WHAT THIS BILL REGULATES · 4 REQUIREMENT TYPES
How Is This Bill Enforced
Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.
The legislature finds that artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) is a dynamic technology that is changing the way Washingtonians live, learn, and work. Emerging artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) technologies seek to enhance information gathering and decision making, create new efficiencies throughout the economy, and advance scientific discovery. The legislature also recognizes that there are potential risks associated with the rapid development and deployment of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems, including the generation of bias and unintentional discrimination. These risks are especially profound when an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system is used to make decisions that have a material or legal impact on someone's life. The legislature recognizes Washington's role as a leader and innovator within the high-technology economy. The legislature intends to adopt an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) regulatory framework that continues to promote innovation, reduce risk, and protect residents from discriminatory actions. The legislature further recognizes that regulatory frameworks that align with national standards and specify clear compliance requirements provide developersDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) with certainty to support continued innovation while also protecting consumersConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) from unfair or unclear artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) decisions. Therefore, it is the intent of the legislature to protect Washingtonians from algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) by establishing a comprehensive risk-based approach to artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) accountability. The legislature intends to regulate deployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) under the presumption that they are acting in good faith when they comply with the provisions of this act. The legislature also intends to ensure that government agencies are transparent and accountable by requiring disclosure when consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) interactions are supported by an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system. Finally, the legislature intends to extend and expand the work of the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force to develop a framework for the adoption of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) in the workplace in a way that centers workers and protects fairness and opportunity.
Section 1 sets out the legislature's findings regarding AI's dynamic impact on Washington residents and the risks of bias and discrimination in high-stakes AI decisions. It declares intent to establish a comprehensive risk-based framework, regulate deployers under a good-faith presumption, require government AI disclosure, and extend the AI task force's work on workplace AI policy.
(1)–(12) The definitions in this section apply throughout this chapter unless the context clearly requires otherwise. (1)(a) "Algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1)" means the use of an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. (b) "Algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1)" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) by a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) or deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) for the sole purpose of: (A) The developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s or deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6)'s testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended. (2) "Artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2)" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation. (3) "Consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3)" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service. (4)(a) "ConsumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4)" means a personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) who is a resident of this state and is acting only in an individual or household context. (b) "ConsumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4)" does not include a personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) acting in a commercial or employment context. (5) "Deploys" or "deployed" means to put a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) into use. (6) "DeployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6)" means any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) doing business in this state that deploys a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) to make a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) in the state. (7) "DeveloperDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)" means any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) intended for use within the state. (8)(a) "High-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8)" means any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that is specifically intended to autonomously make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that: (i) Uses the principal basis for making a consequential decision; (ii) Is capable of altering the outcome of a consequential decision; and (iii) Is generated by an artificial intelligence system. "Substantial factor" does not include any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as the principal basis to make a consequential decision concerning the consumer.Sec. 2(12) in making, a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) without meaningful human considerationMeaningful human consideration"Meaningful human consideration" means review or oversight by one or more individuals who have training or expertise in the decision being made and who have the authority to alter the decision under review.Sec. 2(10). (b) "High-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8)" does not include: (i) Any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful. (9)(a) "Intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to: (i) An artificial intelligence system that at the time when the change is implemented and any time thereafter, results in any new material risk of algorithmic discrimination; or (ii) A general purpose artificial intelligence model that affects compliance of the general purpose artificial intelligence model, materially changes the purpose of the general purpose artificial intelligence model, or results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" does not include: (i) Any customization made by deployers that is based on legitimate nondiscriminatory business justifications, is within the scope and purpose of the artificial intelligence tool, and that does not result in a material change to the risks of algorithmic discrimination; or (ii) Any change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if the high-risk artificial intelligence system continues to learn after such high-risk artificial intelligence system is offered, sold, leased, licensed, given, or otherwise made available to a deployer, or deployed, and such change is made to the high-risk artificial intelligence system as a result of learning after the system is offered, sold, leased, licensed, given, or otherwise made available to the deployer or deployed and predetermined by the deployer or a third party contracted by the deployer and included within the initial impact assessment of such high-risk artificial intelligence system as required in section 6 of this act.Sec. 2(9)" or "intentionally and substantially modifies" means a deliberate change made to: (i) An artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that at the time when the change is implemented and any time thereafter, results in any new material risk of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1); or (ii) A general purpose artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) model that affects compliance of the general purpose artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) model, materially changes the purpose of the general purpose artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) model, or results in any new reasonably foreseeable risk of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). (b) "Intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to: (i) An artificial intelligence system that at the time when the change is implemented and any time thereafter, results in any new material risk of algorithmic discrimination; or (ii) A general purpose artificial intelligence model that affects compliance of the general purpose artificial intelligence model, materially changes the purpose of the general purpose artificial intelligence model, or results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" does not include: (i) Any customization made by deployers that is based on legitimate nondiscriminatory business justifications, is within the scope and purpose of the artificial intelligence tool, and that does not result in a material change to the risks of algorithmic discrimination; or (ii) Any change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if the high-risk artificial intelligence