Washington · House Bill · 69th Legislature 2026 Regular Session
HB2667
Washington House Bill 2667 — Consumer Protections for Artificial Intelligence Systems

Status ● Introduced Effective Jul 1, 2026 Passage Likelihood M

WHAT THIS BILL REGULATES · 4 REQUIREMENT TYPES

How Is This Bill Enforced

Enforcement Authority
Attorney general enforcement only. The attorney general may bring an action in the name of the state or as parens patriae on behalf of state residents. A violation is treated as an unfair or deceptive act under the Consumer Protection Act, chapter 19.86 RCW, but no private action may be brought under RCW 19.86.090. The attorney general must provide 45 days' written notice before commencing an action. For a first violation, the developer or deployer may cure within 60 days of receiving notice. A rebuttable presumption of reasonable care applies to deployers who comply with the chapter.
Private Right of Action
No private right of action. Enforcement is exclusive to the designated authority.
Penalties
Enforcement is through the Consumer Protection Act, chapter 19.86 RCW, which provides for injunctive relief, restitution, and civil penalties available to the attorney general. The private right of action under RCW 19.86.090 is expressly excluded. Specific penalty amounts are governed by the CPA's existing penalty framework rather than this bill.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Sec. 1
Legislative findings and intent

The legislature finds that artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) is a dynamic technology that is changing the way Washingtonians live, learn, and work. Emerging artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) technologies seek to enhance information gathering and decision making, create new efficiencies throughout the economy, and advance scientific discovery. The legislature also recognizes that there are potential risks associated with the rapid development and deployment of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems, including the generation of bias and unintentional discrimination. These risks are especially profound when an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system is used to make decisions that have a material or legal impact on someone's life. The legislature recognizes Washington's role as a leader and innovator within the high-technology economy. The legislature intends to adopt an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) regulatory framework that continues to promote innovation, reduce risk, and protect residents from discriminatory actions. The legislature further recognizes that regulatory frameworks that align with national standards and specify clear compliance requirements provide developersDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) with certainty to support continued innovation while also protecting consumersConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) from unfair or unclear artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) decisions. Therefore, it is the intent of the legislature to protect Washingtonians from algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) by establishing a comprehensive risk-based approach to artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) accountability. The legislature intends to regulate deployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) under the presumption that they are acting in good faith when they comply with the provisions of this act. The legislature also intends to ensure that government agencies are transparent and accountable by requiring disclosure when consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) interactions are supported by an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system. Finally, the legislature intends to extend and expand the work of the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force to develop a framework for the adoption of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) in the workplace in a way that centers workers and protects fairness and opportunity.

Section 1 sets out the legislature's findings regarding AI's benefits and risks, and declares the intent to establish a risk-based accountability framework focused on algorithmic discrimination. It establishes a good-faith presumption for deployers who comply with the act and signals intent to require government agency AI transparency and to extend the existing AI task force's work on workplace AI adoption.

Sec. 2
Definitions

(1)–(11) "Algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1)": (a) Means the use of an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) by a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) or deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) for the sole purpose of: (A) The developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s or deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)'s testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended. (2) "Artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2)" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation. (3) "Consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3)" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4)'s access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service. (4) "ConsumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4)" means any individual who is a resident of this state. (5) "DeploysDeploys"Deploys" or "deployed" means to put a high-risk artificial intelligence system into use.Sec. 2(5)" or "deployed" means to put a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) into use. (6) "DeployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)" means any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) doing business in this state that deploysDeploys"Deploys" or "deployed" means to put a high-risk artificial intelligence system into use.Sec. 2(5) a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) in the state. (7) "DeveloperDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)" means any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) intended for use within the state. (8) "High-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8)": (a) Means any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system designed by its developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) to, when deployed, make, or is a substantial factorSubstantial factor"Substantial factor" means a factor that is: (a) Considered when making a consequential decision; (b) Likely to alter the outcome of a consequential decision; and (c) Weighed more heavily by a deployer of the applicable high-risk artificial intelligence system than any other factor contributing to the consequential decision.Sec. 2(11) in making, a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); and (b) Does not include: (i) Any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful. (9) "Intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that materially increases the risk of algorithmic discrimination.Sec. 2(9)" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that materially increases the risk of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). (10) "PersonPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10)" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. (11) "Substantial factorSubstantial factor"Substantial factor" means a factor that is: (a) Considered when making a consequential decision; (b) Likely to alter the outcome of a consequential decision; and (c) Weighed more heavily by a deployer of the applicable high-risk artificial intelligence system than any other factor contributing to the consequential decision.Sec. 2(11)" means a factor that is: (a) Considered when making a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); (b) Likely to alter the outcome of a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); and (c) Weighed more heavily by a deployer of the applicable high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) than any other factor contributing to the consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3).

