G-01
Governance & Documentation
AI Governance Program & Documentation
Organizations developing or deploying AI must establish a formal AI governance program, maintain contemporaneous records of AI system design, testing, and deployment decisions, and designate a responsible individual or office for AI governance. Program establishment is not a one-time exercise — ongoing maintenance, recordkeeping, and accountability designation are continuing obligations.
Sub-obligations7
Bills243
Jurisdictions41
Enacted17
Show
Sort bills within section

7 sub-obligations of G-01

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
G-01.1 Risk management program establishment
Developers and/or deployers must establish, document, and obtain leadership approval of a formal AI risk-management program covering risk identification, assessment criteria, mitigation strategies, and escalation procedures.
19Enacted 58Live 78Failed 155Total Jump →
G-01.2 Ongoing program maintenance and update
Developers and/or deployers must review and update the AI risk-management program periodically and after material changes to the AI systems in scope or to the regulatory environment.
5Enacted 28Live 28Failed 61Total Jump →
G-01.3 Record keeping and audit trail
Developers and/or deployers must contemporaneously create and retain documentation of AI system design decisions, training-data characteristics, bias-testing results, safety-evaluation results, and/or deployment parameters.
9Enacted 119Live 72Failed 200Total Jump →
G-01.4 Regulatory production of records
Records must be organized and maintained in a form that can be produced to regulatory authorities upon request within a reasonable timeframe.
4Enacted 75Live 39Failed 118Total Jump →
G-01.5 Third-party audit and certification
High-risk AI systems must be submitted to a qualified independent auditor for evaluation, and results disclosed to regulators or publicly.
1Enacted 23Live 19Failed 43Total Jump →
G-01.6 Designated AI accountability role
A specific individual or office must be formally designated as responsible for AI governance, with defined responsibilities, authority, and resources. SPublic disclosure of the designated role may be required.
2Enacted 14Live 23Failed 39Total Jump →
G-01.7 AI System Operator Training
Deployers using AI systems in consequential decision-making contexts must train personnel who operate or rely on the system on its inputs, outputs, known biases, limitations, potential adverse effects, applicable appeals processes, and inappropriate or out-of-scope uses.
1Enacted 4Live 4Failed 9Total Jump →
Bills That Map This Requirement 645 mappings
G-01.1
Risk management program establishment
Developers and/or deployers must establish, document, and obtain leadership approval of a formal AI risk-management program covering risk identification, assessment criteria, mitigation strategies, and escalation procedures.
Enacted
19
Live
58
Failed
78
Total
155
CO
Enacted eff 2026-02-01
Deployers must implement and maintain a risk management policy and program governing deployment of each high-risk AI system, specifying the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks. The program must be iteratively reviewed and updated over the system's life cycle and must be reasonable considering NIST AI RMF, ISO/IEC 42001, or an AG-designated framework, as well as the deployer's size, system scope, and data sensitivity.
CO
Enacted eff 2026-02-01
Deployers must implement a risk management policy and program governing their deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. It must be iterative — planned, implemented, and regularly and systematically reviewed and updated over the life cycle of the system. Reasonableness is assessed considering: the NIST AI RMF, ISO/IEC 42001, or another recognized framework (or any AG-designated framework); the deployer's size and complexity; the nature and scope of systems deployed; and the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems.
CT
Enacted eff 2023-07-01
The Office of Policy and Management must develop and establish policies and procedures governing the development, procurement, implementation, utilization, and ongoing assessment of AI systems used by state agencies, including procurement governance, non-discrimination safeguards across enumerated protected characteristics, pre-implementation impact assessment requirements, and ongoing DAS assessment.
CT
Enacted eff 2023-07-01
The Judicial Department must develop, establish, and post on its website policies and procedures governing its AI procurement, implementation, utilization, and ongoing assessment, including non-discrimination safeguards, pre-implementation impact assessment requirements, and ongoing bias assessment provisions.
IN
Enacted eff 2025-07-01
Each school corporation and charter school must adopt a formal AI policy that includes restrictions on student AI platform use, an inventory of approved AI platforms, a process for teachers to report unauthorized AI use, a formal review process for such reports at the high school level, and disclosure requirements for students using AI on assignments.
KY
KY SB 176 (Facial Recognition Technology) § KRS Chapter 61, Section 1(3)
Enacted eff 2022-04-08
The working group must create and make publicly available by January 1, 2024, a model policy for law enforcement use of facial recognition technology covering authorized uses (including a prohibition on identifying persons in constitutionally protected activities absent probable cause), personnel authorization, documentation of use, secondary-examiner confirmation of findings, data integrity and retention, data security and data-sharing, training, image-source requirements, audit records, and privacy protections for nudity.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-506
Enacted eff 2024-10-01
The Department of State Police must adopt and publish a model statewide FRT policy, and law enforcement agencies must not use FRT unless in accordance with that published model policy.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–802
Enacted eff 2024-07-01
The Office of the Attorney General, the Comptroller, and the State Treasurer must each establish policies and procedures functionally compatible with DoIT's AI governance policies for the development, procurement, deployment, use, and ongoing assessment of systems that employ high-risk artificial intelligence, by June 1, 2025.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–804
Enacted eff 2024-07-01
The Department of Information Technology, in consultation with the Governor's AI Subcabinet, must adopt policies and procedures governing the development, procurement, deployment, use, and ongoing assessment of high-risk AI systems by State agencies — including inventory criteria, adequate guardrails, notification and opt-out guidance for negatively impacted individuals, and procurement guidance ensuring data privacy and legal compliance — by December 1, 2024.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–806
Enacted eff 2024-07-01
The Governor's AI Subcabinet must develop strategy and monitoring processes for responsible AI use, oversee the statewide AI inventory and impact assessments, monitor high-risk AI, ensure compliance with State AI policies, develop and implement a comprehensive action plan, and support AI innovation, workforce skills, and foundational infrastructure across State government.