system continues to learn after such high-risk artificial intelligence system is offered, sold, leased, licensed, given, or otherwise made available to a deployer, or deployed, and such change is made to the high-risk artificial intelligence system as a result of learning after the system is offered, sold, leased, licensed, given, or otherwise made available to the deployer or deployed and predetermined by the deployer or a third party contracted by the deployer and included within the initial impact assessment of such high-risk artificial intelligence system as required in section 6 of this act.Sec. 2(9)" does not include: (i) Any customization made by deployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) that is based on legitimate nondiscriminatory business justifications, is within the scope and purpose of the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) tool, and that does not result in a material change to the risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1); or (ii) Any change made to a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8), or the performance of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8), if the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) continues to learn after such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is offered, sold, leased, licensed, given, or otherwise made available to a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or deployed, and such change is made to the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) as a result of learning after the system is offered, sold, leased, licensed, given, or otherwise made available to the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) or deployed and predetermined by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) or a third party contracted by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) and included within the initial impact assessment of such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) as required in section 6 of this act. (10) "Meaningful human considerationMeaningful human consideration"Meaningful human consideration" means review or oversight by one or more individuals who have training or expertise in the decision being made and who have the authority to alter the decision under review.Sec. 2(10)" means review or oversight by one or more individuals who have training or expertise in the decision being made and who have the authority to alter the decision under review. (11)(a) "PersonPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11)" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. (b) "PersonPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11)" does not include any government or political subdivision. (12)(a) "Substantial factorSubstantial factor"Substantial factor" means a factor that: (i) Uses the principal basis for making a consequential decision; (ii) Is capable of altering the outcome of a consequential decision; and (iii) Is generated by an artificial intelligence system. "Substantial factor" does not include any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as the principal basis to make a consequential decision concerning the consumer.Sec. 2(12)" means a factor that: (i) Uses the principal basis for making a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); (ii) Is capable of altering the outcome of a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); and (iii) Is generated by an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system. (b) "Substantial factorSubstantial factor"Substantial factor" means a factor that: (i) Uses the principal basis for making a consequential decision; (ii) Is capable of altering the outcome of a consequential decision; and (iii) Is generated by an artificial intelligence system. "Substantial factor" does not include any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as the principal basis to make a consequential decision concerning the consumer.Sec. 2(12)" does not include any use of an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system to generate any content, decision, prediction, or recommendation concerning a consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) that is used as the principal basis to make a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) concerning the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4).
Section 2 establishes the definitions used throughout the new Title 19 chapter. Key terms include algorithmic discrimination (tied to chapter 49.60 RCW and federal law), consequential decision (covering nine enumerated domains), high-risk AI system (with significant carve-outs for narrow procedural tasks, cybersecurity tools, and natural language systems subject to acceptable use policies), and meaningful human consideration (requiring trained reviewers with override authority).
The high-risk AI carve-out for natural language systems subject to acceptable use policies is notably broad — it could exclude many general-purpose chatbots and LLM-based tools from the high-risk definition entirely.
(1)(a)–(b) 1 Beginning July 1, 2027, each deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) must use industry-standard means to protect consumersConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) from any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). (b) In any enforcement action brought on or after July 1, 2027, by the attorney general pursuant to section 10 of this act, there is a rebuttable presumption that a deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) used reasonable care as required under this section if the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) complied with this chapter.
(2)(a)–(b) 2 By July 1, 2027, and at least annually thereafter, a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) or third party contracted by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) shall review the deployment of each high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) to ensure that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is not causing algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). (b) If a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) subsequently discovers that the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) has caused algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1), the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), without unreasonable delay, but no later than 90 days after the date of the discovery, shall send to the attorney general, in a form and manner prescribed by the attorney general, a notice disclosing the discovery.
(3) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.
Section 3 imposes two core obligations on deployers of high-risk AI systems beginning July 1, 2027. First, deployers must use industry-standard means to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with the chapter creates a rebuttable presumption of reasonable care in attorney general enforcement actions. Second, deployers must conduct at least annual reviews to verify their high-risk AI systems are not causing algorithmic discrimination, and must notify the attorney general within 90 days of discovering discrimination.
(1)–(2) 3 Beginning July 1, 2027, and except as provided in section 6(6) of this act, each deployer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) shall implement and maintain a risk management policy and program to govern the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6)'s deployment of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8). (2)(a) The risk management policy and program must specify and incorporate the principles, processes, and personnel that the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). The risk management policy and program must include an iterative process that is planned, implemented, and regularly and systematically reviewed and updated over the lifecycle of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8). (b) A risk management policy and program implemented and maintained pursuant to this subsection must be reasonable, considering: (i) The size and complexity of the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6); (ii) The nature and scope of the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) including, but not limited to, the intended uses of such high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (iii) The sensitivity and volume of data processed in connection with the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6); and (iv) A risk management framework that either: (A) Adheres to the guidance and standards set forth in the latest version of the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) risk management framework published by the national institute of standards and technology, ISO/IEC 42001, or another nationally or internationally recognized risk management framework for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems, if the standards are substantially equivalent to or more stringent than the requirements; or (B) Complies with any risk management framework for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems that the attorney general, in the attorney general's discretion, may designate. (c) A risk management policy and program implemented and maintained pursuant to this subsection (2) may cover multiple high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6).