Section 2 defines the key terms used throughout the chapter. Notably, the definition of high-risk artificial intelligence system contains three broad carve-outs: systems performing narrow procedural tasks, common IT infrastructure tools, and natural-language systems subject to an acceptable use policy prohibiting unlawful content. The substantial factor definition is unusually restrictive, requiring the AI factor to be weighed more heavily than any other factor in the consequential decision.

Sec. 3
Deployer duty to protect against algorithmic discrimination
Deployer

(1)(a)–(b) 1 Beginning July 1, 2027, each deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) must use industry-standard means to protect consumersConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) from any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). (b) In any enforcement action brought on or after July 1, 2027, by the attorney general pursuant to section 9 of this act, there is a rebuttable presumption that a deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) used reasonable care as required under this section if the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) complied with this chapter.

(2)(a)–(b) 2 By July 1, 2027, and at least annually thereafter, a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) or third party contracted by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) shall review the deployment of each high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) to ensure that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is not causing algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). (b) If a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) subsequently discovers that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) has caused algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1), the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), without unreasonable delay, but no later than 90 days after the date of the discovery, shall send to the attorney general, in a form and manner prescribed by the attorney general, a notice disclosing the discovery.

(3) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.

Section 3 establishes two core deployer obligations beginning July 1, 2027. First, deployers must use industry-standard means to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Second, deployers must conduct at least annual reviews of each deployed high-risk AI system to verify it is not causing algorithmic discrimination, and must notify the attorney general within 90 days of discovering discrimination. Compliance with the full chapter creates a rebuttable presumption of reasonable care. Trade secret protections apply.

Compliance actions 2 items
1
DeployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must use industry-standard means to protect consumersConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) from any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) arising from each deployed high-risk AI system. Compliance with the full chapter creates a rebuttable presumption of reasonable care in any attorney general enforcement action.
H-02.1
2
DeployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must conduct at least annual reviews — either internally or through a contracted third party — of each deployed high-risk AI system to verify the system is not causing algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). If a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) discovers that the system has caused algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1), the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must notify the attorney general within 90 days of discovery, in the form and manner prescribed by the attorney general.
H-02.8
Sec. 4
Risk management policy and program
Deployer

(1) 3 Beginning July 1, 2027, and except as provided in section 5(6) of this act, each deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) shall implement and maintain a risk management policy and program to govern the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)'s deployment of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).

(2)(a)–(c) 3 The risk management policy and program must specify and incorporate the principles, processes, and personnel that the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). The risk management policy and program must include an iterative process that is planned, implemented, and regularly and systematically reviewed and updated over the lifecycle of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8). (b) A risk management policy and program implemented and maintained pursuant to this subsection must be reasonable, considering: (i) The size and complexity of the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6); (ii) The nature and scope of the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) including, but not limited to, the intended uses of such high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (iii) The sensitivity and volume of data processed in connection with the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6); and (iv) A risk management framework that either: (A) Adheres to the guidance and standards set forth in the latest version of the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) risk management framework published by the national institute of standards and technology, ISO/IEC 42001, or another nationally or internationally recognized risk management framework for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems, if the standards are substantially equivalent to or more stringent than the requirements; or (B) Complies with any risk management framework for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems that the attorney general, in the attorney general's discretion, may designate. (c) A risk management policy and program implemented and maintained pursuant to this subsection (2) may cover multiple high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6).

(3) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.

Section 4 requires deployers to implement and maintain a risk management policy and program governing the deployment of high-risk AI systems, beginning July 1, 2027. The program must identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination and must be iterative and regularly updated. Reasonableness is calibrated to the deployer's size, the nature and scope of deployed systems, and data sensitivity. Compliance with NIST AI RMF, ISO/IEC 42001, or another nationally recognized framework — or a framework designated by the attorney general — satisfies the requirement. A single program may cover multiple systems. Small deployer exemptions under Section 6 apply.