MT
Enacted eff 2025-05-07
Deployers must develop a risk management policy after deploying a critical artificial intelligence system that controls a critical infrastructure facility in whole or in part. The policy must be reasonable and must consider guidance and standards from the latest version of the NIST AI Risk Management Framework, the ISO/IEC 42001 AI standard, or another nationally or internationally recognized AI risk management framework. A plan prepared under federal requirements constitutes compliance with this obligation.
TN
TN HB 1630 (AI in Education Policy) § Tenn. Code Ann. § 49-7-1xx (new section, Section 1 of the Act)
Enacted eff 2024-03-11
The University of Tennessee Board of Trustees, the Board of Regents, and each state university local governing board must adopt and implement a policy governing the use of artificial intelligence by students, faculty, and staff for instructional and assignment purposes no later than July 1, 2025.
TN
TN HB 1630 (AI in Education Policy) § Tenn. Code Ann. § 49-2-203(a)(new subdivision) (Section 2 of the Act)
Enacted eff 2024-03-11
Each local board of education must adopt and implement a policy governing AI use by students, teachers, and staff for instructional and assignment purposes no later than the 2024-2025 school year, and must report annually by July 1 to the Department of Education, including the adopted policy and an enforcement plan for the upcoming school year.
TN
TN HB 1630 (AI in Education Policy) § Tenn. Code Ann. § 49-13-xxx (new section, Section 3 of the Act)
Enacted eff 2024-03-11
Each public charter school governing body must adopt and implement a policy governing AI use by students, teachers, and staff for instructional and assignment purposes no later than the 2024-2025 school year, and must report annually by July 1 to the Department of Education, including the adopted policy and an enforcement plan for the upcoming school year.
TN
TN SB 1711 (AI in Education Policy) § Tenn. Code Ann. § 49-7-1xx (new section, Title 49, Chapter 7, Part 1)
Enacted eff 2024-03-11
The University of Tennessee Board of Trustees, the Board of Regents, and each local governing board of a state university must adopt a policy governing the use of artificial intelligence by students, faculty, and staff for instructional and assignment purposes, implemented no later than July 1, 2025.
TN
TN SB 1711 (AI in Education Policy) § Tenn. Code Ann. § 49-2-203(a)(new subdivision)
Enacted eff 2024-03-11
Each local board of education must adopt a policy governing the use of artificial intelligence by students, teachers, and staff for instructional and assignment purposes, implemented no later than the 2024-2025 school year, and must report annually by July 1 to the Department of Education with the adopted policy and a description of how it will be enforced.
TN
TN SB 1711 (AI in Education Policy) § Tenn. Code Ann. § 49-13-1xx (new section, Title 49, Chapter 13)
Enacted eff 2024-03-11
Each public charter school governing body must adopt a policy governing the use of artificial intelligence by students, teachers, and staff for instructional and assignment purposes, implemented no later than the 2024-2025 school year, and must report annually by July 1 to the Department of Education with the adopted policy and a description of how it will be enforced.
VA
Enacted eff 2026-07-01
Deployers must design, implement, and maintain a risk management policy and program for each high-risk AI system before deploying or using the system to make a consequential decision. The policy must specify principles, processes, and personnel for identifying, mitigating, and documenting risks of algorithmic discrimination. The program must be reasonable considering the NIST AI RMF, ISO/IEC 42001, or equivalent frameworks. Conformity with these frameworks creates a rebuttable presumption of compliance.
VT
Enacted eff 2026-07-01
Suppliers of mental health chatbots must, to avail themselves of the affirmative defense against professional misconduct claims, create, maintain, and implement a comprehensive written policy that: states the chatbot's intended purposes, abilities, and limitations; ensures licensed mental health provider involvement in development and review; ensures clinical best practices compliance; describes pre-launch and ongoing testing procedures; identifies foreseeable adverse outcomes; provides user harm-reporting mechanisms; describes real-time risk response protocols; ensures regular safety, accuracy, and efficacy reviews (internal or external); provides safe-use instructions; ensures users understand they are interacting with AI and understand the chatbot's purpose, capabilities, and limitations; prioritizes user safety over engagement metrics; implements nondiscrimination measures; and ensures HIPAA-level privacy and security compliance. Suppliers must also maintain documentation describing foundation models, training tools, federal health privacy compliance, data practices, and ongoing accuracy and safety efforts.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.3
Engrossed eff 2026-01-01
Developers and deployers must establish, document, implement, and maintain a governance program containing reasonable administrative and technical safeguards to manage the reasonably foreseeable risks of algorithmic discrimination associated with high-risk automated decision systems. The governance program must be appropriately designed considering: (1) the system's use or intended use; (2) the entity's size, complexity, and resources; (3) the nature, context, and scope of the entity's activities in connection with the system; and (4) the technical feasibility and cost of available risk management tools.