(3) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.
Section 4 requires each deployer to implement and maintain a risk management policy and program governing deployment of high-risk AI systems, beginning July 1, 2027. The program must identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must be iterative, regularly reviewed, and updated over the system's lifecycle. The program's reasonableness is assessed against the deployer's size and complexity, the scope and sensitivity of data processed, and adherence to a recognized risk management framework — the NIST AI RMF, ISO/IEC 42001, or an equivalent framework designated by the attorney general.
(1)–(2) 4 Beginning July 1, 2027, and except as provided in section 6(6) of this act, each developer of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) shall implement and maintain a risk management policy and program to govern the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s deployment of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8). (2)(a) The risk management policy and program must specify and incorporate the principles, processes, and personnel that the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1). The risk management policy and program must include an iterative process that is planned, implemented, and regularly and systematically reviewed and updated over the life cycle of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8). (b) A risk management policy and program implemented and maintained pursuant to this subsection must be reasonable, considering: (i) The size and complexity of the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7); (ii) The nature and scope of the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) including, but not limited to, the intended uses of such high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (iii) The sensitivity and volume of data processed in connection with the high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7); and (iv) A risk management framework that either: (A) Adheres to the guidance and standards set forth in the latest version of the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) risk management framework published by the national institute of standards and technology, ISO/IEC 42001, or another nationally or internationally recognized risk management framework for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems, if the standards are substantially equivalent to or more stringent than the requirements; or (B) Complies with any risk management framework for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems that the attorney general, in the attorney general's discretion, may designate. (c) A risk management policy and program implemented and maintained pursuant to this subsection (2) may cover multiple high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6).
(3) A developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) that also serves as a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) for any high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) may not be required to generate the documentation required by this section unless such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is provided to an unaffiliated entity acting as a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) or as otherwise required by law.
(4) Nothing in this section may be construed to require a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) to disclose any trade secret, or other confidential or proprietary information.
(5) This section does not apply to a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) with fewer than 50 full-time equivalent employees.
Section 5 mirrors Section 4's risk management program requirements but applies to developers. The program must cover the same elements — identification, documentation, and mitigation of algorithmic discrimination risks with iterative review. The section includes a small-developer exemption (fewer than 50 FTEs) and an exemption for developers who also serve as deployers unless the system is provided to an unaffiliated deployer.
(1)–(3) 5 Except as provided in subsection (6) of this section, a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) that deploys a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) on or after July 1, 2027, or a third party contracted by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) for such purposes, shall complete an impact assessment for: (a) The high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); and (b) A deployed high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) no later than 90 days after any intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to: (i) An artificial intelligence system that at the time when the change is implemented and any time thereafter, results in any new material risk of algorithmic discrimination; or (ii) A general purpose artificial intelligence model that affects compliance of the general purpose artificial intelligence model, materially changes the purpose of the general purpose artificial intelligence model, or results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" does not include: (i) Any customization made by deployers that is based on legitimate nondiscriminatory business justifications, is within the scope and purpose of the artificial intelligence tool, and that does not result in a material change to the risks of algorithmic discrimination; or (ii) Any change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if the high-risk artificial intelligence system continues to learn after such high-risk artificial intelligence system is offered, sold, leased, licensed, given, or otherwise made available to a deployer, or deployed, and such change is made to the high-risk artificial intelligence system as a result of learning after the system is offered, sold, leased, licensed, given, or otherwise made available to the deployer or deployed and predetermined by the deployer or a third party contracted by the deployer and included within the initial impact assessment of such high-risk artificial intelligence system as required in section 6 of this act.Sec. 2(9) to such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is made available. (2) Each impact assessment completed pursuant to this section must include, at a minimum, and to the extent reasonably known by, or available to, the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6): (a) A statement by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (b) An analysis of whether the deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) poses any known or reasonably foreseeable risks of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) and, if so, the nature of such algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) and the steps that have been taken to mitigate such risks; (c) A description of the following: (i) The categories of data the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) processes as inputs; (ii) The outputs the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) produces; (iii) Any metrics used to evaluate the performance and known limitations of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (iv) A description of any transparency measures taken concerning the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8), such as any measures taken to disclose to a consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) that such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is in use when such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is in use; and (v) A description of the postdeployment monitoring and user safeguards provided concerning such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8), such as the oversight process established by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) to address issues arising from deployment of such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8). (3) In addition to the information required under subsection (2)(c) of this section, each impact assessment completed following an intentional and substantial modificationIntentional and substantial modification"Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to: (i) An artificial intelligence system that at the time when the change is implemented and any time thereafter, results in any new material risk of algorithmic discrimination; or (ii) A general purpose artificial intelligence model that affects compliance of the general purpose artificial intelligence model, materially changes the purpose of the general purpose artificial intelligence model, or results in any new reasonably foreseeable risk of algorithmic discrimination. "Intentional and substantial modification" does not include: (i) Any customization made by deployers that is based on legitimate nondiscriminatory business justifications, is within the scope and purpose of the artificial intelligence tool, and that does not result in a material change to the risks of algorithmic discrimination; or (ii) Any change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if the high-risk artificial intelligence system continues to learn after such high-risk artificial intelligence system is offered, sold, leased, licensed, given, or otherwise made available to a deployer, or deployed, and such change is made to the high-risk artificial intelligence system as a result of learning after the system is offered, sold, leased, licensed, given, or otherwise made available to the deployer or deployed and predetermined by the deployer or a third party contracted by the deployer and included within the initial impact assessment of such high-risk artificial intelligence system as required in section 6 of this act.Sec. 2(9) made to a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) on or after July 1, 2027, must include a statement disclosing the extent to which the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) was used in a manner that was consistent with, or varied from, the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s intended uses of such high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).