Compliance actions 1 item
3
DeployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must implement and maintain a risk management policy and program governing the deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1), and must include an iterative process that is planned, implemented, and regularly and systematically reviewed and updated over the lifecycle of the system. The program must be reasonable considering the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)'s size and complexity, the nature and scope of deployed systems, the sensitivity and volume of data processed, and adherence to a recognized risk management framework such as the NIST AI RMF, ISO/IEC 42001, or a framework designated by the attorney general. A single program may cover multiple high-risk AI systems.
G-01.1
Sec. 5
Impact assessments
Deployer

(1)(a)–(b) 4 Except as provided in subsection (6) of this section, a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) that deploysDeploys"Deploys" or "deployed" means to put a high-risk artificial intelligence system into use.Sec. 2(5) a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) on or after July 1, 2027, or a third party contracted by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) for such purposes, shall complete an impact assessment for: (a) The high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); and (b) A deployed high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) no later than 90 days after any intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that materially increases the risk of algorithmic discrimination.Sec. 2(9) to such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is made available.

(2)(a)–(c) 4 Each impact assessment completed pursuant to this section must include, at a minimum, and to the extent reasonably known by, or available to, the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6): (a) A statement by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (b) An analysis of whether the deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) poses any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) and, if so, the nature of such algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) and the steps that have been taken to mitigate such risks; (c) A description of the following: (i) The categories of data the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) processes as inputs; (ii) The outputs the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) produces; (iii) Any metrics used to evaluate the performance and known limitations of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (iv) A description of any transparency measures taken concerning the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8), such as any measures taken to disclose to a consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) that such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is in use when such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is in use; and (v) A description of the postdeployment monitoring and user safeguards provided concerning such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8), such as the oversight process established by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) to address issues arising from deployment of such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).

(3) 4 In addition to the information required under subsection (2)(c) of this section, each impact assessment completed following an intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that materially increases the risk of algorithmic discrimination.Sec. 2(9) made to a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) on or after July 1, 2027, must include a statement disclosing the extent to which the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) was used in a manner that was consistent with, or varied from, the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s intended uses of such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).

(4)–(5) 4 A single impact assessment may address a comparable set of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6). (5) If a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or a third party contracted by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), completes an impact assessment for the purpose of complying with another applicable law or regulation, such impact assessment satisfies the requirements established in this section if such impact assessment is reasonably similar in scope and effect to the impact assessment that would otherwise be completed pursuant to this subsection.

(6) 5 A deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) shall maintain the most recently completed impact assessment for a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) as required under this section, relevant records supporting the impact assessment, and prior impact assessments, if any, for a period of at least three years following the final deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).

(7) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.

Section 5 requires deployers to complete impact assessments for each high-risk AI system deployed on or after July 1, 2027, and within 90 days of any intentional and substantial modification. Impact assessments must cover purpose and intended use, algorithmic discrimination risks and mitigation steps, data categories, outputs, performance metrics, transparency measures, and post-deployment monitoring. Assessments following a substantial modification must also disclose consistency with the developer's intended uses. A single assessment may cover comparable systems, and assessments completed under other applicable law may satisfy this requirement if reasonably similar in scope. Deployers must retain the most recent assessment, supporting records, and prior assessments for at least three years following final deployment.

Compliance actions 2 items
4
DeployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must complete an impact assessment for each high-risk AI system before deployment on or after July 1, 2027, and within 90 days after any intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that materially increases the risk of algorithmic discrimination.Sec. 2(9). Each assessment must include, to the extent reasonably known: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of known or reasonably foreseeable algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination": (a) Means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law; and (b) Does not include the following: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) risks and mitigation steps; (3) categories of input data, system outputs, performance metrics and limitations, transparency measures taken, and post-deployment monitoring and user safeguards. Assessments following a substantial modification must also disclose the extent to which the system was used consistently with or in variance from the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s intended uses. A single assessment may cover comparable systems, and an assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect.
H-02.3
5
DeployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must retain the most recently completed impact assessment, relevant supporting records, and all prior impact assessments for at least three years following the final deployment of each high-risk AI system.
H-02.10
Sec. 6
Small deployer exemption

(1)(a)–(c) The requirements in section 5 (1) through (3) of this act and section 3(2) of this act do not apply to a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) if, at the time the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) deploysDeploys"Deploys" or "deployed" means to put a high-risk artificial intelligence system into use.Sec. 2(5) a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) and at all times while the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is deployed: (a) The deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6): (i) Employs fewer than 50 full-time equivalent employees; and (ii) Does not use the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)'s own data to train the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (b) The high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8): (i) Is used for the intended uses that are disclosed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6); and (ii) Continues learning based on data derived from sources other than the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)'s own data; and (c) The deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) makes available to consumersConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) any impact assessment that: (i) The developer of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) has completed and provided to the deployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6); and (ii) Includes information that is substantially similar to the information in the impact assessment required under section 5 of this act.