IL
Engrossed
Health insurance issuers must maintain an AI systems program that includes policies and procedures ensuring compliance with this Act by all employees, directors, trustees, agents, representatives, and persons directly or indirectly contracted to administer health insurance coverage. The issuer bears ultimate responsibility for any noncompliance under the Act with respect to its health insurance coverage.
NY
Engrossed
Each developer and deployer of high-risk AI systems must plan, document, and implement a risk management policy and program governing the development or deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative, with regular and systematic review and updates over the system's life cycle, including updates to documentation. Reasonableness is assessed considering: (1) the NIST AI RMF v1.0 or a substantially equivalent framework selected by the attorney general; (2) the entity's size and complexity; (3) the nature, scope, and intended uses of the system; and (4) the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems if sufficient.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-2007(B)(10)
Engrossed eff 2026-07-01
The CIO must develop, publish, and maintain policies and procedures governing public body procurement, implementation, ongoing assessment, data security, privacy, acceptable use, and algorithmic discrimination prevention for high-risk AI systems, including requiring a high-risk AI compliance clause in procurement contracts negotiated or renegotiated on or after July 1, 2026.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must design, implement, and maintain a risk management policy and program specifying principles, processes, and personnel for identifying, mitigating, and documenting algorithmic discrimination risks, at least as stringent as the NIST AI RMF, ISO/IEC 42001, or an equivalent recognized framework, and reasonable in light of the deployer's size, system complexity, data sensitivity, and cost.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5520
Engrossed eff 2026-07-01
Integrators must develop and adopt an acceptable use policy that limits the use of the high-risk AI system to mitigate known risks of algorithmic discrimination.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of personal data and chat logs maintained. The program must be made publicly available on the chatbot provider's website.
CA
Introduced
Each community choice aggregator and each local publicly owned electric utility must adopt a policy regarding its use of artificial intelligence models. The policy must be consistent with the standards adopted by the commission.
GA
Introduced
Deployers must implement a risk management policy and program governing deployment of each automated decision system. The program must specify the principles, processes, and personnel the deployer uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative — planned, implemented, and regularly and systematically reviewed and updated over the system's lifecycle. The program must take into consideration (1) the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized or AG-designated AI risk management framework, (2) the size and complexity of the deployer, (3) the nature and scope of the systems deployed, and (4) the sensitivity and volume of data processed. A single program may cover multiple systems. Subject to small-deployer exemption in § 10-16-6.
HI
Introduced
Deployers must implement and maintain a written, risk-based risk management program before and throughout deployment of any high-risk AI system, including (1) governance and accountability with designated responsible personnel, (2) documented policies covering the full AI lifecycle, (3) data governance controls, (4) pre-deployment testing and ongoing monitoring for errors, drift, and discrimination, (5) vendor and third-party risk controls, and (6) recordkeeping sufficient to demonstrate compliance.
IA
Introduced
Deployers must implement an iterative risk management policy and program governing their use of high-risk AI systems, specifying the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks. The program must consider NIST AI RMF, ISO/IEC 42001, or other recognized frameworks and attorney general-designated standards, and must be regularly and systematically reviewed and updated for the duration of the deployer's use of high-risk AI systems.
IL
Introduced
Persons or entities that use predictive data analytics to determine creditworthiness of more than 50 Illinois-resident consumers per calendar year must devise procedures within 90 days of the effective date to ensure they do not consider information that assigns specific risk factors to a consumer's race or zip code when rejecting or taking adverse action on credit applications.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers must describe in their published safety plan how they incorporate national, international, and industry-consensus standards; how and when they update the plan (including criteria for triggering updates upon substantial model modifications); how they identify and respond to safety incidents; and how they institute internal governance practices to ensure plan implementation.
IL
Introduced
Deployers earn a rebuttable presumption of non-defectiveness by designing and implementing a risk management policy that (1) specifies principles, processes, and personnel for identifying, mitigating, and documenting foreseeable risks (especially to users under 17); (2) is consistent with NIST AI RMF; (3) is reasonable given the deployer's size, the system's scope and inputs, and modifications made by the deployer; and (4) is electronically available to employees and to the Attorney General upon request.
IL
Introduced
Deployers may earn a rebuttable presumption of non-defectiveness by designing and implementing a risk management policy that (1) specifies principles, processes, and personnel for identifying, mitigating, and documenting foreseeable risks — with particular attention to impacts on individuals under 17; (2) is consistent with NIST AI RMF; (3) is proportionate to the deployer's size, system scope, and data inputs; and (4) is electronically available to employees and the Attorney General on request.
KS
Introduced
Health insurers must establish written policies and procedures that (1) describe the process by which the health benefit plan prospectively, retrospectively, or concurrently reviews and approves, modifies and delays, or denies requests based in whole or in part on medical necessity, and (2) require that medical necessity decisions are consistent with criteria or guidelines supported by clinical principles and processes.
LA
Introduced
Chatbot providers must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of personal data and chat logs maintained, and must publish the program on their website.
LA
Introduced
Covered insurers must adopt written governance policies and procedures for the development, validation, deployment, monitoring, and retirement of algorithmic decision systems, addressing roles and responsibilities, pre-deployment disparate impact testing, ongoing monitoring, investigation and remediation procedures, documentation, and escalation.
MA
Introduced
Covered entities and service providers must establish, implement, and maintain reasonable privacy policies, practices, and procedures addressing applicable law, minor-specific risks, product lifecycle privacy risks, data retention, and employee training — scaled proportionally to entity size, data sensitivity, data volume, number of individuals affected, and implementation costs.
