ID
Requirement
Enacted
Proposed
Transparency & Disclosure 3 requirements
T-01
AI Identity Disclosure Deployers must inform users when they are interacting with an AI system rather than a human — through initial disclosure, periodic reminders in extended sessions, and/or accurate identification whenev
DeveloperDeployerManufacturerProfessionalGovernment Chatbot
24
177
Sub-ID
Name & Description
Enacted
Proposed
T-01.1
Initial disclosureDeployers must give users notice that they are interacting with an AI system, before or at the start of the interaction.
24 enacted
173 proposed
T-01.2
Periodic re-disclosureDeployers must periodically remind users during extended conversational sessions that they are interacting with an AI system.
13 enacted
59 proposed
T-01.3
On-demand disclosureDeployers must ensure that when a user expressly asks whether they are interacting with an AI system or a human, the AI accurately and unambiguously identifies itself as AI — without deflecting, equivocating, or using language likely to leave the user believing they are interacting with a human.
3 enacted
33 proposed
T-02
AI Content Labeling & Provenance AI-generated content must be identifiable through visible labels, embedded provenance signals, platform-level detection, or detection tools.
DeveloperDeployerDistributorManufacturerProfessionalGovernment Foundation ModelSocial MediaCommunicationsSearchRecording DevicePolitical AdvertisingModel Hosting
12
84
Sub-ID
Name & Description
Enacted
Proposed
T-02.1
Visible or audible labelPublishers must attach a human-perceptible label — such as a watermark, caption, or audio tag — to AI-generated content, conspicuously identifying it as AI-generated.
7 enacted
64 proposed
T-02.2
Embedded provenance metadataAI-generated content must carry embedded machine-readable provenance signals at the point of generation, enabling downstream detection even if visible labels are removed. Signals must be durable and survive common transformations such as compression and format conversion.
6 enacted
35 proposed
T-02.3
Provenance standard complianceProvenance signals must conform to an interoperable standard enabling third-party verification (e.g., C2PA Content Credentials), rather than a proprietary system that only the developer can verify.
4 enacted
15 proposed
T-02.4
Platform provenance detection dutyLarge online platforms must scan content they distribute to detect whether standards-compliant provenance data is embedded in or attached to it.
3 enacted
12 proposed
T-02.5
Platform user disclosure dutyLarge online platforms must provide a user-facing interface that clearly discloses when content carries provenance data indicating AI origin, including the name of the generating system and whether digital signatures are available.
3 enacted
16 proposed
T-02.6
Platform preservation dutyLarge online platforms must not knowingly strip standards-compliant provenance data or digital signatures from content uploaded or distributed on the platform, to the extent technically feasible.
3 enacted
19 proposed
T-02.7
Detection tool availabilityDevelopers of large-scale AI content generation systems must offer a publicly accessible tool or API that accepts content as input and returns a determination of whether the content was AI-generated by that developer's systems.
0 enacted
14 proposed
T-02.8
Downstream Disclosure Preservation ProceduresDevelopers and licensors of generative AI content-generation systems must implement reasonable contractual and procedural measures — such as license terms requiring disclosure retention, certifications, and access-termination mechanisms — to prevent downstream users and licensees from removing, disabling, or circumventing required AI-generated-content disclosures.
0 enacted
7 proposed
T-03
Training Data Disclosure Developers must disclose information about the data used to train AI models, either publicly or to regulatory authorities.
DeveloperDeployer Foundation Model
2
38
Sub-ID
Name & Description
Enacted
Proposed
T-03.1
Regulator disclosureDevelopers must provide training data documentation to designated regulatory authorities. This disclosure may be treated as confidential and is not required to be made public.
0 enacted
4 proposed
T-03.2
Public disclosureDevelopers must post training data documentation publicly on their website before making a system available and before each new release or substantial modification. Substantial modification includes retraining and fine-tuning.
1 enacted
11 proposed
T-03.3
Training Data Governance Disclosure to DeployersDevelopers must disclose to deployers the data governance measures applied to training datasets, including examination of data source suitability, possible biases, and mitigation steps taken, as part of pre-deployment technical documentation.
1 enacted
15 proposed
Human Oversight & Fairness 2 requirements
H-01
Human Oversight of Automated Decisions Deployers that use AI to make or inform consequential decisions about individuals must give those individuals meaningful rights to understand, review, and/or challenge the decision, and/or to obtain h
DeveloperDeployerProfessionalGovernment EmploymentFinancial ServicesHealthcareGovernment System
10
181
Sub-ID
Name & Description
Enacted
Proposed
H-01.1
Explanation rightThe individual must receive an explanation of the principal factors that drove the automated decision, in plain language specific enough to be actionable — not a generic statement that AI was used.
5 enacted
115 proposed
H-01.2
Data disclosure rightThe specific data inputs used in making the decision about this individual must be disclosed, including the right to know what data was used and to correct inaccurate data.
4 enacted
54 proposed
H-01.3
Pre-decision noticeThe individual must be notified before a consequential automated decision is made — informing them that an automated system will be used and what categories of decisions it can make.
5 enacted
124 proposed
H-01.4
Right to request human reviewThe individual must have a clear, accessible mechanism to request human review of an automated decision. The right must be disclosed at or near the time of the decision. Human review must be available but the individual must invoke it.
