any means other than the use of facial recognition technology, prevent, detect, protect against, or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activities, or illegal activity; investigate, report, or prosecute the persons responsible for any such action; or preserve the integrity or security of systems; (7) engage in public or peer-reviewed scientific or statistical research in the public interest that adheres to all other applicable ethics and privacy laws and is conducted in accordance with 45 CFR 46, as amended, or relevant requirements established by the federal Food and Drug Administration; (8) conduct research, testing, and development activities regarding an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 or model, other than testing conducted under real-world conditions, before the artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 or model is placed on the market, deployed, or put into service, as applicable; or (i) assist another developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person with any of the obligations imposed under this chapter. (b) the obligations imposed on developersDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployersDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other persons under this chapter do not restrict a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1's, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1's, or other person's ability to: (1) effectuate a product recall; or (2) identify and repair technical errors that impair existing or intended functionality. (c) the obligations imposed on developersDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployersDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other persons under this chapter do not apply where compliance with this chapter by the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person would violate an evidentiary privilege under the laws of this state. (d) nothing in this chapter imposes any obligation on a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person that adversely affects the rights or freedoms of a person, including the rights of a person to freedom of speech or freedom of the press that are guaranteed in: (1) the First Amendment to the United States constitution; or (2) Part the First, Article XVI of the state constitution. (e) nothing in this chapter applies to a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person: (1) insofar as the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person develops, deploysDeploy"Deploy" means to use a high-risk artificial intelligence system.Ch. 93M § 1, puts into service, or intentionally and substantially modifies, as applicable, a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1: (i) that has been approved, authorized, certified, cleared, developed, orgranted by a federal agency, such as the federal food and drug administration or the federal aviation administration, acting within the scope of the federal agency's authority, or by a regulated entity subject to the supervision and regulation of the federal housing finance agency; or (ii) in compliance with standards established by a federal agency, including standards established by the federal office of the national coordinator for health information technology, or by a regulated entity subject to the supervision and regulation of the federal housing finance agency, if the standards are substantially equivalent or more stringent than the requirements of this chapter; (2) conducting research to support an application for approval or certification from a federal agency, including the federal Aviation Administration, the federal Communications Commission, or the federal Food and Drug Administration or research to support an application otherwise subject to review by the federal agency; (3) performing work under, or in connection with, a contract with the United States Department of Commerce, the United States Department of Defense, or the National Aeronautics and Space Administration, unless the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person is performing the work on a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 that is used to make, or is a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a decision concerning employment or housing; or (4) that is a covered entity within the meaning of the federal "Health Insurance Portability and Accountability Act of 1996", 42 U.S.C. Secs. 1320d to 1320d-9, and the regulations promulgated under the federal act, as both may be amended from time to time, and is providing health-care recommendations that: (i) are generated by an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1; (ii) require a health-care provider to take action to implement the recommendations; and (iii) are not considered to be high risk. (f) nothing in this chapter applies to any artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 that is acquired by or for the federal government or any federal agency or department, including the United States Department of Commerce, the United States Department of Defense, or the National Aeronautics and Space Administration, unless the artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 is a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 that is used to make, or is a substantial factorSubstantial factor"Substantial factor" means a factor that: (1) assists in making a consequential decision; (2) is capable of altering the outcome of a consequential decision; and (3) is generated by an artificial intelligence system. "Substantial factor" includes any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as a basis to make a consequential decision concerning the consumer.Ch. 93M § 1 in making, a decision concerning employment or housing. (g) an insurer, as defined in chapter 175, a fraternal benefit society, as defined in chapter 176, or a developer of an artificial intelligence systemArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 used by an insurer is in full compliance with this chapter if the insurer, the fraternal benefit society, or the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 is subject to the requirements of chapter 175 and any rules adopted by the commissioner of insurance. (h) (1) a bank, out-of-state bank, credit union chartered by the state of Massachusetts, federal credit union, out-of-state credit union, or any affiliate or subsidiary thereof, is in full compliance with this chapter if the bank, out-of-state bank, credit union chartered by the state of Massachusetts, federal credit union, out-of-state credit union, or affiliate or subsidiary is subject to examination by a state or federal prudential regulator under any published guidance or regulations that apply to the use of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 and the guidance or regulations: (i) impose requirements that are substantially equivalent to or more stringent than the requirements imposed in this chapter; and (ii) at a minimum, require the bank, out-of-state bank, credit union chartered by the state of Massachusetts, federal credit union, out-of-state credit union, or affiliate or subsidiary to: (A) regularly audit the bank's, out-of-state bank's, credit union chartered by the state of Massachusetts', federal credit union's, out-of-state credit union's, or affiliate's or subsidiary's use of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 for compliance with state and federal anti-discrimination laws and regulations applicable to the bank, out-of-state bank, credit union chartered by the state of Massachusetts federal credit union, out-of-state credit union, or affiliate or subsidiary; and (B) mitigate any algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 caused by the use of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1 or any risk of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals on the basis of their actual or perceived age, color, disability, ethnicity, genetic information, limited proficiency in the English language, national origin, race, religion, reproductive health, sex, veteran status, or other classification protected under the laws of this state or federal law. "Algorithmic discrimination" does not include: (1) the offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (i) the developer's or deployer's self-testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (ii) expanding an applicant, customer, or participant pool to increase diversity or redress historical discrimination; or (2) an act or omission by or on behalf of a private club or other establishment that is not in fact open to the public, as set forth in Title II of the federal "Civil Rights Act of 1964", 42 U.S.C. Sec. 2000a (e), as amended.Ch. 93M § 1 that is reasonably foreseeable as a result of the use of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that, when deployed, makes, or is a substantial factor in making, a consequential decision. "High-risk artificial intelligence system" does not include: (1) an artificial intelligence system if the artificial intelligence system is intended to: (i) perform a narrow procedural task; or (ii) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review; or (2) the following technologies, unless the technologies, when deployed, make, or are a substantial factor in making, a consequential decision: (i) anti-fraud technology that does not use facial recognition technology; (ii) anti-malware; (iii) anti-virus; (iv) artificial intelligence-enabled video games; (v) calculators; (vi) cybersecurity; (vii) databases; (viii) data storage; (ix) firewall; (x) internet domain registration; (xi) internet website loading; (xii) networking; (xiii) spam- and robocall-filtering; (xiv) spell-checking; (xv) spreadsheets; (xvi) web caching; (xvii) web hosting or any similar technology; or (xviii) technology that communicates with consumers in natural language for the purpose of providing users with information, making referrals or recommendations, and answering questions and is subject to an accepted use policy that prohibits generating content that is discriminatory or harmful.Ch. 93M § 1. (i) if a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person engages in an action pursuant to an exemption set forth in this section, the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person bears the burden of demonstrating that the action qualifies for the exemption.
