Minnesota · House File · Ninety-Fourth Session
HF4532
Minnesota HF 4532 — Responsible Artificial Intelligence Safety and Education Act (RAISE Act)

Status ● Introduced Effective N/A Passage Likelihood L

WHAT THIS BILL REGULATES · 4 REQUIREMENT TYPES

How Is This Bill Enforced

Enforcement Authority
Attorney general enforcement and private right of action. The attorney general may bring a civil action for violations of section 325M.41. A person injured by a violation may also bring a civil action. Private plaintiffs must demonstrate injury.
Private Right of Action
private right of action.
Penalties
Attorney general may recover civil penalties up to $10,000,000 for a first violation and up to $30,000,000 for subsequent violations, plus injunctive or declaratory relief. Private plaintiffs may recover actual damages, costs, disbursements, reasonable attorney fees, and other equitable relief as determined by the court. Private action requires injury.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Minn. Stat. § 325M.39
Title

Sections 325M.40 to 325M.42 may be cited as the "Responsible Artificial IntelligenceArtificial intelligence"Artificial intelligence" means a machine-based system that: (1) is able to, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments; and (2) uses machine- and human-based inputs to perceive real and virtual environments, abstract the perceptions into models through analysis in an automated manner, and use model inference to formulate options for information or action.Minn. Stat. § 325M.40(b) Safety and Education Act" or the "RAISE Act."

This section establishes the short title of the act as the "Responsible Artificial Intelligence Safety and Education Act" or the "RAISE Act." It imposes no compliance obligations.

Minn. Stat. § 325M.40
Definitions

(a) For the purposes of sections 325M.40 to 325M.42, the following terms have the meanings given.

(b) "Artificial intelligenceArtificial intelligence"Artificial intelligence" means a machine-based system that: (1) is able to, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments; and (2) uses machine- and human-based inputs to perceive real and virtual environments, abstract the perceptions into models through analysis in an automated manner, and use model inference to formulate options for information or action.Minn. Stat. § 325M.40(b)" means a machine-based system that: (1) is able to, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments; and (2) uses machine- and human-based inputs to perceive real and virtual environments, abstract the perceptions into models through analysis in an automated manner, and use model inference to formulate options for information or action.

(c) "Artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c)" means an information system or component of an information system that implements artificial intelligenceArtificial intelligence"Artificial intelligence" means a machine-based system that: (1) is able to, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments; and (2) uses machine- and human-based inputs to perceive real and virtual environments, abstract the perceptions into models through analysis in an automated manner, and use model inference to formulate options for information or action.Minn. Stat. § 325M.40(b) technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.

(d) "Critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d)" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e)'s use, storage, or release of an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.

(e) "DeveloperDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e)" means a person that has trained at least one artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c).

(f) "Safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f)" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d); (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence modelsArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) within the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e)'s control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence modelsArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) leading to critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d), including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) (i) poses an unreasonable risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d), (ii) could evade the artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c)'s developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e)'s or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) in a manner that increases the risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d); (4) enables the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.

(g) "Safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g)" means a known incident of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d) or one of the following that provides demonstrable evidence of an increased risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d): (1) an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c)'s model weights; or (3) unauthorized use of an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c).

This section defines the key terms used throughout the RAISE Act. The definition of developer is notably broad — any person who has trained at least one AI model — with no compute threshold or revenue qualifier. Critical harm sets the threshold for the bill's safety obligations at death, serious physical injury, or mental injury of 25 or more people, or $1,000,000 in property damage, tied to CBRN weapons or autonomous criminal conduct. The safety and security protocol definition is prescriptive, requiring five enumerated elements including designated senior compliance personnel.

Minn. Stat. § 325M.41
Transparency requirements
Developer

Subd. 1(1)–(2) 1 Before deploying an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c), a developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must: (1) implement a written safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f); (2) retain an unredacted copy of the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f), including records and dates of updates or revisions, for the entire period of time an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) is deployed, plus five years;

Subd. 1(3)–(4) 2 conspicuously publish a copy of the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) with appropriate redactions, and transmit a copy of the redacted safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) to the attorney general; (4) grant the attorney general access to the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) with redactions only to the extent required by federal law, if the attorney general requests access;

Subd. 1(5) 3 record and retain information on the specific tests and test results used in any assessment of the artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) required under this section or by the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e)'s safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) that provides sufficient detail for third parties to replicate the testing procedure for the entire period of time an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) is deployed, plus five years;

Subd. 1(6) 4 implement appropriate safeguards to prevent unreasonable risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d).

Subd. 2 5 A developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must not deploy an artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) if doing so creates an unreasonable risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d).

Subd. 3(a)–(b) 6 A developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must (1) conduct an annual review of the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) required under this section to account for changes to the capabilities of the artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) and industry best practices; and (2) modify the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f). (b) If a material modification is made to the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f), the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must publish the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) in the same manner required under subdivision 1, clause (3).

Subd. 4 7 A developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must disclose each safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g) affecting the artificial intelligence modelArtificial intelligence model"Artificial intelligence model" means an information system or component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputs.Minn. Stat. § 325M.40(c) to the attorney general within 72 hours of the date the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) learns of the safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g) or within 72 hours of the date the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) learns sufficient facts to establish a reasonable belief that a safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g) has occurred. The disclosure must include: (1) the date of the safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g); (2) the reasons the safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g) qualifies as a safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g) as defined in this section; and (3) a short statement describing in plain language the safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g).

Subd. 5 8 A developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must not knowingly make false or materially misleading statements or omissions in or regarding documents produced under this section.