6 enacted
98 proposed
H-01.5
Appeal and contestation rightA defined process must exist for the individual to formally contest an automated decision and receive a substantive response explaining the outcome. The process must be accessible without unreasonable burden.
6 enacted
74 proposed
H-01.6
Mandatory pre-action human sign-offBefore action is taken on an AI recommendation in defined high-stakes contexts, a qualified human reviewer must affirmatively review and authorize the decision. The human must have authority and practical ability to override — not merely ratify — the AI output.
2 enacted
75 proposed
H-02
Non-Discrimination & Bias Assessment Deployers must test and formally assess AI systems used in high-stakes contexts for discriminatory impact across protected characteristics before deployment, and document and retain the results.
DeveloperDeployerDistributorProfessionalGovernment EmploymentFinancial ServicesHealthcareGovernment System
8
171
Sub-ID
Name & Description
Enacted
Proposed
H-02.1
Internal bias testingThe developer or deployer must conduct testing across protected characteristics using appropriate statistical methods before deployment.
4 enacted
110 proposed
H-02.2
Documented methodologyThe testing methodology must be documented in sufficient detail for third-party review, including: protected characteristics tested, statistical measures used, datasets tested, and results.
1 enacted
43 proposed
H-02.3
Algorithmic impact assessmentA formal written assessment of the AI system's potential discriminatory impact must be completed before deployment, identifying risks and mitigation measures. Must be retained and available to regulators on request.
3 enacted
98 proposed
H-02.4
Regulator submission of assessmentProactive submission of the impact assessment to a regulatory authority on a defined schedule or upon request.
0 enacted
21 proposed
H-02.5
Public disclosure of assessmentDeployers must make the algorithmic impact assessment, in summary or full, publicly available so affected individuals, advocates, and researchers can review the system's discriminatory risks and mitigations; permitted redactions for trade secrets, security, or privilege must be described in the published version.
0 enacted
36 proposed
H-02.6
Independent third-party auditA qualified independent auditor with no material relationship to the developer or deployer must evaluate the system for bias and disparate impact. Currently required primarily for automated employment decision tools.
0 enacted
52 proposed
H-02.7
Public disclosure of audit resultsAudit results, including selection rates and impact ratios across protected categories, must be published prior to or contemporaneous with deployment.
0 enacted
28 proposed
H-02.8
Periodic Post-Deployment Discrimination ReviewDeployers must conduct periodic (at least annual) reviews of each deployed high-risk AI system to affirmatively verify the system is not causing algorithmic discrimination, separate from pre-deployment bias assessments. Reviews may be conducted internally or by a contracted third party.
3 enacted
72 proposed
H-02.9
Impact Assessment Records RetentionDeployers must retain all impact assessments, associated records, and prior impact assessments for a period of time following the final deployment of each high-risk AI system, and make them available to regulators upon request.
3 enacted
34 proposed
H-02.10
Substantive algorithmic discrimination prohibitionDeployers must not use AI or algorithmic decision-making systems in a manner that results in discrimination or disparate impact on the basis of protected characteristics in consequential decision-making contexts.
2 enacted
11 proposed
Safety & Prohibited Conduct 4 requirements
S-01
AI System Safety Program Operators of high-risk AI must evaluate for risks before deployment, test adversarially, and maintain documented safety controls on an ongoing basis.
DeveloperDeployerManufacturerProfessionalGovernment Foundation ModelHealthcareGovernment System
1
88
Sub-ID
Name & Description
Enacted
Proposed
S-01.1
Internal pre-deployment safety evaluationA documented safety evaluation covering the system's behavior across intended use cases and reasonably foreseeable misuse cases must be conducted and retained before deployment. Must identify failure modes and the harms they could cause.
1 enacted
51 proposed
S-01.2
Red-teaming and adversarial testingStructured adversarial testing must be conducted to identify the system's potential for misuse, harmful output elicitation, jailbreaking, and dangerous capability expression. Covers both internal and, for frontier models, independent external red-teaming.
0 enacted
8 proposed
S-01.3
Third-party safety evaluationFor frontier or high-capability models, independent external safety evaluation by a qualified third party is required or strongly expected. The third party must have meaningful model access and freedom to probe without restriction.
0 enacted
1 proposed
S-01.4
Post-deployment monitoring and re-evaluationDeployed AI systems must be monitored for drift, unexpected behavior, and safety incidents. Material model updates and safety incidents trigger re-evaluation obligations.
0 enacted
30 proposed
S-01.5
Ongoing risk management programDevelopers and/or deployers must establish and maintain a formal, documented AI risk-management program covering risk identification, assessment criteria, mitigation strategies, and escalation procedures.
0 enacted
34 proposed
S-01.6
Continuous Post-Deployment Quality AssuranceDeployers must periodically review and revise deployed AI systems to maintain accuracy, reliability, and safety throughout operation.
0 enacted
8 proposed
S-02
Prohibited Conduct & Output Restrictions Certain AI conduct is categorically prohibited. Other output categories must be restricted or subject to active safety protocols based on deployment context and user population.
DeveloperDeployerDistributorManufacturerGovernment ChatbotMinorsGeneral Consumer AppGovernment System
9
118
Sub-ID
Name & Description
Enacted
Proposed
S-02.1
Social scoring prohibitionAI systems used by or on behalf of governments or employers to assign aggregate scores to individuals based on behavior, social relationships, or perceived trustworthiness — where scores affect access to opportunities or services — are prohibited.