Section 5 is a comprehensive savings clause and exemptions section. It preserves the ability of developers, deployers, and other persons to comply with other laws, cooperate with law enforcement, conduct research, and effectuate product recalls. It exempts from the chapter: (1) high-risk AI systems approved or certified by federal agencies (FDA, FAA, etc.) or subject to equivalent federal standards; (2) research supporting federal agency applications; (3) work under federal government contracts (except employment/housing decisions); (4) HIPAA covered entities providing AI-generated health-care recommendations that require provider action and are not high-risk; (5) AI acquired by the federal government (except employment/housing); (6) insurers subject to Chapter 175; and (7) banks and credit unions subject to substantially equivalent state or federal prudential regulator guidance. The section also preserves First Amendment rights and state constitutional press/speech freedoms.
(a)–(f) the attorney general has exclusive authority to enforce this chapter. (b) except as provided in subsection (c) of this section, a violation of the requirements established in this chapter constitutes an unfair trade practice pursuant to chapter 93A. (c) in any action commenced by the attorney general to enforce this chapter, it is an affirmative that the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person: (1) discovers and cures a violation of this this chapter 93 as a result of: (i) feedback that the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person encourages deployersDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1 or users to provide to the developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person; (ii) adversarial testing or red teaming, as those terms are defined or used by the national institute of standards and technology; or (iii) an internal review process; and (2) is otherwise in compliance with: (i) the latest version of the "Artificial intelligence risk management framework" published by the national institute of standards and technology in the United States Department of Commerce and Standard ISO/IEC 42001 of the International Organization for Standardization; (ii) another nationally or internationally recognized risk management framework for artificial intelligence systemsArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1, if the standards are substantially equivalent to or more stringent than the requirements of this chapter; or (iii) any risk management framework for artificial intelligence systemsArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1 that the attorney general, in the attorney general's discretion, may designate and, if designated, shall publicly disseminate. (d) a developerDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1, a deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Ch. 93M § 1, or other person bears the burden of demonstrating to the attorney general that the requirements established in subsection (3) of this section have been satisfied. (e) nothing in this chapter, including the enforcement authority granted to the attorney general under this section, preempts or otherwise affects any right, claim, remedy, presumption, or defense available at law or in equity. A rebuttable presumption or affirmative defense established under this chapter applies only to an enforcement action brought by the attorney general pursuant to this section and does not apply to any right, claim, remedy, presumption, or defense available at law or in equity. (f) this chapter does not provide the basis for, and is not subject to, a private right of action for violations of this chapter or any other law.
Section 6 grants the attorney general exclusive enforcement authority. Violations constitute unfair trade practices under Chapter 93A. An affirmative defense is available where the entity (1) discovers and cures a violation through user feedback, adversarial testing/red teaming, or internal review, and (2) is otherwise in compliance with the NIST AI RMF and ISO/IEC 42001, an equivalent framework, or an AG-designated framework. The section expressly disclaims any private right of action and preserves all existing rights, claims, and remedies at law or equity. Rebuttable presumptions and affirmative defenses apply only in AG enforcement actions.
(a) the attorney general may promulgate rules as necessary for the purpose of implementing and enforcing this chapter, including: (1) the documentation and requirements for developersDeveloper"Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system.Ch. 93M § 1 pursuant to section 2 (b); (2) the contents of and requirements for the notices and disclosures required by sections 2 (c) and (g); 3 (d), (e), (g), and (i); and 4; (3) the content and requirements of the risk management policy and program required by section 3 (b); (4) the content and requirements of the impact assessments required by section 3 (c); (5) the requirements for the rebuttable presumptions set forth in sections 2 and 3; and (6) the requirements for the affirmative defense set forth in section 6 (c), including the process by which the attorney general will recognize any other nationally or internationally recognized risk management framework for artificial intelligence systemsArtificial intelligence system"Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.Ch. 93M § 1.
Section 7 authorizes the attorney general to promulgate rules to implement and enforce the chapter, covering developer documentation requirements, notice and disclosure contents, risk management policy requirements, impact assessment requirements, rebuttable presumption requirements, and affirmative defense requirements including the process for recognizing alternative risk management frameworks.