MA
Introduced
Deployers of high-risk AI systems must implement and maintain a risk management program that (1) identifies and mitigates known or foreseeable risks of algorithmic discrimination and (2) aligns with industry standards such as the NIST AI Risk Management Framework.
MA
Introduced
Deployers must implement a risk management policy and program governing their deployment of each high-risk AI system. The policy and program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. It must be iterative, planned, implemented, and regularly and systematically reviewed and updated over the system's life cycle. Reasonableness is assessed in light of the NIST AI RMF, ISO/IEC 42001, or an equivalent nationally or internationally recognized framework (or any AG-designated framework), the deployer's size and complexity, the nature and scope of deployed systems, and the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must implement a data governance framework that (1) certifies data sources for accuracy and relevance with at least monthly updates, (2) tracks data lineage and establishes quality control measures, and (3) includes minimum dataset size requirements — at least 1,000 data points for simple algorithms, 5,000 for complex algorithms, and 10,000 for highly complex models — to ensure statistical significance in algorithmic evaluations.
MD
MD HB 712 (AI Product Liability) § Md. Code, Cts. & Jud. Proc. § 3–2703
Introduced eff 2026-10-01
Deployers may establish a rebuttable presumption of non-defectiveness by implementing and adhering to a risk management policy that (1) specifies how the deployer will identify, document, and mitigate foreseeable risks, especially to minor users, (2) is consistent with industry best practices, (3) is reasonable in light of the deployer's size, complexity, the product's nature and scope, and the data the system processes, and (4) is electronically available to employees and to the Attorney General on request.
NY
Introduced
Deployers must implement and maintain a risk management policy and program governing deployment of high-risk AI decision systems. The policy and program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. Both must be iterative, regularly and systematically reviewed and updated over the system lifecycle. Reasonableness is assessed considering: (1) the latest NIST AI RMF, ISO/IEC 42001, or a substantially equivalent framework; (2) the deployer's size and complexity; (3) the nature and scope of deployed systems; and (4) the sensitivity and volume of data processed. A single policy and program may cover multiple high-risk systems.
NY
Introduced
Developers of general-purpose AI models that are exempt from technical documentation requirements because the model is not offered for sale, not intended to interact with consumers, and solely used for internal purposes must nonetheless establish and maintain an AI risk management framework. The framework must be iterative and ongoing, and must include at minimum: (1) an internal governance function; (2) a map function establishing context to frame risks; (3) a risk management function; and (4) a measurement function to assess, analyze, and track identified risks. The developer bears the burden of demonstrating qualification for the exemption.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 112
Introduced
Covered developers and deployers must plan, document, and implement an iterative risk management policy and program — reasonable against the NIST AI RMF v1.0 or ISO 42001 — that identifies, documents, and mitigates foreseeable risks of algorithmic discrimination across the high-risk AI system's life cycle, with regular review and updates.
NY
Introduced
Deployers must implement and maintain a risk management policy and program governing deployment of each high-risk AI decision system. The policy and program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. Both must be iterative, planned, implemented, and regularly and systematically reviewed and updated over the system's lifecycle. Reasonableness is assessed considering (1) alignment with the NIST AI RMF, ISO/IEC 42001, or a substantially equivalent framework; (2) the deployer's size and complexity; (3) the nature and scope of the deployed systems; and (4) the sensitivity and volume of data processed. A single risk management policy and program may cover multiple high-risk AI decision systems.
NY
Introduced
Developers of general-purpose AI models must create and maintain technical documentation covering: (1) training and testing processes; (2) evaluation results demonstrating article compliance; (3) as appropriate given size and risk profile — intended tasks, types of downstream AI systems the model is designed for, acceptable use policies, release date, distribution methods, and input/output modalities and formats. Documentation must be reviewed and revised at least annually or more frequently as necessary for accuracy. Developers must also create, implement, maintain, and make available to downstream integrators documentation enabling them to understand the model's capabilities and limitations, comply with the article, and integrate the model, including the technical means for integration and the information listed above. Integrator documentation must also be reviewed and revised at least annually.
NY
Introduced
Developers of general-purpose AI models used solely for internal purposes (not offered for sale and not intended to interact with consumers) are exempt from the full technical documentation and annual-review requirements of subdivision 1, but must establish and maintain an AI risk management framework that includes: (1) an internal governance function; (2) a risk-mapping function establishing context to frame risks; (3) a risk management function; and (4) a risk-measurement function assessing, analyzing, and tracking identified risks. The framework must be the product of an iterative process and ongoing efforts. The developer bears the burden of demonstrating eligibility for the exemption.
NY
Introduced
Deployers and developers must establish, document, implement, and maintain an AI governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern foreseeable discrimination risk associated with their AEDTs, scaled to the entity's role, size, complexity, resources, and the technical feasibility and cost of available tools.
OH
Introduced
Any person or entity that operates an AI system controlling a critical infrastructure facility must implement a risk management policy conforming to the NIST AI RMF, ISO/IEC 42001 (or equivalent recognized standard), and all applicable federal regulations, before or within a reasonable period after deployment. This requirement does not apply to AI systems performing only nonexecutive procedural tasks, implementing only human-made decisions, or functioning exclusively as antivirus, antimalware, or cybersecurity tools.
