Massachusetts · Senate Bill · 193rd General Court (2023–2024)
SB31
An Act drafted with the help of ChatGPT to regulate generative artificial intelligence models like ChatGPT

Status ● Failed Effective N/A Passage Likelihood N/A

WHAT THIS BILL REGULATES · 5 REQUIREMENT TYPES

How Is This Bill Enforced

Enforcement Authority
Attorney General enforcement. The attorney general may bring an action pursuant to section 4 of chapter 93A against a person to remedy violations. The attorney general is also directed to adopt regulations to carry out the chapter. No private right of action is created by the bill itself.
Private Right of Action
No private right of action. Enforcement is exclusive to the designated authority.
Penalties
Enforcement is through attorney general action under chapter 93A, § 4, which provides for injunctive relief and civil penalties. The bill does not specify independent penalty amounts; remedies are those available under the existing 93A enforcement framework.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Ch. 93A½, § 1
Purpose

The purpose of this chapter is to regulate generative artificial intelligence models, such as ChatGPT, in order to protect the public's safety, privacy and intellectual property rights.

This section states the legislative purpose of Chapter 93A½: to regulate generative artificial intelligence models in order to protect the public's safety, privacy, and intellectual property rights. It creates no compliance obligation.

Ch. 93A½, § 2
Definitions

(a) A "large-scale generative artificial intelligence modelLarge-scale generative artificial intelligence modelA "large-scale generative artificial intelligence model" shall mean a machine learning model with a capacity of at least one billion parameters that generates text or other forms of output, such as ChatGPT.Ch. 93A½, § 2(a)" shall mean a machine learning model with a capacity of at least one billion parametersParameter"Parameter" shall mean any variable or value used to control the operation or output of a generative artificial intelligence model.Ch. 93A½, § 2(b) that generates text or other forms of output, such as ChatGPT.

(b) "ParameterParameter"Parameter" shall mean any variable or value used to control the operation or output of a generative artificial intelligence model.Ch. 93A½, § 2(b)" shall mean any variable or value used to control the operation or output of a generative artificial intelligence model.

This section defines the two key terms for the chapter. A large-scale generative artificial intelligence model is any machine learning model with at least one billion parameters that generates text or other output. Parameter is defined broadly as any variable or value used to control a model's operation or output. The one-billion-parameter threshold was a relatively rough proxy in early 2023; many commercially significant models exceed it by orders of magnitude.

Ch. 93A½, § 3
Operating Standards
DeployerDeveloper

(1) 1 the model shall not be used to engage in discrimination or bias against any individual or group based on protected characteristics, as defined by state or federal law;

(2) 2 in order to prevent plagiarism, the model shall be programmed to generate all text with a distinctive watermark or offer an authentication process that allows a user to determine whether a particular output was generated by the model;

(3) 3 the company shall implement reasonable security measures to protect the data of individuals used to train the model;

(4) 4 the company shall obtain informed consent from individuals before collecting, using or disclosing their data;

(5) 5 the company shall delete or de-identify any data collected from individuals if it is no longer needed for the intended purpose of the model; and

(6) 6 the company shall conduct regular risk assessments to identify, assess and mitigate reasonably foreseeable risks and cognizable harms related to their products and services, including in the design, development and implementation of such products and services.

Section 3 imposes six operating standards on any company operating a large-scale generative AI model. The obligations span non-discrimination, content watermarking or authentication, training-data security, informed consent for data collection, data minimization, and regular risk assessments. The provisions are broadly drafted — for example, the watermarking requirement applies to "all text" generated by the model, and the risk-assessment obligation uses general "reasonably foreseeable risks" language without specifying methodology or frequency beyond "regular."