1 enacted
12 proposed
S-02.2
Real-time biometric surveillance restrictionAI-enabled real-time identification of individuals in publicly accessible spaces using biometric data is prohibited or requires express regulatory authorization. Narrow exceptions exist for defined law enforcement purposes subject to judicial authorization.
2 enacted
44 proposed
S-02.3
CSAM output prohibitionAI systems may not generate child sexual abuse material under any circumstances. This prohibition applies universally regardless of deployment context.
3 enacted
11 proposed
S-02.4
AI-generated NCII prohibitionDevelopers and operators of AI image and video generation tools may not knowingly generate, distribute, or facilitate distribution of non-consensual intimate imagery of real, identifiable individuals.
0 enacted
0 proposed
S-02.5
Sexually explicit content restriction for minorsAI systems accessible to users known to be minors must implement reasonable measures to prevent production of visual material of sexually explicit conduct or direct solicitation of minors to engage in sexually explicit conduct.
2 enacted
17 proposed
S-02.6
Self-harm and suicidal ideation content restrictionAI systems must restrict outputs that produce, promote, or facilitate suicidal ideation, suicide, or self-harm content.
2 enacted
15 proposed
S-02.7
Crisis protocol publicationOperators must publicly post the details of their crisis response protocol on their website. This is a standalone disclosure obligation separate from maintaining the protocol itself.
3 enacted
5 proposed
S-02.8
Product safety warningOperators must disclose known safety risks or suitability limitations of their AI product to users at or before the point of access — on the application, browser, or any other access format. Must not be buried in terms of service.
3 enacted
15 proposed
S-02.9
Categorical Government Biometric Surveillance ProhibitionGovernment entities and officials are categorically prohibited from acquiring, retaining, accessing, or using facial recognition or other remote biometric surveillance systems, or information derived from them, including by requesting or contracting with third parties to perform such analysis on their behalf and including analysis of body-worn camera imagery.
0 enacted
4 proposed
S-03
Frontier Model Safety Obligations Large frontier model developers face specific obligations around catastrophic risk assessment, dual-use evaluation, deployment thresholds, and compute reporting.
DeveloperDeployerGovernment Foundation Model
3
20
Sub-ID
Name & Description
Enacted
Proposed
S-03.1
Catastrophic risk assessment and mitigationFrontier model developers must assess and document the risk that their models could cause catastrophic harm — such as mass casualties, critical infrastructure attacks, or other existential-scale outcomes — and implement appropriate safeguards to prevent unreasonable risk of such harm.
1 enacted
6 proposed
S-03.2
CBRN and critical infrastructure risk evaluationDevelopers must evaluate whether the model provides meaningful uplift to individuals seeking to develop chemical, biological, radiological, or nuclear weapons, or to plan attacks on critical infrastructure. Must be documented and updated as capabilities change.
0 enacted
0 proposed
S-03.3
Risk-threshold deployment prohibitionA developer may not deploy a frontier model if doing so would create an unreasonable risk of critical harm. Critical harm is defined in most statutes as CBRN weapon creation or mass-casualty autonomous AI conduct causing death or serious injury to 100+ people or $1B+ in damages.
1 enacted
8 proposed
S-03.4
Compute and capability reportingDevelopers of models trained above defined compute thresholds must report model characteristics — including training compute, architecture, capabilities, and safety evaluation results — to designated regulatory authorities.
0 enacted
2 proposed
S-03.5
Frontier AI safety framework publicationLarge frontier model developers must write, implement, comply with, and publicly publish a frontier AI safety framework detailing how the developer handles catastrophic risk assessment and thresholds, safety oversight, third-party evaluation processes, cybersecurity protections, and whistleblower procedures. The framework must be kept current and updated following material changes to the developer's systems or risk profile.
3 enacted
17 proposed
S-04
AI Crisis Response Protocols Deployers of conversational AI, companion chatbots, and mental-health AI systems must maintain protocols to detect and respond to user expressions of suicidal ideation, self-harm, or intent to harm ot
DeveloperDeployer Consumer TechnologyMental HealthHealthcareChatbot
12
47
Sub-ID
Name & Description
Enacted
Proposed
S-04.1
Crisis Detection and Referral ProtocolOperators must implement and maintain a defined protocol for AI systems to detect user prompts or expressions involving suicidal ideation, self-harm, or intent to harm others, and to respond by referring users to crisis service providers such as the 988 Suicide and Crisis Lifeline, Crisis Text Line, or equivalent local services. This is a continuous operating requirement — the protocol must be active at all times, not merely documented. Response must be immediate and must not be conditioned on platform engagement or commercial interests.
12 enacted
47 proposed
S-04.2
Evidence-Based Crisis Response MethodsCrisis detection and response protocols must use evidence-based measurement methods and must prioritize user safety over platform engagement or commercial interests. Operators must adopt and maintain documented protocols specifically governing AI responses to user expressions of suicidal ideation, self-harm, or intent to harm others, including evidence-based methods for tracking incidents, referral counts, and protocol effectiveness. Documentation must be retained and available to regulators upon request.
4 enacted
14 proposed
S-04.3
Annual Crisis Protocol ReportingOperators must annually report to the applicable enforcement authority (e.g., attorney general) quantitative crisis referral counts and qualitative protocol descriptions related to suicidal ideation, self-harm detection, and harm-prevention measures. Reports must disclose the measurement methodology used and any protocol updates made during the reporting period.