OK
Introduced eff 2025-11-01
Deployers must implement and maintain a Quality Assurance Program to ensure the safe, effective, and compliant use of AI devices in patient care, as further specified in Section 5504 of this act.
PA
Introduced
Suppliers must develop, implement, and maintain a written disclosure policy for each chatbot containing the specific disclosures required by subsection (c). The supplier must protect any trade secret or other proprietary information regarding the chatbot when complying with this requirement.
PA
Introduced
Suppliers must comply with all requirements of the disclosure policy filed with the Bureau of Consumer Protection. The filed policy becomes a binding operational standard — failure to follow the supplier's own filed procedures is itself a violation of this chapter.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must implement and maintain an iterative risk management policy and program covering principles, processes, and personnel for identifying, documenting, and mitigating algorithmic discrimination risks, conforming to NIST AI RMF, ISO/IEC 42001, or an equivalent framework, and regularly reviewed and updated over the system lifecycle.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-6
Introduced eff 2025-10-01
Developers of general-purpose AI models must create and maintain technical documentation covering training and testing processes, intended tasks, integration targets, acceptable use policies, release date, distribution methods, input/output modalities, and a detailed training data description including data type and provenance, curation methodologies, selection methods, unsuitable data source identification, and bias detection methods. Documentation must be reviewed and revised at least annually.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-6
Introduced eff 2025-10-01
Developers exempt from technical documentation requirements (open-source, internal-use, or internal-management models) must still establish and maintain an AI risk management framework that includes an internal governance function, a risk-context mapping function, a risk management function, and a risk measurement and tracking function.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of personal data and chat logs maintained. The program must be made publicly available on the chatbot provider's website.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(E)
Introduced
School entities must adopt policies governing student use of generative AI for coursework and must ensure students do not use generative AI to complete graded assignments unless expressly authorized by a teacher for a defined instructional purpose.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of personal data and chat logs maintained. The written program must be made publicly available on the chatbot provider's website.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must implement a risk management policy and program governing deployment of each high-risk AI system. The program must specify and incorporate the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative, regularly and systematically reviewed, and updated over the life cycle of the system. Reasonableness is assessed by reference to the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized or AG-designated risk management framework, the deployer's size and complexity, the nature and scope of deployed systems, and the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems. Small deployers with fewer than 50 employees that do not train the system on their own data are exempt if other conditions in subsection (F) are met.
TX
TX HB 5496 (AI Transparency) § Bus. & Com. Code § 611.002
Introduced eff 2025-09-01
Persons using AI in conducting business or providing goods or services to Texas residents must implement and maintain standards representing the best practices of the artificial intelligence industry.
TX
TX SB 2966 (AI Consequential Decisions Framework) § Bus. & Com. Code § 551.002
Introduced eff 2025-09-01
Private companies that use an AI system to make a consequential decision must establish a framework governing the use of that system to ensure consumer protection.
US
Introduced
Covered entities must meaningfully consult with internal stakeholders (employees, ethics teams, responsible technology teams) and independent external stakeholders (impacted group representatives, civil society, technology experts) when performing impact assessments, including through participatory design, independent auditing, or soliciting and incorporating feedback.
US
Introduced
Covered entities must provide ongoing training and education to all relevant employees, contractors, and agents on documented material negative impacts from similar covered algorithms and improved impact assessment methods based on industry best practices.
US
Introduced
Employers must train all individuals and entities that operate or use ADS outputs on the system's inputs, appeals process, potential biases, limitations, potential adverse effects on covered individuals, potential errors, and examples of inappropriate uses.
US
Introduced
Covered entities must describe their efforts to align each foundation model with the NIST AI Risk Management Framework (or a successor framework), a similar Federal Government-approved consensus technical standard, or the covered entity's own model specification including intended behavior, outcomes, and guardrails.
VA
VA HB 1170 (Law Enforcement AI Policy) § Va. Code § 15.2-1723.3
Introduced
Each local law-enforcement agency and sheriff's department must establish and adopt a written policy for the use of covered AI systems that meets or exceeds the DCJS model policy and must publish the policy on its website.
VA
Introduced
The Department of State Police must establish and adopt a written policy for the use of covered AI systems by State Police officers that meets or exceeds the DCJS model policy and must publish the policy on its website.
VT
Introduced eff 2025-07-01
Each developer or deployer must plan, document, and implement a risk management policy and program governing the development or deployment of automated decision systems used in consequential decisions. The program must specify and incorporate the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative, regularly and systematically reviewed and updated over the system's lifecycle, with documentation updates. Reasonableness is assessed against: (1) the NIST AI RMF version 1.0 (or a later version if the Attorney General determines it is at least as stringent); (2) the size and complexity of the entity; (3) the nature, scope, and intended uses of the system; and (4) the sensitivity and volume of data processed. A single program may cover multiple systems. The Attorney General may require disclosure in a prescribed form and evaluate the program for compliance.
VT
VT HB 341 (AI Safety Standards) § 9 V.S.A. § 4193g
Introduced eff 2025-07-01
Deployers must not deploy any inherently dangerous AI system or any AI system creating reasonably foreseeable risks unless the deployer has designed and implemented a risk management policy and program for the system. The policy must specify the principles, processes, and personnel used to identify, mitigate, and document foreseeable risks. The program must be at least as stringent as the latest NIST AI RMF and must be reasonable considering the deployer's size and complexity, the system's nature, scope, intended and unintended uses, deployer modifications, and the data the system processes as inputs.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of the personal data and chat logs maintained. The program must be made publicly available on the chatbot provider's website.