(2) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.

Section 6 exempts small deployers — those with fewer than 50 full-time equivalent employees who do not use their own data to train the high-risk AI system — from the impact assessment requirements in Section 5(1)–(3) and the annual bias review requirement in Section 3(2), provided the system is used for its disclosed intended uses, continues learning from non-deployer data, and the deployer makes available to consumers any developer-completed impact assessment that is substantially similar to the Section 5 assessment. This is a conditional exemption that must be satisfied at deployment and at all times during deployment.

Sec. 7
Consumer notification before consequential decisions
Deployer

(1)–(2) 6 Beginning July 1, 2026, each time a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) deploysDeploys"Deploys" or "deployed" means to put a high-risk artificial intelligence system into use.Sec. 2(5) a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) to make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that is: (a) Considered when making a consequential decision; (b) Likely to alter the outcome of a consequential decision; and (c) Weighed more heavily by a deployer of the applicable high-risk artificial intelligence system than any other factor contributing to the consequential decision.Sec. 2(11) in making, a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) concerning a consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4), the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) shall: (1) Notify the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) that the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) has deployed a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) to make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that is: (a) Considered when making a consequential decision; (b) Likely to alter the outcome of a consequential decision; and (c) Weighed more heavily by a deployer of the applicable high-risk artificial intelligence system than any other factor contributing to the consequential decision.Sec. 2(11) in making, a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) before the decision is made; and (2) Provide to the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) a statement disclosing: (a) The purpose of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) and the nature of the consequential decisionsConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); (b) The contact information for the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6); and (c) A description, in plain language, of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).

Section 7 requires deployers, beginning July 1, 2026, to notify consumers before a consequential decision is made using a high-risk AI system. The notification must disclose the system's purpose, the nature of the consequential decisions, the deployer's contact information, and a plain-language description of the system. This is the earliest operative date in the bill — one year before most other obligations take effect.

Compliance actions 1 item
6
DeployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must notify the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) before any consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) is made using a high-risk AI system that the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) has deployed such a system to make or substantially factor in the decision. The deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) must also provide a statement disclosing: (1) the purpose of the system and the nature of the consequential decisionsConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer's access to: (a) Pardon, parole, probation, or release; (b) Education enrollment or opportunity; (c) Employment; (d) A financial or lending service; (e) An essential government service; (f) Health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); (2) the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)'s contact information; and (3) a plain-language description of the system.
H-01.3
Sec. 8
Exemptions and savings clauses