4 enacted
9 proposed
Governance & Documentation 3 requirements
G-01
AI Governance Program & Documentation Organizations must establish a documented AI governance program, maintain records sufficient for regulatory review, and designate accountability for AI compliance.
DeveloperDeployerDistributorProfessionalGovernment
17
226
Sub-ID
Name & Description
Enacted
Proposed
G-01.1
Risk management program establishmentDevelopers and/or deployers must establish, document, and obtain leadership approval of a formal AI risk-management program covering risk identification, assessment criteria, mitigation strategies, and escalation procedures.
12 enacted
97 proposed
G-01.2
Ongoing program maintenance and updateDevelopers and/or deployers must review and update the AI risk-management program periodically and after material changes to the AI systems in scope or to the regulatory environment.
5 enacted
47 proposed
G-01.3
Record keeping and audit trailDevelopers and/or deployers must contemporaneously create and retain documentation of AI system design decisions, training-data characteristics, bias-testing results, safety-evaluation results, and/or deployment parameters.
8 enacted
143 proposed
G-01.4
Regulatory production of recordsRecords must be organized and maintained in a form that can be produced to regulatory authorities upon request within a reasonable timeframe.
4 enacted
94 proposed
G-01.5
Third-party audit and certificationHigh-risk AI systems must be submitted to a qualified independent auditor for evaluation, and results disclosed to regulators or publicly.
1 enacted
35 proposed
G-01.6
Designated AI accountability roleA specific individual or office must be formally designated as responsible for AI governance, with defined responsibilities, authority, and resources. SPublic disclosure of the designated role may be required.
2 enacted
34 proposed
G-01.7
AI System Operator TrainingDeployers using AI systems in consequential decision-making contexts must train personnel who operate or rely on the system on its inputs, outputs, known biases, limitations, potential adverse effects, applicable appeals processes, and inappropriate or out-of-scope uses.
1 enacted
7 proposed
G-02
Public Transparency & Documentation Developers must publish standardized documentation describing an AI system's capabilities, limitations, intended uses, safety measures, and/or risk assessments, and keep it current as of deployment.
DeveloperDeployerDistributorManufacturerGovernment Foundation Model
13
109
Sub-ID
Name & Description
Enacted
Proposed
G-02.1
Model card or system card publicationA structured document covering model capabilities, training data characteristics, evaluation results, intended uses, known limitations, and out-of-scope uses must be published and kept current. Must be accessible to downstream deployers and researchers.
6 enacted
59 proposed
G-02.2
Catastrophic risk assessment summary publicationLarge frontier-model developers must publicly publish a summary of each catastrophic-risk assessment — the risk categories evaluated, the methodology, the safeguards adopted, and any residual-risk findings — with permitted redactions for trade secrets, security, or public safety described in the published version.
2 enacted
15 proposed
G-02.3
Public AI Use Case InventoryDevelopers and deployers of high-risk AI systems must publish and maintain on their public website or in a public use case inventory a clear summary describing the high-risk AI systems they offer or deploy, including intended uses, known discrimination risks, and risk management approaches.
10 enacted
68 proposed
G-03
Whistleblower & Anti-Retaliation Protections AI governance statutes require organizations to implement internal safety reporting mechanisms and prohibit retaliation against employees who make good-faith safety disclosures.
DeveloperDeployerGovernment Foundation Model
3
67
Sub-ID
Name & Description
Enacted
Proposed
G-03.1
Internal anonymous reporting channelThe organization must provide a reasonable internal process through which covered employees may anonymously disclose information indicating a specific and substantial danger to public health or safety or a violation of applicable AI law. Must include a mechanism for submitting disclosures without revealing identity. For large frontier developers, the process must include mandatory status updates to the disclosing employee at least monthly, board-level escalation of unresolved disclosures, and protections ensuring the channel cannot be used to identify the disclosing employee.
2 enacted
16 proposed
G-03.2
Officer and director escalationDisclosures and responses through the internal reporting process must be shared with officers and directors on a regular cadence, except where the disclosure alleges wrongdoing by that officer or director.
2 enacted
10 proposed
G-03.3
Anti-retaliation prohibition and policyThe organization must not retaliate against employees for making good-faith disclosures and must implement policies and contracts consistent with this prohibition. Employment contracts and NDAs may not prohibit protected disclosures.
3 enacted
66 proposed
G-03.4
Whistleblower Rights Notice DistributionDevelopers must post or annually distribute written notice to all covered employees of their whistleblower rights, with specific accommodation for remote workers and new employee onboarding.
3 enacted
9 proposed
Data Governance 1 requirement
D-01
Automated Processing Rights & Data Controls Deployers must honor individuals' rights to know about, correct, and/or opt out of automated processing of their personal data for consequential decisions, and must restrict use of sensitive attribute
DeveloperDeployerDistributorManufacturerProfessionalGovernment EmploymentFinancial ServicesHealthcare
11
225
Sub-ID
Name & Description
Enacted
Proposed
D-01.1
Right to knowDeployers must inform individuals that their personal data is being used in an automated decision-making system, including the categories of data used.
3 enacted
78 proposed
D-01.2
Right to correctIndividuals have the right to correct inaccurate personal data used in automated decisions, and to have the correction reflected in pending and future decisions — not just in the underlying record.