VT
VT HB 792 (AI Products Liability) § 9 V.S.A. § 4193d
Introduced eff 2026-07-01
Deployers seeking the safe-harbor presumption of non-defectiveness must design and implement a risk management policy that specifies principles, processes, and personnel for identifying, mitigating, and documenting foreseeable risks (with emphasis on risks to minors), is consistent with industry best practices, is proportionate to the deployer's size and the system's nature, and is electronically available to employees and to the Attorney General upon request.
WA
Introduced eff 2027-01-01
Deployers must design and implement a risk management policy and program for each high-risk AI system before deploying or using it to make a consequential decision. The risk management policy must specify the principles, processes, and personnel the deployer uses to identify, mitigate, and document any reasonably foreseeable risk of algorithmic discrimination. A policy and program aligned with the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized AI risk management framework with substantially equivalent or more stringent requirements is presumed to be in conformity with this section's requirements.
WA
Introduced eff 2026-07-01
Deployers must implement and maintain a risk management policy and program governing the deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must include an iterative process that is planned, implemented, and regularly and systematically reviewed and updated over the lifecycle of the system. The program must be reasonable considering the deployer's size and complexity, the nature and scope of deployed systems, the sensitivity and volume of data processed, and adherence to a recognized risk management framework such as the NIST AI RMF, ISO/IEC 42001, or a framework designated by the attorney general. A single program may cover multiple high-risk AI systems.
WA
Introduced eff 2027-01-01
Deployers must not deploy or use a high-risk AI system to make a consequential decision unless the deployer has designed and implemented a risk management policy and program for that system. The risk management policy must specify the principles, processes, and personnel to identify, mitigate, and document any reasonably foreseeable risk of algorithmic discrimination. Conformity with the NIST AI RMF, ISO/IEC 42001, or an equivalent nationally or internationally recognized framework creates a rebuttable presumption of compliance.
WA
Introduced
Deployers must implement and maintain a risk management policy and program governing deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must include an iterative process that is planned, implemented, and regularly reviewed and updated over the system's lifecycle. The program's reasonableness is assessed based on the deployer's size and complexity, the nature and scope of deployed systems, the sensitivity and volume of data processed, and adherence to the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized AI risk management framework, or a framework designated by the attorney general. A single program may cover multiple high-risk AI systems.
WA
Introduced
Developers of high-risk AI systems with 50 or more full-time equivalent employees must implement and maintain a risk management policy and program governing deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must include an iterative, regularly reviewed process updated over the system's lifecycle. Reasonableness is assessed based on the developer's size, system scope, data sensitivity, and adherence to NIST AI RMF, ISO/IEC 42001, or an equivalent recognized framework. A developer that also serves as deployer is exempt from this section's documentation requirements unless the system is provided to an unaffiliated deployer.
AK
Failed
The Department of Administration must adopt regulations governing the development, procurement, implementation, use, and ongoing assessment of state agency AI systems for consequential decisions, including provisions ensuring pre-implementation impact assessments, non-discrimination safeguards, and ongoing system assessment.
AK
Failed
The Department of Administration must adopt regulations governing the development, procurement, implementation, use, and ongoing assessment of state agency generative AI systems for consequential decisions, including pre-implementation impact assessment requirements, anti-discrimination safeguards, ongoing assessment, and foreign adversary country designations.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable safeguards to manage algorithmic discrimination risks, proportionate to the tool's use and the entity's role and resources. The program must (1) designate at least one employee responsible for compliance oversight with authority to raise compliance concerns, (2) identify and implement anti-discrimination safeguards, (3) conduct annual comprehensive compliance reviews, (4) retain impact assessment results for five years after completion, and (5) adjust safeguards in light of material changes in technology, risk, or operations.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage algorithmic discrimination risks. The program must (1) designate at least one compliance employee with authority to raise compliance concerns and trigger prompt internal investigation, (2) identify and implement discrimination safeguards, (3) provide for required impact assessments, (4) conduct an annual comprehensive compliance review, (5) retain impact assessment results for two years, and (6) adjust safeguards in response to material changes in technology, risk, standards, or business operations.
CA
Failed
Covered deployers must develop, implement, and maintain a comprehensive written information security program containing administrative, technical, and physical safeguards appropriate to the deployer's size, scope, and type of business; available resources; volume of data stored; and the security and confidentiality needs of the personal information stored. The program must incorporate safeguards consistent with protections for personal information under all applicable state and federal laws and regulations.
CA
Failed
Covered deployers must identify and assess reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of records containing personal information, and establish a process for evaluating and improving the effectiveness of current safeguards, including: (1) ongoing employee and contractor education and training on proper use of security procedures and the importance of personal information security; (2) mandating employee compliance with program policies and procedures; (3) providing a means for detecting and preventing security system failures; (4) security policies for storage, access, and transportation of personal information records outside business premises; (5) disciplinary measures for program violations; (6) measures preventing terminated employees from accessing personal information records; (7) reasonable restrictions on physical access to personal information records including locked storage; and (8) regular monitoring to ensure the program prevents unauthorized access or use, with information safeguard upgrades as necessary.