Compliance actions 6 items
1
Companies operating a large-scale generative AI model must not use the model to engage in discrimination or bias against any individual or group based on protected characteristics as defined by state or federal law.
H-02
2
Companies must program their large-scale generative AI model to generate all text with a distinctive watermark, or offer an authentication process allowing users to determine whether a particular output was generated by the model.
T-02.1
3
Companies must implement reasonable security measures to protect the personal data of individuals used to train the model.
D-01
4
Companies must obtain informed consent from individuals before collecting, using, or disclosing their data for model training or operation.
D-01.8
5
Companies must delete or de-identify any data collected from individuals once it is no longer needed for the intended purpose of the model.
D-01.4
6
Companies must conduct regular risk assessments to identify, assess, and mitigate reasonably foreseeable risks and cognizable harms related to their generative AI products and services, including in design, development, and implementation.
S-01.5
Ch. 93A½, § 4
Registration with the Attorney General
DeployerDeveloper

(a) 7 Any company operating a large-scale generative artificial intelligence modelLarge-scale generative artificial intelligence modelA "large-scale generative artificial intelligence model" shall mean a machine learning model with a capacity of at least one billion parameters that generates text or other forms of output, such as ChatGPT.Ch. 93A½, § 2(a) shall register with the attorney general within 90 days of the effective date of this act.

(b)(1)–(3) 7 The registration shall include the following information: (1) the name and contact information of the company; (2) a description of the large-scale generative artificial intelligence modelLarge-scale generative artificial intelligence modelA "large-scale generative artificial intelligence model" shall mean a machine learning model with a capacity of at least one billion parameters that generates text or other forms of output, such as ChatGPT.Ch. 93A½, § 2(a), including its capacity, training data, intended use, design process and methodologies; and (3) information on the company's data collection, storage and security practices.

(c) The attorney general shall maintain a public registry of all companies registered under this act.

Section 4 requires companies operating a large-scale generative AI model to register with the attorney general within 90 days of the act's effective date. The registration must include company contact information, a description of the model (covering capacity, training data, intended use, design process, and methodologies), and information on data practices. The attorney general must maintain a public registry. This is an early example of a mandatory AI registration requirement — functionally similar to later pre-market registration obligations but framed as a post-effective-date compliance deadline rather than a pre-deployment gate.

Compliance actions 1 item
7
Companies must register with the attorney general within 90 days of the act's effective date, providing company contact information, a description of the model (including capacity, training data, intended use, design process, and methodologies), and information on data collection, storage, and security practices.
R-02.3
Ch. 93A½, § 5
Enforcement

(a) The attorney general shall adopt regulations for the purposes of carrying out this chapter.

(b) To remedy violations of this chapter and for other relief that may be appropriate, the attorney general may bring an action pursuant to section 4 of chapter 93A against a person.

Section 5 establishes the enforcement framework. The attorney general is directed to adopt implementing regulations and may bring enforcement actions under the existing chapter 93A, § 4 authority — the Commonwealth's consumer-protection enforcement statute. This leverages the well-established 93A enforcement apparatus rather than creating a bespoke penalty regime. No private right of action is created by this chapter.

SECTION 2
Effective Date

Chapter 93A½. of the General Laws shall take effect on the ninetieth day following the passage of this act.

The act takes effect on the ninetieth day following passage. This creates a 90-day implementation window for all obligations, and separately, Section 4 provides an additional 90 days from the effective date for the registration requirement — meaning companies would have had approximately 180 days from passage to complete registration.

SECTION 3
Disclaimer

This act has been drafted with the help of ChatGPT and any errors or inaccuracies in the bill should not be attributed to the language model but rather to its human authors.

An unusual disclaimer provision acknowledging that the bill was drafted with the assistance of ChatGPT and attributing any errors to the human authors rather than the language model. This creates no compliance obligation.

Passage Likelihood

Failed
Status Failed
Final action Accompanied a new draft, see S2539

Legislative History

2023-02-16 Referred to the Joint Committee on Advanced Information Technology, the Internet and Cybersecurity
2023-02-16 House concurred
2023-07-05 Hearing scheduled for 07/13/2023 from 01:00 PM-05:00 PM in B-2
2023-07-05 Hearing rescheduled to 07/13/2023 from 01:00 PM-05:00 PM in B-2
2023-12-28 Accompanied a new draft, see S2539

Entry Last Reviewed

2026-05-16
AI generated