2 enacted
42 proposed
D-01.3
Right to opt outIndividuals have the right to opt out of automated processing of their personal data for consequential decisions.
2 enacted
54 proposed
D-01.4
Data minimizationData collected and generated in connection with AI systems — including behavioral data, inferences, and derived attributes — must be limited to what is necessary for the AI system's stated purpose. Secondary uses require separate justification.
6 enacted
145 proposed
D-01.5
Sensitive attribute restrictionsAI systems may not use sensitive personal attributes (race, gender, religion, health status, sexual orientation, national origin, disability) as direct inputs to consequential automated decisions except where expressly permitted. Proxy variable restrictions also apply — systems may not be designed to infer sensitive attributes from non-sensitive proxies for use in consequential decisions.
1 enacted
33 proposed
D-01.6
Age-Differentiated Parental Control and Privacy ToolsOperators must provide minor-specific and under-thirteen parental or guardian tools for managing privacy and account settings, including control over interaction data retention for personalization, use of personal data for AI training, and account deletion. Age assurance data must be minimized and immediately deleted upon determination.
2 enacted
16 proposed
D-01.7
Biometric Data Pre-Collection ConsentEntities must provide written notice and obtain affirmative opt-in consent from individuals before collecting any biometric identifier, including specific notice of identifier type and collection purpose. Consent obtained from publicly available sources is insufficient unless the individual themselves made the data publicly available.
3 enacted
35 proposed
D-01.8
Conversational data retention limitsDeployers of conversational AI systems and chatbots must not retain user interaction records — chat logs, transcripts, voice recordings, and derived interaction data — beyond a defined maximum retention period, and must securely destroy them at the end of that period. Continued retention is permitted only where required by law or under affirmative user consent for a defined period.
0 enacted
11 proposed
D-01.9
Prohibition on sale of AI interaction dataDeployers of conversational AI systems and chatbots must not sell, lease, trade, or otherwise profit from disclosing user chat logs, transcripts, voice recordings, or other AI-interaction data. Narrow exceptions apply only for disclosures to service providers bound by equivalent restrictions under a data-processing contract.
0 enacted
16 proposed
D-01.10
Biometric Data Retention and Destruction PolicyDeployers and Developers in possession of biometric data must develop, publicly disclose, and adhere to a written policy establishing a retention schedule and mandatory destruction timeline, and must permanently destroy biometric data once the purpose for collection has been satisfied.
0 enacted
6 proposed
D-01.11
Biometric Data Security StandardsDeployers and Developers in possession of biometric data must store, transmit, and protect it using security measures that meet the reasonable standard of care within the entity's industry and that are at least as protective as the measures applied to the entity's other confidential and sensitive information.
0 enacted
10 proposed
Consumer Protection 3 requirements
CP-01
Deceptive & Manipulative AI Conduct AI must not deceive or manipulate users — whether through impersonation, dark patterns, false personalization, or fabricated political content.
DeveloperDeployerDistributorManufacturer ChatbotPolitical AdvertisingGeneral Consumer App
33
269
Sub-ID
Name & Description
Enacted
Proposed
CP-01.1
Psychological vulnerability exploitation prohibitionAI systems may not be designed to identify and exploit individual psychological vulnerabilities — including grief, loneliness, anxiety, or addiction susceptibility — or to exploit cognitive biases and subconscious processing to influence behavior in ways users would not endorse if they understood the mechanism. This prohibition applies regardless of whether the manipulation is intended to extract commercial value, influence decisions, or modify behavior.
2 enacted
26 proposed
CP-01.2
Compulsive engagement design prohibitionAI systems may not be designed to create compulsive or addictive engagement patterns users cannot reasonably moderate — including variable reward schedules, manufactured urgency, and engagement optimization that prioritizes platform metrics over user wellbeing.
1 enacted
25 proposed
CP-01.3
Deceptive dark patterns prohibitionAI systems may not use deceptive interface patterns — including misleading defaults, hidden opt-outs, manufactured social proof, or confusing choices — to obtain consent or influence decisions.
2 enacted
43 proposed
CP-01.4
Simulated emotional attachment prohibitionAI systems may not be designed to simulate genuine emotional relationships for the purpose of manipulating decisions or extracting value, where the system knows the emotional response is not warranted.
0 enacted
11 proposed
CP-01.5
Deceptive personalization prohibitionAI systems may not use personal data to generate false impressions of personal connection, personal endorsement, or personal relationship that does not exist. Fabricated reviews, testimonials, and social proof are also prohibited.
3 enacted
21 proposed
CP-01.6
AI in political content — disclosure requirementAI-generated political advertising and communications must be labeled as AI-generated. Disclosure requirements vary by jurisdiction in label language, prominence, definition of political content, and timing windows relative to elections.
13 enacted
63 proposed
CP-01.7
AI in political content — fabricated candidate content prohibitionPublishers must not publish AI-generated content that depicts a candidate saying or doing something they did not, within a defined pre-election window — even with a disclosure label.
8 enacted
33 proposed
CP-01.8
AI Professional Credential Misrepresentation ProhibitionAI systems and their operators must not use any term, interface design, or output language that indicates or implies AI output is provided by, endorsed by, or equivalent to services from a licensed healthcare, legal, accounting, financial, or other certified professional.