CA
Failed
Covered deployers must maintain policies for the supervision of third-party service providers that include: (1) taking reasonable steps to select and retain service providers capable of maintaining appropriate security measures for personal information consistent with applicable law, and (2) requiring service providers by contract to implement and maintain appropriate security measures for personal information.
CA
Failed
Covered deployers must, to the extent feasible, implement technical computer system security measures including: (1) secure user authentication protocols with login credential controls, reasonably secure password or unique identifier methods, password security controls, restriction to active users and accounts, and account lockout after multiple failed access attempts; (2) secure access controls restricting personal information access to employees and contractors who need it and assigning unique identification and passwords; (3) encryption of personal information transmitted across public networks, wirelessly, or stored on laptops and portable devices; (4) reasonable monitoring for unauthorized use of or access to personal information; (5) reasonably current firewall protection and operating system security patches for internet-connected systems; and (6) reasonably current system security agent software with malware protection, patches, and virus definitions set to receive regular updates.
CO
Failed
Deployers must implement and maintain an iterative risk management policy and program that specifies the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must regularly and systematically review and update the program over the AI system's life cycle.
CO
Failed
Deployers must implement and maintain a risk management policy and program specifying the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks, with regular and systematic review and updates over the system's life cycle.
CO
Failed eff 2025-05-05
Deployers must implement and maintain an iterative risk management policy and program specifying the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, reviewed and updated regularly over the system's lifecycle. This obligation applies only to high-risk AI systems that are the principal basis of consequential decisions.
CO
Failed
Deployers must implement and maintain a risk management policy and program covering the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks. The program must be iterative and regularly reviewed and updated over the system's life cycle. Effective June 30, 2026.
CT
Failed
Deployers must implement and maintain an iterative risk management policy and program covering principles, processes, and personnel for identifying, documenting, and mitigating algorithmic discrimination risks, calibrated to NIST AI RMF, ISO/IEC 42001, or an equivalent framework and to the deployer's size, system scope, and data sensitivity.
CT
Failed
Developers of general-purpose AI models must create, maintain, and annually revise technical documentation covering training and testing processes, intended tasks, integration contexts, acceptable-use policies, release dates, distribution methods, input/output modalities, and detailed training data descriptions (type, provenance, curation methods, selection criteria, bias detection methods). Developers must also establish and maintain a copyright compliance policy.
GA
Failed
Law enforcement agencies must formally adopt facial recognition software in writing and establish standard operating procedures before conducting any facial recognition searches.
GA
Failed
Law enforcement agencies must ensure each facial recognition specialist has completed agency-approved training, assign each specialist a unique username and password, and restrict access to authorized persons only.
GA
Failed
Law enforcement agencies must establish policies providing for suspension or revocation of facial recognition software access for users who fail to comply with this Code section or other applicable law.
HI
Failed
The Chief Information Officer must develop and implement statewide technology standards, including standards and guidelines for the State's use of generative AI.
IL
Failed
Businesses with 10 or more employees that use AI systems must comply with the five AI governance principles — safety, transparency, accountability, fairness, and contestability — as implemented through rules adopted by the Department of Innovation and Technology. The Department must adopt rules to ensure businesses: (1) ensure AI systems operate without causing harm to individuals; (2) provide clear and understandable explanations of how AI systems work and make decisions; (3) identify and hold individuals or companies responsible for AI system performance and outcomes; (4) prevent and mitigate bias to ensure equitable treatment for all individuals; and (5) allow individuals to challenge and seek redress for decisions made by AI systems.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern the risks of algorithmic discrimination. The program must include discrimination safeguards, impact assessment procedures, an annual compliance review, two-year retention of impact assessment results, and ongoing adjustment of safeguards in light of material changes.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern reasonably foreseeable algorithmic discrimination risks associated with each automated decision tool. Safeguards must be proportionate to the tool's use, the deployer's role and size, the nature of the deployer's activities, and the technical feasibility and cost of available tools. The program must: (1) identify and implement safeguards for foreseeable discrimination risks; (2) support performance of impact assessments required by Section 10; (3) conduct an annual comprehensive compliance review; (4) retain impact assessment results for at least two years after completion; and (5) adapt safeguards in response to material changes in technology, risk, technical standards, or business operations. This obligation does not apply to deployers with fewer than 25 employees unless the tool impacted more than 999 people in the prior calendar year.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–802
Failed
The Office of the Attorney General, the Comptroller, and the State Treasurer must each establish policies and procedures functionally compatible with the Department's AI policies for the development, procurement, deployment, use, and ongoing assessment of high-risk AI systems by June 1, 2025.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–804
Failed
The Department of Information Technology must adopt, by December 1, 2024, policies and procedures governing the development, procurement, deployment, use, and ongoing assessment of high-risk AI by State agencies, including inventory criteria, adequate guardrails, notification and opt-out guidance for impacted individuals, and procurement guidance ensuring data privacy and legal compliance.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–806
Failed
The Governor's AI Subcabinet must develop AI strategy and monitoring processes, oversee AI inventories and impact assessments, ensure compliance with State AI policies, develop a comprehensive action plan, and build foundational AI infrastructure across State government.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5003
Failed
Deployers must implement a risk management policy governing deployment of each high-risk AI system that (1) identifies, documents, and mitigates algorithmic discrimination risks, (2) specifies principles, processes, and personnel, (3) spans the entire deployment period, and (4) is regularly and systematically reviewed and updated, drawing on the NIST AI RMF, ISO/IEC 42001, or an equivalent framework.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must implement a data governance framework that (1) certifies data sources for accuracy and relevance with at least monthly updates, (2) tracks data lineage and establishes quality control measures, and (3) meets minimum dataset size requirements — at least 1,000 data points per category for simple algorithms, 5,000 for more complex algorithms, and 10,000 for highly complex models or small-effect detection.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must maintain a contingency plan for system failures or data breaches that could compromise algorithmic integrity.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-508
Failed
Law enforcement agencies using facial recognition technology must adopt and maintain a use and data management policy and post a copy of the policy on the agency's public website.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–508
Failed
Law enforcement agencies that use facial recognition technology must adopt and maintain a use and data management policy and post the policy on the agency's public website.