(4)–(5) 5 A single impact assessment may address a comparable set of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) deployed by a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6). (5) If a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or a third party contracted by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), completes an impact assessment for the purpose of complying with another applicable law or regulation, such impact assessment satisfies the requirements established in this section if such impact assessment is reasonably similar in scope and effect to the impact assessment that would otherwise be completed pursuant to this subsection.
(6) 6 A deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) shall maintain the most recently completed impact assessment for a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) as required under this section, relevant records supporting the impact assessment, and prior impact assessments, if any, for a period of at least three years following the final deployment of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).
(7) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.
Section 6 requires deployers to complete impact assessments for each high-risk AI system deployed on or after July 1, 2027, and within 90 days of any intentional and substantial modification. The impact assessment must cover the system's purpose and intended use cases, algorithmic discrimination risk analysis and mitigation steps, data categories, outputs, performance metrics, transparency measures, and post-deployment monitoring. Additional content is required when the assessment follows a substantial modification. Impact assessments may cover comparable sets of systems and may satisfy equivalent obligations under other laws. All impact assessments and supporting records must be retained for at least three years following final deployment.
(1)(a)–(c) The requirements in sections 4 and 6 of this act do not apply to a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) if, at the time the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) deploys a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) and at all times while the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) is deployed: (a) The deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6): (i) Employs fewer than 50 full-time equivalent employees; and (ii) Does not use the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6)'s own data to train the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (b) The high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8): (i) Is used for the intended uses that are disclosed by the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6); and (ii) Continues learning based on data derived from sources other than the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6)'s own data; and (c) The deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) makes available to consumersConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) any impact assessment that: (i) The developer of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) has completed and provided to the deployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6); and (ii) Includes information that is substantially similar to the information in the impact assessment required under section 6 of this act.
(2) Nothing in this section may be construed to require a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) to disclose any trade secret, or other confidential or proprietary information.
Section 7 exempts small deployers from the risk management program (Sec. 4) and impact assessment (Sec. 6) requirements, provided three conditions are met continuously: the deployer employs fewer than 50 FTEs and does not use its own data to train the system; the system is used for disclosed intended uses and continues learning from non-deployer data only; and the deployer makes available to consumers any impact assessment the developer has completed and provided. This is a significant compliance relief provision for small businesses using third-party AI systems.
(1)–(2) 7 Beginning July 1, 2026, each time a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) deploys a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) to make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that: (i) Uses the principal basis for making a consequential decision; (ii) Is capable of altering the outcome of a consequential decision; and (iii) Is generated by an artificial intelligence system. "Substantial factor" does not include any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as the principal basis to make a consequential decision concerning the consumer.Sec. 2(12) in making, a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) concerning a consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4), the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) shall: (1) Notify the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) that the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) has deployed an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system to make, or be a substantial factorSubstantial factor"Substantial factor" means a factor that: (i) Uses the principal basis for making a consequential decision; (ii) Is capable of altering the outcome of a consequential decision; and (iii) Is generated by an artificial intelligence system. "Substantial factor" does not include any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as the principal basis to make a consequential decision concerning the consumer.Sec. 2(12) in making, a consequential decisionConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3) before the decision is made; and (2) Provide to the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) a statement disclosing: (a) The purpose of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) and the nature of the consequential decisionsConsequential decision"Consequential decision" means any decision that has a material legal or similarly significant effect on the provision or denial of any consumer to: (a) Pardon, parole, probation, or any other release from incarceration or court supervision; (b) Education enrollment or an education opportunity; (c) Access to employment; (d) A financial or lending service; (e) An essential government service; (f) Access to health care services; (g) Housing; (h) Insurance; or (i) Legal service.Sec. 2(3); (b) The contact information for the deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6); and (c) A description, in plain language, of the high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8).
Section 8 imposes the bill's earliest operative obligation, effective July 1, 2026. Each time a deployer uses a high-risk AI system to make or substantially factor into a consequential decision concerning a consumer, the deployer must notify the consumer before the decision is made and provide a disclosure statement covering the system's purpose, the nature of the consequential decision, the deployer's contact information, and a plain-language description of the system.