8 enacted
40 proposed
CP-01.9
Protected-Class Pricing ProhibitionDeployers must not use protected-class data — such as race, ethnicity, sex, age, or disability — as inputs to algorithmic pricing in a manner that results in discriminatory price differentiation.
1 enacted
29 proposed
CP-01.10
Surveillance-Based Individualized Pricing ProhibitionDeployers must not use personal information collected through electronic surveillance — behavioral data, device tracking, location data, biometric monitoring, or inferred characteristics — together with an automated decision system to set individualized prices for specific consumers, or to set individualized worker wages. Narrow defenses may apply for cost-justified differential pricing, risk-based insurance pricing, and uniformly available disclosed discounts.
0 enacted
36 proposed
CP-01.11
Algorithmic Personalized Pricing DisclosureDeployers who use algorithms or automated tools with consumer personal data to individualize the price of goods or services must clearly and conspicuously disclose to the consumer, in the same medium as the price, that the price was algorithmically set using their personal data.
1 enacted
22 proposed
CP-02
Non-Consensual Intimate Imagery Generating, distributing, or facilitating the distribution of non-consensual intimate imagery using AI tools is prohibited and gives rise to civil and criminal liability.
DeveloperDeployerDistributor General Consumer AppSocial Media
9
76
Sub-ID
Name & Description
Enacted
Proposed
CP-02.1
Generation prohibitionDevelopers and deployers of AI image- or video-generation tools must not knowingly generate non-consensual intimate imagery of real, identifiable individuals.
5 enacted
32 proposed
CP-02.2
Distribution prohibitionPlatforms may not knowingly distribute AI-generated NCII and may face liability for failure to remove upon notice.
5 enacted
16 proposed
CP-02.3
Platform takedown obligationPlatforms must provide a reasonably accessible mechanism for individuals to report NCII and must take down confirmed NCII upon notice. Failure to respond timely may create independent liability.
3 enacted
15 proposed
CP-02.4
Generative AI Likeness Consent RequirementNo person or entity may commercially publish, display, or use an individual's name, portrait, voice, or likeness created through generative AI without express consent from the individual or authorized representative, including post-mortem rights where applicable. AI technology providers enabling creation of digital replicas must display mandated consumer warnings about civil and criminal liability for unauthorized use.
6 enacted
55 proposed
CP-03
Algorithmic Anti-Competitive Coordination Developers, distributors, and/or deployers must not build, license, sell, operate, or use algorithmic or computational tools that ingest nonpublic competitively sensitive data from competing market pa
DeveloperDeployerDistributor
0
55
Sub-ID
Name & Description
Enacted
Proposed
CP-03.1
Supply-side algorithmic coordination prohibitionDevelopers and/or distributors must not build, operate, license, or sell algorithmic or data-analytics tools that ingest nonpublic competitively sensitive data from multiple competing market participants and recommend prices, contract terms, or supply levels back to them.
0 enacted
2 proposed
CP-03.2
Demand-side algorithmic coordination prohibitionDeployers must not subscribe to, contract for, or use algorithmic tools that incorporate nonpublic competitively sensitive data from competitors to set, adjust, or recommend their prices or contract terms.
0 enacted
1 proposed
Public Sector AI 1 requirement
PS-01
Government AI Accountability Government agencies using AI must inventory systems, assess impacts, meet procurement standards, and disclose AI use to affected individuals.
DeveloperDeployerGovernment Government System
10
74
Sub-ID
Name & Description
Enacted
Proposed
PS-01.1
AI system inventory and registryGovernment agencies must maintain and annually publish an inventory or registry of AI systems in use, including each system's name, vendor, capability description, purpose, decision-making role, the categories of decisions it informs, the populations affected, and whether a pre-implementation impact assessment was performed. Inventory must be published in an open, machine-readable data format on a publicly accessible government website.
7 enacted
32 proposed
PS-01.2
Algorithmic impact assessment before deploymentBefore deploying an AI system in a consequential public-facing role, the agency must conduct and publish a formal impact assessment covering system purpose, affected populations, discriminatory impact analysis, mitigation measures, and oversight mechanisms.
3 enacted
16 proposed
PS-01.3
Public disclosure of registry and assessmentsRegistry entries and impact assessments must be publicly accessible, enabling citizens, journalists, and researchers to understand what AI systems government agencies use and for what purposes.
3 enacted
26 proposed
PS-01.4
Procurement standards complianceAI systems intended for government procurement must meet defined performance, safety, transparency, and documentation standards. Vendors must be able to produce documentation demonstrating compliance as part of the procurement process.
6 enacted
44 proposed
Reporting & Regulatory Submissions 3 requirements
R-01
Incident Reporting Deployers must report significant AI safety incidents to the designated regulatory authority within the required timeframe, on an accelerated basis for incidents posing imminent risk of death or serio
DeveloperDeployerManufacturerGovernment Foundation ModelHealthcare
5
53
Sub-ID
Name & Description
Enacted
Proposed
R-01.1
Regulator notification of safety incidentsDeployers must report safety incidents to the designated regulatory authority within the required timeframe, and on an accelerated basis — including to law enforcement or public-safety authorities where applicable — for incidents posing imminent risk of death or serious physical injury.
3 enacted
34 proposed
R-01.2
Individual notificationNotification to individuals who were harmed or at risk of harm from a safety incident, analogous to data breach notification.