Section 325M.41 imposes the bill's core substantive obligations on developers. Subdivision 1 requires developers, before deploying any AI model, to implement a written safety and security protocol, retain unredacted copies and test records for the deployment period plus five years, conspicuously publish a redacted copy and transmit it to the attorney general, grant the attorney general access to unredacted versions on request, and implement safeguards against unreasonable critical-harm risk.

Subdivision 2 prohibits deployment of an AI model that creates an unreasonable risk of critical harm. Subdivision 3 requires annual review and modification of the safety and security protocol, with republication upon material modification. Subdivision 4 requires 72-hour safety incident disclosure to the attorney general. Subdivision 5 prohibits knowingly making false or materially misleading statements in or regarding documents produced under this section.

Compliance actions 8 items
1
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must, before deploying an AI model, implement a written safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) that describes reasonable protections to reduce the risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d), cybersecurity protections against unauthorized access or misuse, detailed testing procedures for evaluating critical-harm risk, and designated senior compliance personnel. DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must retain an unredacted copy of the protocol, including all update records and dates of revisions, for the entire period the AI model is deployed plus five years.
S-03.5
2
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must conspicuously publish a copy of the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) with appropriate redactions, and transmit a copy of the redacted protocol to the attorney general. If the attorney general requests access, the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must grant access to the protocol with redactions only to the extent required by federal law.
S-03.5
3
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must record and retain information on the specific tests and test results used in any assessment of the AI model required under section 325M.41 or by the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e)'s safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f). Records must provide sufficient detail for third parties to replicate the testing procedure and must be retained for the entire deployment period plus five years.
G-01.3
4
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must implement appropriate safeguards to prevent unreasonable risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d) before deploying an AI model.
S-01.1
5
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must not deploy an AI model if doing so creates an unreasonable risk of critical harmCritical harm"Critical harm" means the death, serious physical injury, or mental injury of 25 or more people, or at least $1,000,000 of damages to rights in money or property, caused or materially enabled by a developer's use, storage, or release of an artificial intelligence model that is the result of: (1) the creation or use of a chemical, biological, radiological, or nuclear weapon; or (2) conduct that with no meaningful human intervention would, if committed by a human, constitute a crime that requires intent, recklessness, or gross negligence, or the solicitation or aiding and abetting of a crime that requires intent, recklessness, or gross negligence.Minn. Stat. § 325M.40(d).
S-03.3
6
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must conduct an annual review of the safety and security protocolSafety and security protocol"Safety and security protocol" means a documented technical and organizational protocol that: (1) describes reasonable protections and procedures that, if successfully implemented, appropriately reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections for artificial intelligence models within the developer's control that, if successfully implemented, appropriately reduce the risk of unauthorized access to or misuse of the artificial intelligence models leading to critical harm, including by sophisticated actors; (3) describes in detail the testing procedure to evaluate whether the artificial intelligence model (i) poses an unreasonable risk of critical harm, (ii) could evade the artificial intelligence model's developer's or user's control, or (iii) could be misused, modified, executed with increased computational resources, combined with other software, or used to create another artificial intelligence model in a manner that increases the risk of critical harm; (4) enables the developer or third party to comply with the requirements of sections 325M.40 to 325M.42; and (5) designates senior personnel to be responsible for ensuring compliance.Minn. Stat. § 325M.40(f) to account for changes to the AI model's capabilities and industry best practices, and must modify the protocol accordingly. If a material modification is made, the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must republish the protocol with appropriate redactions and transmit a copy to the attorney general in the same manner required for the initial publication.
G-01.2
7
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must disclose each safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g) affecting the AI model to the attorney general within 72 hours of the date the developerDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) learns of the incident or learns sufficient facts to establish a reasonable belief that an incident has occurred. The disclosure must include: (1) the date of the safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g), (2) the reasons the incident qualifies as a safety incidentSafety incident"Safety incident" means a known incident of critical harm or one of the following that provides demonstrable evidence of an increased risk of critical harm: (1) an artificial intelligence model autonomously engages in behavior other than at the request of a user; (2) theft, misappropriation, malicious use, inadvertent release, unauthorized access, or escape of an artificial intelligence model's model weights; or (3) unauthorized use of an artificial intelligence model.Minn. Stat. § 325M.40(g) under the statute, and (3) a short plain-language statement describing the incident.
R-01.1
8
DevelopersDeveloper"Developer" means a person that has trained at least one artificial intelligence model.Minn. Stat. § 325M.40(e) must not knowingly make false or materially misleading statements or omissions in or regarding documents produced under section 325M.41.
Minn. Stat. § 325M.42
Enforcement; private right of action

Subd. 1 The attorney general may bring a civil action for a violation of section 325M.41 and recover, based on severity of the violation: (1) a civil penalty in an amount not exceeding $10,000,000 for a first violation and in an amount not exceeding $30,000,000 for any subsequent violation; and (2) injunctive or declaratory relief.

Subd. 2 A person injured by a violation of this section may bring a civil action to recover damages, costs, and disbursements, including reasonable attorney fees, and receive other equitable relief as determined by the court.

Section 325M.42 establishes a dual enforcement mechanism. Subdivision 1 authorizes the attorney general to bring civil actions for violations of section 325M.41, with penalties scaled by severity: up to $10,000,000 for a first violation and $30,000,000 for subsequent violations, plus injunctive or declaratory relief. Subdivision 2 creates a private right of action for any person injured by a violation, allowing recovery of damages, costs, disbursements, reasonable attorney fees, and other equitable relief.

Passage Likelihood

Low
Status Introduced
Chamber No passage
Committee No action
Majority party No
Bipartisan No
Prior session None

Legislative History

2026-03-23 Introduction and first reading, referred to Commerce Finance and Policy

Entry Last Reviewed

2026-05-20
AI generated