(1)(a)–(g) Nothing in this chapter may be construed to: (a) Restrict a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7)'s, deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6)'s, or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11)'s ability to: (i) Comply with federal, state, or municipal law; (ii) Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, municipal, or other governmental authorities; (iii) Cooperate with law enforcement agencies concerning conduct or activity that the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) reasonably and in good faith believes may violate federal, state, or municipal law; (iv) Investigate, establish, exercise, prepare for, or defend legal claims; (v) Take immediate steps to protect an interest that is essential for the life or physical safety of a consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) or another individual; (vi) Engage in public or peer-reviewed scientific or statistical research in the public interest that adheres to all other applicable ethics and privacy laws and is conducted in accordance with 45 C.F.R. Part 46, as amended from time to time, or relevant requirements established by the federal food and drug administration; (vii) Conduct any research, testing, or development activities regarding any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system or model, other than testing conducted under real world conditions, before such artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system or model is placed on the market, deployed, or put into service, as applicable; (viii) Effectuate a product recall; (ix) Identify and repair technical errors that impair existing or intended functionality; or (x) Assist another developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) with any of the obligations imposed under this chapter; (b) Impose any obligation on a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) that adversely affects the rights or freedoms of any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) including, but not limited to, the rights of any personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution; (c) Apply to any developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11): (i) Insofar as such developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) develops, deploys, puts into service, or intentionally and substantially modifies, as applicable, a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) that has been approved, authorized, certified, cleared, or granted: (A) By a federal agency, such as the federal food and drug administration or the federal aviation administration, acting within the scope of such federal agency's authority; or (B) In compliance with standards established by any federal agency including, but not limited to, standards established by the federal office of the national coordinator for health information technology; (ii) Conducting any research to support an application for approval or certification from any federal agency including, but not limited to, the federal aviation administration, the federal communications commission, or the federal food and drug administration, or otherwise subject to review by such federal agency; (iii) Performing work under, or in connection with, a contract with the United States department of commerce, the United States department of defense, or the national aeronautics and space administration, unless such developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) is performing such work on a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) that is used to make, or as a substantial factorSubstantial factor"Substantial factor" means a factor that: (i) Uses the principal basis for making a consequential decision; (ii) Is capable of altering the outcome of a consequential decision; and (iii) Is generated by an artificial intelligence system. "Substantial factor" does not include any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as the principal basis to make a consequential decision concerning the consumer.Sec. 2(12) in making, a decision concerning employment or housing; or (iv) That is a covered entity or business associate within the meaning of the health insurance portability and accountability act of 1996, P.L. 104-191, and the regulations promulgated thereunder, as both may be amended from time to time, and is: (A) Providing health care recommendations that are generated by an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system and require a health care provider to take action to implement such recommendations; or (B) Utilizing an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system for health care operations, performance, and quality improvement purposes including, but not limited to, administrative, quality measurement, security, patient access, scheduling, referral management, transfer coordination, care coordination, bed management, or eligibility screening; (d) Apply to any artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that is acquired by or for the federal government or any federal agency or department including, but not limited to, the United States department of commerce, the United States department of defense, or the national aeronautics and space administration, unless such artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system is a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) that is used to make, or as a substantial factorSubstantial factor"Substantial factor" means a factor that: (i) Uses the principal basis for making a consequential decision; (ii) Is capable of altering the outcome of a consequential decision; and (iii) Is generated by an artificial intelligence system. "Substantial factor" does not include any use of an artificial intelligence system to generate any content, decision, prediction, or recommendation concerning a consumer that is used as the principal basis to make a consequential decision concerning the consumer.Sec. 2(12) in making, a decision concerning employment or housing; (e) Apply to any insurer, or any high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) developed by or for or deployed by an insurer for use in the business of insurance, if such insurer is regulated and supervised by the office of the insurance commissioner or a comparable federal regulating body and: (i) Is subject to examination by such entity under any existing statutes, rules, or regulations pertaining to unfair trade practices and unfair discrimination prohibited under RCW 48.30.300, or published guidance or regulations that apply to the use of high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); and (ii) Such guidance or regulations aid in the prevention and mitigation of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) caused by the use of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8) or any risk of algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) that is reasonably foreseeable as a result of the use of a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (f) Delegate existing regulatory oversight of the business of insurance to any department or agency other than the office of the insurance commissioner; or (g) Apply to any financial institution. For purposes of this subsection, "financial institution" includes the following: (i) A bank, foreign bank, national bank, mutual savings bank, or savings association, as defined in RCW 30A.04.010; (ii) A credit union, out-of-state credit union, or federal credit union as defined in RCW 31.12.005; (iii) A mortgage lender as defined in RCW 43.180.020; or (iv) Any subsidiary, affiliate, or service provider of an entity listed in (g)(i) through (iii) of this subsection.
(2) If a developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) engages in any action pursuant to an exemption set forth in this section, the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7), deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6), or other personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) bears the burden of demonstrating that such action qualifies for such exemption.