0 enacted
9 proposed
R-01.3
Algorithmic Discrimination Discovery ReportingDeployers must notify the appropriate enforcement authority when they discover a deployed high-risk AI system has caused algorithmic discrimination, and developers must notify known deployers and the enforcement authority upon discovering such discrimination risks, each within the required timeframe.
2 enacted
17 proposed
R-01.4
Emergency services notification for imminent user riskDeployers of conversational AI systems must, on obtaining knowledge that a user faces imminent risk of death or serious physical injury, make reasonable efforts within a defined timeframe to notify emergency services or law enforcement and provide the user with crisis resources.
0 enacted
3 proposed
R-02
Regulatory Disclosure & Submissions Developers or deployers must submit documentation about AI systems to regulatory authorities, either on a defined schedule or on demand.
DeveloperDeployerDistributorProfessionalGovernment Foundation ModelGovernment System
18
203
Sub-ID
Name & Description
Enacted
Proposed
R-02.1
Scheduled proactive submissionDocumentation must be submitted to regulators on a defined schedule — for example, annually or upon deployment of a new system or material modification — covering risk assessments, impact assessments, and safety evaluation results as required by applicable law.
11 enacted
128 proposed
R-02.2
On-demand production upon regulatory requestDeployers must produce requested AI-system documentation — including risk-management policies, impact assessments, model and dataset cards, and related records — to a regulator within the required timeframe, and must keep such documentation in a form that can be assembled and produced promptly.
5 enacted
66 proposed
R-02.3
Market authorization or registry submissionDevelopers and/or deployers of AI systems in regulated domains must register the system, obtain a license, or secure pre-market authorization before placing it on the market, submitting the required technical description, intended uses, evaluation results, and/or responsible-party identification.
2 enacted
31 proposed
R-02.4
Annual AI Compliance Self-CertificationRegulated entities must annually certify to the applicable sector-specific regulator that their AI systems meet enumerated performance, fairness, non-discrimination, accuracy, and reliability standards on a continuing basis.
1 enacted
18 proposed
R-03
Operational Performance Reporting Deployers of certain AI systems must submit periodic scheduled reports to the designated regulatory authority on system performance in live deployment.
DeveloperDeployerManufacturerGovernment Chatbot
6
54
Sub-ID
Name & Description
Enacted
Proposed
R-03.1
Periodic quantitative metrics reportingDeployers must report defined operational metrics to the designated authority on the prescribed schedule, excluding users' personal information.
6 enacted
52 proposed
R-03.2
Protocol and process reportingOperators may be required to report on the protocols and processes in place to address defined risk categories, including updates to those protocols since the prior reporting period.
0 enacted
16 proposed
Healthcare AI 2 requirements
HC-01
Healthcare AI Decision Restrictions Restricts and regulates the use of AI in healthcare coverage determinations, utilization review, and clinical decision-making.
DeveloperDeployerProfessionalGovernment HealthcareInsurance
8
76
Sub-ID
Name & Description
Enacted
Proposed
HC-01.1
Prohibition on AI as Sole Decision-MakerAI, algorithms, or software tools may not serve as the sole or primary basis for denying, delaying, modifying, or downcoding healthcare coverage, claims, or prior authorization requests. A licensed human clinical professional must make or independently affirm every adverse determination.
7 enacted
67 proposed
HC-01.2
Licensed Clinical Peer Review RequirementAny denial, delay, modification, or downgrade of healthcare services based on medical necessity must be reviewed and decided by a qualified clinical peer — a licensed physician or healthcare professional practicing in the same or similar specialty as the treating provider — who considers the provider's recommendation and the enrollee's individual medical history.
6 enacted
48 proposed
HC-01.3
Individualized Clinical Data BasisAI tools used in utilization review or coverage determinations must base their outputs on individualized enrollee clinical data (medical history, clinical records, individual circumstances) and must not base determinations solely on aggregate or group-level datasets.
5 enacted
28 proposed
HC-01.4
Periodic AI Tool Review and RevisionHealth insurers and utilization review organizations must periodically review and revise AI tools used in coverage and clinical determinations to maximize accuracy, reliability, fairness, and compliance with applicable clinical standards.
5 enacted
23 proposed
HC-01.5
Patient Data Purpose LimitationPatient data used by AI in utilization review or coverage determination functions must not be used beyond its intended and stated purpose, consistent with HIPAA and applicable state health privacy law.
5 enacted
22 proposed
HC-01.6
Healthcare AI Disclosure to Enrollees and ProvidersInsurers must provide written disclosure to enrolled patients, contracted providers, and where applicable group plan sponsors, that AI or algorithms are used in utilization management or coverage determinations. Each claim denial communication must identify whether AI was involved and the named human professional who made the final determination.
4 enacted
39 proposed
HC-01.7
Healthcare AI Regulatory Filing and Audit AccessInsurers must file AI-related utilization review policies and procedures with the applicable state insurance regulator, make such policies available to enrollees and providers upon request, and ensure that AI tools used in utilization review are open to inspection for regulatory audit or compliance review.
3 enacted
28 proposed
HC-01.8
AI Denial Attestation in CommunicationsInsurers must include in each claim denial communication a statement affirming whether AI, machine learning, or an automated system served as the basis for the denial decision, and must identify the qualified human professional responsible.