(1)(a)–(d) Nothing in this chapter may be construed to: (a) Restrict a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s, deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6)'s, or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10)'s ability to: (i) Comply with federal, state, or municipal law; (ii) Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, municipal, or other governmental authorities; (iii) Cooperate with law enforcement agencies concerning conduct or activity that the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) reasonably and in good faith believes may violate federal, state, or municipal law; (iv) Investigate, establish, exercise, prepare for, or defend legal claims; (v) Take immediate steps to protect an interest that is essential for the life or physical safety of a consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) or another individual; (vi) Engage in public or peer-reviewed scientific or statistical research in the public interest that adheres to all other applicable ethics and privacy laws and is conducted in accordance with 45 C.F.R. Part 46, as amended from time to time, or relevant requirements established by the federal food and drug administration; (vii) Conduct any research, testing, or development activities regarding any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system or model, other than testing conducted under real world conditions, before such artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system or model is placed on the market, deployed, or put into service, as applicable; (viii) Effectuate a product recall; (ix) Identify and repair technical errors that impair existing or intended functionality; or (x) Assist another developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) with any of the obligations imposed under this chapter; (b) Impose any obligation on a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) that adversely affects the rights or freedoms of any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) including, but not limited to, the rights of any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution; (c) Apply to any developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10): (i) Insofar as such developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) develops, deploysDeploys"Deploys" or "deployed" means to put a high-risk artificial intelligence system into use.Sec. 2(5), puts into service, or intentionally and substantially modifies, as applicable, a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) that has been approved, authorized, certified, cleared, or granted: (A) By a federal agency, such as the federal food and drug administration or the federal aviation administration, acting within the scope of such federal agency's authority; or (B) In compliance with standards established by any federal agency including, but not limited to, standards established by the federal office of the national coordinator for health information technology; (ii) Conducting any research to support an application for approval or certification from any federal agency including, but not limited to, the federal aviation administration, the federal communications commission, or the federal food and drug administration, or otherwise subject to review by such federal agency; (iii) Performing work under, or in connection with, a contract with the United States department of commerce, the United States department of defense, or the national aeronautics and space administration, unless such developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) is performing such work on a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) that is used to make, or as a substantial factorSubstantial factor"Substantial factor" means a factor that is: (a) Considered when making a consequential decision; (b) Likely to alter the outcome of a consequential decision; and (c) Weighed more heavily by a deployer of the applicable high-risk artificial intelligence system than any other factor contributing to the consequential decision.Sec. 2(11) in making, a decision concerning employment or housing; or (iv) That is a covered entity within the meaning of the health insurance portability and accountability act of 1996, P.L. 104-191, and the regulations promulgated thereunder, as both may be amended from time to time, and providing health care recommendations that: (A) Are generated by an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system; (B) Require a health care provider to take action to implement such recommendations; and (C) Are not considered to be high risk; or (d) Apply to any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that is acquired by or for the federal government or any federal agency or department including, but not limited to, the United States department of commerce, the United States department of defense, or the national aeronautics and space administration, unless such artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system is a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system": (a) Means any artificial intelligence system designed by its developer to, when deployed, make, or is a substantial factor in making, a consequential decision; and (b) Does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) that is used to make, or as a substantial factorSubstantial factor"Substantial factor" means a factor that is: (a) Considered when making a consequential decision; (b) Likely to alter the outcome of a consequential decision; and (c) Weighed more heavily by a deployer of the applicable high-risk artificial intelligence system than any other factor contributing to the consequential decision.Sec. 2(11) in making, a decision concerning employment or housing.

(2) If a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) engages in any action pursuant to an exemption set forth in this section, the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) bears the burden of demonstrating that such action qualifies for such exemption.

Section 8 establishes broad exemptions and savings clauses. The chapter does not restrict compliance with other laws, cooperation with law enforcement, legal defense activities, public research, product recalls, technical error repair, pre-market R&D, or any obligation that would adversely affect First Amendment rights. The chapter also does not apply to AI systems approved by federal agencies (FDA, FAA), systems used under federal defense or commerce contracts (unless for employment or housing decisions), HIPAA covered entities providing AI health care recommendations where a provider must act, or AI acquired by federal agencies (unless for employment or housing). Parties claiming an exemption bear the burden of proof.

Sec. 9
Enforcement

(1)(a)–(b) The attorney general may bring an action in the name of the state, or as parens patriae on behalf of personsPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is an unfair or deceptive act in trade or commerce for the purpose of applying the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) protection act, chapter 19.86 RCW. An action to enforce this chapter may not be brought under RCW 19.86.090. (b) The office of the attorney general, before commencing an action under the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) protection act, chapter 19.86 RCW, must provide 45 days' written notice to a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) or developer of the alleged violation of this chapter. For the first violation, the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) or deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) may cure the noticed violation within 60 days of receiving the written notice.

(2) Nothing in this chapter may be construed to limit or otherwise affect the obligations of developersDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) and deployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system in the state.Sec. 2(6) under applicable laws, rules, or regulations relating to data privacy or security.

Section 9 establishes exclusive attorney general enforcement. Violations are treated as unfair or deceptive acts under the Consumer Protection Act (chapter 19.86 RCW), but private suits under RCW 19.86.090 are expressly barred. The AG must provide 45 days' written notice before commencing an action. For a first violation, the developer or deployer has 60 days to cure. The section also preserves obligations under existing data privacy and security laws.