Section 9 establishes broad exemptions from the chapter's requirements. The chapter does not restrict compliance with law, cooperation with law enforcement, legal defense, life-safety actions, peer-reviewed research, pre-market R&D, product recalls, or bug fixes. It preserves First Amendment rights. It exempts AI systems approved by federal agencies (FDA, FAA, etc.), federal contractor work (except employment/housing decisions), HIPAA-covered entities providing AI-generated health care recommendations or using AI for health care operations, AI acquired for federal agencies, insurers regulated by the Office of the Insurance Commissioner, and financial institutions. The burden of demonstrating eligibility for an exemption falls on the developer, deployer, or other person claiming it.
(1)(a)–(c) The attorney general may bring an action in the name of the state, or as parens patriae on behalf of personsPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is an unfair or deceptive act in trade or commerce for the purpose of applying the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) protection act, chapter 19.86 RCW. An action to enforce this chapter may not be brought under RCW 19.86.090. (b) The office of the attorney general, before commencing an action under the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) protection act, chapter 19.86 RCW, must provide 45 days' written notice to a deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) or developer of the alleged violation of this chapter. For the first violation, the developerDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) or deployerDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) may cure the noticed violation within 60 days of receiving the written notice. (c) This chapter may be enforced solely by the attorney general under the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) protection act, chapter 19.86 RCW, and may not be construed as providing the basis for, or be subject to, a private right of action for violations of this chapter. This chapter does not incorporate RCW 19.86.093.
(2) Nothing in this chapter may be construed to limit or otherwise affect the obligations of developersDeveloper"Developer" means any person doing business in this state that develops, or intentionally and substantially modifies, a high-risk artificial intelligence system intended for use within the state.Sec. 2(7) and deployersDeployer"Deployer" means any person doing business in this state that deploys a high-risk artificial intelligence system to make a consequential decision in the state.Sec. 2(6) under applicable laws, rules, or regulations relating to data privacy or security.
Section 10 designates the attorney general as the exclusive enforcement authority. A violation of the chapter is deemed an unfair or deceptive act under the Consumer Protection Act (chapter 19.86 RCW). The bill expressly bars private rights of action and excludes RCW 19.86.090 (private treble damages) and RCW 19.86.093. Pre-suit notice of 45 days is required, and a 60-day cure period is available for first violations. Existing data privacy and security obligations are preserved.
(1)–(3) 8 A government agency that makes available an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system intended to interact with consumersConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) must disclose to each consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4), before or at the time of interaction, that the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) is interacting with an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system. The disclosure must be: (a) Clear and conspicuously posted; (b) Written in plain language; and (c) May not use a dark pattern. (2) The disclosure may be provided by using a hyperlink to direct a consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) to a separate web page. (3) A personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) is required to make the disclosure under subsection (1) of this section regardless of whether it would be obvious to a reasonable consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) that the consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) is interacting with an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system.
Section 11 imposes an unconditional AI identity disclosure obligation on government agencies that deploy AI systems intended to interact with consumers. Unlike the private-sector provisions, this obligation is not limited to high-risk AI systems and applies regardless of whether a reasonable consumer would recognize they are interacting with AI. The disclosure must be clear, conspicuous, in plain language, and must not use a dark pattern. A hyperlink to a separate page is permitted. This section is codified separately in Title 42 RCW (public agencies) rather than Title 19 (consumer protection).
Sections 1 through 10 of this act constitute a new chapter in Title 19 RCW.
Section 12 is a codification directive placing Sections 1 through 10 as a new chapter in Title 19 RCW (Consumer Protection).
Section 11 of this act constitutes a new chapter in Title 42 RCW.
Section 13 is a codification directive placing Section 11 (government AI disclosure) as a new chapter in Title 42 RCW (Public Officers and Agencies).