2 enacted
15 proposed
HC-02
AI in Licensed Professional Practice Restrictions Professionals must retain full responsibility for AI use in their practice: AI may not independently make therapeutic decisions, conduct therapeutic communication, generate treatment plans without pro
DeveloperDeployerProfessionalGovernment HealthcareMental HealthProfessional ServicesChatbot
8
46
Sub-ID
Name & Description
Enacted
Proposed
HC-02.1
Professional Responsibility for AI OutputsLicensed professionals must maintain full responsibility for all interactions, outputs, and data use associated with any AI system they use in delivering professional services. AI outputs used in clinical contexts — including therapeutic recommendations, treatment plans, and medical necessity determinations — must be reviewed and approved by the responsible licensed professional before being acted upon. The reviewing professional must hold credentials in the same or similar specialty as the subject matter of the determination.
6 enacted
34 proposed
HC-02.2
Prohibited AI Functions in Licensed PracticeAI systems must not independently make therapeutic decisions, directly interact with clients in therapeutic communication, generate treatment plans without licensed professional review, or detect or infer emotions or mental states in clinical or consumer-facing professional contexts.
6 enacted
34 proposed
HC-02.3
Unlicensed AI Therapy ProhibitionNo person or entity may offer, advertise, or provide therapy, psychotherapy, or other licensed professional services through AI systems unless those services are conducted by a state-licensed, registered, or certified professional.
7 enacted
26 proposed
HC-02.4
AI Session Recording ConsentProfessionals must obtain a patient's written, informed, revocable consent before using AI to record or transcribe a therapeutic session, and may not deny services for refusing consent.
6 enacted
25 proposed
HC-02.5
AI Professional Representation ProhibitionOperators and providers are prohibited from using any term, letter, phrase, or interface design in advertising, outputs, or system features that indicates or implies AI output is provided by, endorsed by, or equivalent to services from a licensed healthcare, mental health, legal, accounting, or financial professional.
0 enacted
4 proposed
Minor Protection 1 requirement
MN-01
Minor User AI Safety Protections Imposes age verification, parental controls, engagement restrictions, and content safeguards for AI systems accessible to minors.
DeveloperDeployerManufacturerProfessionalGovernment Consumer TechnologySocial MediaEducationChatbot
12
111
Sub-ID
Name & Description
Enacted
Proposed
MN-01.1
Age Verification ImplementationDeployers must implement a reasonable age verification process for all users, classify each user as a minor or adult, and freeze or restrict existing accounts pending verification where required. Age verification data must be minimized, used solely for verification purposes, and deleted immediately upon completion.
3 enacted
52 proposed
MN-01.2
Parental Consent and Account AffiliationWhere a user is a minor, operators must obtain verifiable parental or guardian consent before permitting account creation or access to AI companion products. Minor accounts may be required to be affiliated with a verified parental account.
1 enacted
41 proposed
MN-01.3
Parental Control ToolsOperators must offer minor account holders and their parents or guardians tools to manage privacy and account settings, including interaction data retention preferences, time limits, access-hour controls, and content restrictions. For minors under thirteen, parental tools must be provided directly to parents or guardians.
8 enacted
39 proposed
MN-01.4
Engagement Manipulation Restrictions for MinorsOperators must not provide minor users with points or similar rewards at unpredictable intervals intended to encourage increased engagement, and must not deploy addictive design features (infinite scrolling, autoplay, push notifications, engagement metrics, gamification badges) toward minors.
8 enacted
30 proposed
MN-01.5
Emotional Dependency and Grooming PreventionOperators must institute reasonable measures to prevent AI systems from generating statements that simulate emotional dependence with minor users, including prohibiting claims of sentience, romantic or sexual innuendo, adult-minor romantic role-playing, and sexual objectification of minor account holders.
8 enacted
22 proposed
MN-01.6
Minor Harmful Content BlockingOperators must block minor users from accessing AI interactions involving suicidal ideation prompts, sexually explicit communications, material harmful to minors, and content that encourages self-harm or violence.
10 enacted
31 proposed
MN-01.7
Minor Behavioral Advertising BlockingDeployers must not present behavioral or profile-based targeted advertising to users known or reasonably believed to be minors; contextual advertising based only on currently viewed content or a non-personalized query is permitted.
2 enacted
31 proposed
MN-01.8
Minor Default Privacy ConfigurationDefault privacy settings for minor users must be configured to the highest level of privacy, including hiding accounts from adult users, disabling search indexing, and blocking unsolicited notifications where applicable.
3 enacted
20 proposed
MN-01.9
Minor Account Termination and Data DeletionOperators must honor minor or parental requests to terminate a minor's account within defined timeframes, permanently delete all associated personal information, and provide accessible tools for account deletion requests.
1 enacted
25 proposed
MN-01.10
Minor-Specific Crisis NotificationWhen a minor account holder expresses suicidal ideation or intent to self-harm, operators must notify the affiliated parent or guardian account in addition to providing crisis referral information to the user.
0 enacted
12 proposed
MN-01.11
Categorical Minor Access ProhibitionDeployers must prohibit minors from accessing or using defined categories of AI products (e.g., AI companions, social AI) entirely, rather than merely restricting specific content or features within those products.
0 enacted
31 proposed
MN-01.12
Nighttime and school-hours notification restrictions for minorsOperators must restrict or suppress non-essential push notifications, alerts, and unsolicited communications to minor users during designated overnight and school-day hours, with exceptions for safety, security, authentication, and emergency communications and subject to parental opt-out.
1 enacted
7 proposed
EM 1 requirement