Sec. 10
Government agency AI disclosure
Government

(1)–(3) 7 A government agency that makes available an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system intended to interact with consumersConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) must disclose to each consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4), before or at the time of interaction, that the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) is interacting with an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system. The disclosure must be: (a) Clear and conspicuously posted; (b) Written in plain language; and (c) May not use a dark pattern. (2) The disclosure may be provided by using a hyperlink to direct a consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) to a separate web page. (3) A personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity.Sec. 2(10) is required to make the disclosure under subsection (1) of this section regardless of whether it would be obvious to a reasonable consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) that the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) is interacting with an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system.

Section 10 requires government agencies that deploy consumer-facing AI systems to disclose to each consumer, before or at the time of interaction, that the consumer is interacting with an AI system. The disclosure must be clear and conspicuous, written in plain language, and may not use a dark pattern. Notably, the disclosure obligation applies unconditionally — regardless of whether it would be obvious to a reasonable consumer that AI is in use. The disclosure may be provided via hyperlink. This section is codified in Title 42 RCW (separate from the private-sector obligations in Title 19).

Compliance actions 1 item
7
Government agencies that make available an AI system intended to interact with consumersConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) must disclose to each consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4), before or at the time of interaction, that the consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) is interacting with an AI system. The disclosure must be clear and conspicuously posted, written in plain language, and must not use a dark pattern. The disclosure may be provided via hyperlink. The disclosure obligation applies unconditionally regardless of whether it would be obvious to a reasonable consumerConsumer"Consumer" means any individual who is a resident of this state.Sec. 2(4) that AI is in use.
T-01.1
Sec. 11
Codification — Title 19 RCW

Sections 1 through 9 of this act constitute a new chapter in Title 19 RCW.

Section 11 is a codification directive placing Sections 1 through 9 in a new chapter in Title 19 RCW (Consumer Protection). No obligations are created.

Sec. 12
Codification — Title 42 RCW

Section 10 of this act constitutes a new chapter in Title 42 RCW.

Section 12 is a codification directive placing Section 10 in a new chapter in Title 42 RCW (Public Officers and Agencies). No obligations are created.

Sec. 13
AI Task Force extension (amending 2024 c 163 s 2)

2024 c 163 s 2 (uncodified) is amended to read as follows: (1) A task force to assess current uses and trends and make recommendations to the legislature regarding guidelines and potential legislation for the use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems is established. ... (5) ... a final report by July 1, 2027. Meeting summaries must be posted to the website of the attorney general's office within 30 days of any meeting by the task force. ... (9) This section expires June 30, 2028.

Section 13 amends the 2024 AI Task Force legislation to remove the appropriation prerequisite, extend the task force's final report deadline from July 1, 2026 to July 1, 2027, and extend the sunset date from June 30, 2027 to June 30, 2028. The task force composition, mandate, and subcommittee structure are otherwise unchanged. This section creates no new private-sector compliance obligations.

Sec. 14
AI Workplace Advisory Group

The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group is established for the purpose of developing artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) policy related to the workplace. The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group shall report to the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force established in section 2, chapter 163, Laws of 2024 as prescribed in subsection (4) of this section. (2) The attorney general shall appoint the following members to the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group: (a) Two members representing different statewide labor organizations; (b) Two members representing the business community; (c) One member representing public sector employees; (d) One member representing private sector employees; (e) One member representing higher education institutions with expertise in artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) and the workforce; (f) One member with expertise in ethics and artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2); and (g) Other members as deemed appropriate by the attorney general. (3) The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group is responsible for developing guiding principles for the use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) in the workplace. At a minimum, the guiding principles must prioritize the responsible and ethical use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) tools in ways that protect an individual's privacy and minimize the risk of bias in the workplace. (4) The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group shall deliver an interim report on the development of guiding principles for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) in the workplace to the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force by December 1, 2026, and a final report by March 1, 2027. The final report must be included in the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force's final report as required by section 2(5), chapter 163, Laws of 2024. (5) This section expires June 30, 2028.

Section 14 establishes an AI Workplace Advisory Group, appointed by the attorney general, to develop guiding principles for workplace AI use. The group must deliver an interim report by December 1, 2026, and a final report by March 1, 2027, which must be incorporated into the AI Task Force's final report. The section expires June 30, 2028. This section creates no private-sector compliance obligations — it is a governmental study body.

Passage Likelihood

Medium
Status Introduced
Chamber No passage
Committee No action
Majority party Yes
Bipartisan Yes
Prior session None

Legislative History

2026-01-26 First reading, referred to Technology, Economic Development, & Veterans.

Entry Last Reviewed

2026-05-20
AI generated