(1)–(9) A task force to assess current uses and trends and make recommendations to the legislature regarding guidelines and potential legislation for the use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems is established. (2) The task force is composed of an executive committee consisting of members as provided in this subsection. (a) The president of the senate shall appoint one member from each of the two largest caucuses of the senate. (b) The speaker of the house of representatives shall appoint one member from each of the two largest caucuses of the house of representatives. (c) The attorney general shall appoint the following members, selecting only individuals with experience in technology policy: (i) One member from the office of the governor; (ii) One member from the office of the attorney general; (iii) One member from Washington technology solutions; (iv) One member from the Washington state auditor; (v) One member representing universities or research institutions that are experts in the design and effect of an algorithmic system; (vi) One member representing private technology industry groups; (vii) One member representing business associations; (viii) Three members representing community advocate organizations that represent communities that are disproportionately vulnerable to being harmed by algorithmic bias; (ix) One member representing the LGBTQ+ community; (x) One member representing the retail industry; (xi) One member representing the hospitality industry; (xii) One member representing statewide labor organizations; and (xiii) One member representing public safety. (d) The task force may meet in personPerson"Person" means any individual, association, corporation, limited liability company, partnership, trust, or other legal entity. "Person" does not include any government or political subdivision.Sec. 2(11) or by telephone conference call, videoconference, or other similar telecommunications method, or a combination of such methods. (e) The executive committee may convene subcommittees to advise the task force on the recommendations and findings set out in subsection (4) of this section. (i) The executive committee shall define the scope of activity and subject matter focus required of the subcommittees including, but not limited to: Education and workforce development; public safety and ethics; health care and accessibility; labor; government and public sector efficiency; state security and cybersecurity; consumerConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) protection and privacy; and industry and innovation. (ii) Subcommittees and their members may be invited to participate on an ongoing, recurring, or one-time basis. (iii) The executive committee in collaboration with the attorney general shall appoint members to the subcommittees that must be comprised of industry participants, subject matter experts, representatives of federally recognized tribes, or other relevant stakeholders. (iv) Each subcommittee must contain at least one member possessing relevant industry expertise and at least one member from an advocacy organization that represents communities that are disproportionately vulnerable to being harmed by algorithmic bias including, but not limited to: African American; Hispanic American; Native American; Asian American; Native Hawaiian and Pacific Islander communities; religious minorities; individuals with disabilities; and other vulnerable communities. (v) Meeting summaries and reports delivered by the subcommittees to the executive committee must be made available on the attorney general's website within 30 days of delivery. (3) The office of the attorney general must administer and provide staff support for the task force. The office of the attorney general may, when deemed necessary by the task force, retain consultants to provide data analysis, research, recommendations, training, and other services to the task force for the purposes provided in subsection (4) of this section. The office of the attorney general may work with the task force to determine appropriate subcommittees as needed. (4) The executive committee and subcommittees of the task force shall examine the development and use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) by private and public sector entities and make recommendations to the legislature regarding guidelines and potential legislation for the use and regulation of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems to protect Washingtonians' safety, privacy, and civil and intellectual property rights. The task force findings and recommendations must include: (a) A literature review of public policy issues with artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2), including benefits and risks to the public broadly, historically excluded communities, and other identifiable groups, racial equity considerations, workforce impacts, and ethical concerns; (b) A review of existing protections under state and federal law for individual data and privacy rights, safety, civil rights, and intellectual property rights, and how federal, state, and local laws relating to artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) align, differ, conflict, and interact across levels of government; (c) A recommended set of guiding principles for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) use informed by standards established by relevant bodies, including recommending a definition for ethical artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) and guiding principles; (d) Identification of high-risk uses of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2), including those that may negatively affect safety or fundamental rights; (e) Opportunities to support and promote the innovation of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) technologies through grants and incentives; (f) Recommendations on appropriate uses of and limitations on the use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) by state and local governments and the private sector; (g) Recommendations relating to the appropriate and legal use of training data; (h) Algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1) issues which may occur when artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems are used and contribute to unjustified differential treatment or impacts disfavoring people on the basis of race, color, national origin, citizen or immigration status, families with children, creed, religious belief or affiliation, sex, marital status, the presence of any sensory, mental, or physical disability, age, honorably discharged veteran or military status, sexual orientation, gender expression or gender identity, or any other protected class under RCW 49.60.010 and recommendations to mitigate and protect against algorithmic discriminationAlgorithmic discrimination"Algorithmic discrimination" means the use of an artificial intelligence system which results in any unlawful differential impact that disfavors any individual or group of individuals on the basis of chapter 49.60 RCW or federal law. "Algorithmic discrimination" does not include: (i) Any offer, license, or use of a high-risk artificial intelligence system by a developer or deployer for the sole purpose of: (A) The developer's or deployer's testing to identify, mitigate, or prevent discrimination or otherwise ensure compliance with state and federal law; or (B) Expanding an applicant, customer, or participant pool to increase diversity or redress historic discrimination; or (ii) Any act or omission by or on behalf of a private club or other establishment not in fact open to the public, as set forth in Title II of the Civil Rights Act of 1964, 42 U.S.C. Sec. 2000a(e), as amended.Sec. 2(1); (i) Recommendations on minimizing unlawful discriminatory or biased outputs or applications; (j) Recommendations on prioritizing transparency so that the behavior and functional components artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) can be understood in order to enable the identification of performance issues, safety and privacy concerns, biases, exclusionary practices, and unintended outcomes; (k) Racial equity issues posed by artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems and ways to mitigate the concerns to build equity into the systems; (l) Civil liberties issues posed by artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems and civil rights and civil liberties protections to be incorporated into artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems; (m) Recommendations as to how the state should educate the public on the development and use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2), including information about data privacy and security, data collection and retention practices, use of individual data in machine learning,and intellectual property considerations regarding generative artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2); (n) A review of protections of personhood, including replicas of voice or likeness, in typical contract structures, and a review of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) tools used to support employment decisions; (o) Proposed state guidelines for the use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) to inform the development, deployment, and use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems to: (i) Retain appropriate human agency and oversight; (ii) Be subject to internal and external security testing of systems before public release for high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" means any artificial intelligence system that is specifically intended to autonomously make, or be a substantial factor in making, a consequential decision without meaningful human consideration. "High-risk artificial intelligence system" does not include: (i) Any artificial intelligence system that is intended to: (A) Perform any narrow procedural task; (B) Improve the result of a previously completed human activity; (C) Perform a preparatory task to an assessment relevant to a consequential decision; or (D) Detect any decision-making pattern, or any deviation from any preexisting decision-making pattern; (ii) Any antifraud technology, antimalware, antivirus, calculator, cybersecurity, database, data storage, firewall, internet domain registration, internet website loading, networking, robocall-filtering, spam-filtering, spellchecking, spreadsheet, webcaching, webhosting, search engine, or similar technology; or (iii) Any technology that communicates in natural language for the purpose of providing users with information, making referrals or recommendations, answering questions, or generating other content, and is subject to an acceptable use policy that prohibits generating content that is unlawful.Sec. 2(8); (iii) Protect data privacy and security; (iv) Promote appropriate transparency for consumersConsumer"Consumer" means a person who is a resident of this state and is acting only in an individual or household context. "Consumer" does not include a person acting in a commercial or employment context.Sec. 2(4) when they interact with artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems or products created by artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2); and (v) Ensure accountability, considering oversight, impact assessment, auditability, and due diligence mechanisms; (p) A review of existing civil and criminal remedies for addressing potential harms resulting from the use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) systems and recommendations, if needed, for new means of enforcement and remedies; and (q) Recommendations for establishing an ongoing committee that must study emerging technologies not limited to artificial technology. (5) The executive committee of the task force must hold its first meeting within 45 days of final appointments to the task force and must meet at least twice each year thereafter. The task force must submit reports to the governor and the appropriate committees of the legislature detailing its findings and recommendations. A preliminary report must be delivered by December 31, 2024, an interim report by December 1, 2025, and a final report by July 1, 2027. Meeting summaries must be posted to the website of the attorney general's office within 30 days of any meeting by the task force. (6) Legislative members of the task force shall be reimbursed for travel expenses in accordance with RCW 44.04.120. Nonlegislative members are not entitled to be reimbursed for travel expenses if they are elected officials or are participating on behalf of an employer, governmental entity, or other organization. Any reimbursement for other nonlegislative members is subject to chapter 43.03 RCW. (7) To ensure that the task force has diverse and inclusive representation of those affected by its work, task force members, including subcommittee members, whose participation in the task force may be hampered by financial hardship and may be compensated as provided in RCW 43.03.220. (8) The definitions in this subsection apply throughout this section unless the context clearly requires otherwise. (a) "Artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2)" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation. (b) "Generative artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2)" means an artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) system that generates novel data or content based on a foundation model. (c) "Machine learning" means the process by which artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) is developed using data and algorithms to draw inferences therefrom to automatically adapt or improve its accuracy without explicit programming. (d) "Training data" means labeled data that is used to teach artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) models or machine learning algorithms to make proper decisions. Training data may include, but is not limited to, annotated text, images, video, or audio. (9) This section expires June 30, 2028.
Section 14 amends 2024 c 163 s 2 (the existing AI task force statute). The key operative changes are: (1) removing the appropriations contingency so the task force is established unconditionally; (2) extending the final report deadline from July 1, 2026, to July 1, 2027; and (3) extending the expiration date from June 30, 2027, to June 30, 2028. The remainder of the section re-enacts the existing task force composition, subcommittee structure, and reporting requirements without substantive changes.
(1)–(5) The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group is established for the purpose of developing artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) policy related to the workplace. The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group shall report to the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force established in section 2, chapter 163, Laws of 2024 as prescribed in subsection (4) of this section. (2) The attorney general shall appoint the following members to the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group: (a) Two members representing statewide labor organizations where the statewide labor organization represents at least 200,000 union members in Washington state; (b) Two members representing the business community; (c) One member representing public sector employees; (d) One member representing private sector employees; (e) One member representing higher education institutions with expertise in artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) and the workforce; (f) One member with expertise in ethics and artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2); and (g) Other members as deemed appropriate by the attorney general. (3) The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group is responsible for developing guiding principles for the use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) in the workplace. At a minimum, the guiding principles must prioritize the responsible and ethical use of artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) tools in ways that protect an individual's privacy and minimize the risk of bias in the workplace. (4) The artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) workplace advisory group shall deliver an interim report on the development of guiding principles for artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) in the workplace to the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force by December 1, 2026, and a final report by March 1, 2027. The final report must be included in the artificial intelligenceArtificial intelligence"Artificial intelligence" means the use of machine learning and related technologies that use data to train statistical models for the purpose of enabling computer systems to perform tasks normally associated with human intelligence or perception, such as computer vision, speech or natural language processing, and content generation.Sec. 2(2) task force's final report as required by section 2(5), chapter 163, Laws of 2024. (5) This section expires June 30, 2028.
Section 15 establishes a new artificial intelligence workplace advisory group reporting to the existing AI task force. The attorney general appoints members representing labor, business, public and private sector employees, higher education, and ethics expertise. The group is charged with developing guiding principles for AI in the workplace, prioritizing responsible use, privacy protection, and bias minimization. An interim report is due December 1, 2026, and a final report by March 1, 2027, to be incorporated into the task force's final report. The section expires June 30, 2028.