MT
Failed
State or local government agencies must adopt and provide a written use and privacy policy before using facial verification, covering the specific purpose, data retention period, and consent requirements. Third-party vendors must provide a copy of their written policies to the contracting agency.
MT
Failed
Third-party vendors must provide contracting government agencies with a written privacy policy that is easy to read and understandable to an average consumer, includes the date of last update, and must notify the agency of privacy policy changes within a reasonable period.
MT
Failed
Third-party vendors must develop a written information security policy with administrative, technical, and physical controls to protect the confidentiality, integrity, and availability of facial biometric data. Data must be stored within the United States. Vendors must protect data using at least the industry standard of care and at least as protectively as they protect other personal information, and may not release data to government agencies without a valid warrant or court order.
MT
Failed
State or local government agencies that use facial recognition technology without a third-party vendor must develop the same written privacy and retention policies required of third-party vendors and must adhere to the same retention, destruction, and privacy provisions.
MT
Failed
Government agencies operating facial recognition services without a third-party vendor must establish a policy that ensures best-quality results by following the developer's guidance and that outlines a training protocol for all operators and data processors, covering the service's capabilities and limitations, output-interpretation procedures, and the meaningful human review requirement for decisions with legal effects.
NE
Failed
Deployers must implement a risk management policy and program to govern their deployment of each high-risk AI system. A single policy may cover multiple high-risk systems. Systems conforming to the NIST AI Risk Management Framework or ISO/IEC 42001 as of January 1, 2025, are presumed to satisfy this requirement.
NM
Failed
Deployers must implement a risk management policy and program that specifies principles, processes, and personnel for identifying, documenting, and mitigating algorithmic discrimination risks, must be iterative and regularly updated over the system lifecycle, and must meet standards established by DOJ rule.
NV
Failed eff 2026-01-01
Insurers must adopt practices designed to ensure that their use of AI systems does not result in unfair or deceptive trade practices in violation of NRS 686A.010–686A.310.
NV
Failed eff 2026-01-01
Insurers must develop, implement, and maintain a written plan for responsible AI use that includes a plan for acquiring, using, or relying upon third-party AI systems, covering contractual cooperation with regulatory inquiries and audit rights to confirm third-party compliance.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 416
Failed
Operators must establish an independent ethics and risk management board of at least five members — none of whom may be a member, officer, or director of the operator — to assess the ethical implications and operational outcomes of all use cases of each licensed high-risk AI system.
NY
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage foreseeable discrimination risks, scaled to the entity's role, size, and resources. The program must at minimum (1) identify and implement discrimination safeguards, (2) conduct annual comprehensive compliance reviews, (3) retain impact assessment results for two years, and (4) adjust safeguards in response to material changes in technology or business operations.
OK
Failed
Deployers must classify each AI system into one of the four risk categories (unacceptable, high, limited, or minimal) before deployment.
OK
Failed
Companies that include Oklahoma citizens' personally identifiable information in an AI model must implement reasonable security measures for data privacy within their industry and conduct regular risk assessments addressing design, operational, and discrimination harm.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-5
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern the reasonably foreseeable risks of algorithmic discrimination associated with their automated decision tools, proportionate to the tool's use, the entity's role, size, complexity, resources, and technical feasibility.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must implement and maintain a risk management program establishing policies, processes, and personnel for identifying, mitigating, and documenting risks from CAIDS deployment, calibrated to the deployer's size, system scope, data sensitivity, and implementation cost.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must implement and maintain a risk management program establishing policies, processes, training procedures, and personnel for identifying, mitigating, and documenting risks from CAIDS development, calibrated to the developer's size, system scope, training data sensitivity, and implementation cost.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must implement and maintain a risk management program establishing policies, processes, and personnel to identify, mitigate, and document risks arising from deployment of a CAIDS, scaled to the deployer's size, the system's nature and scope, data sensitivity, and implementation cost.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must implement and maintain a risk management program establishing policies, processes, training procedures, and personnel to identify, mitigate, and document risks arising from development of a CAIDS, scaled to the developer's size, the system's nature and scope, training data sensitivity, and implementation cost.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.008
Failed
Developers and deployers must, prior to deployment, assess potential algorithmic discrimination risks and implement a risk management policy that identifies, documents, and mitigates discrimination risks and Subchapter B prohibited uses, calibrated to the NIST AI RMF GenAI Profile, the entity's size and complexity, the system's scope and intended use, and the sensitivity of personal data processed.
US
Failed
Agencies responsible for maintaining and operating arrest photo databases must establish procedures to ensure compliance with database purging requirements.
US
Failed
Each covered agency must establish and publicly post on its website within 90 days of enactment a policy governing its use of facial recognition systems to ensure officer compliance with the Act.
US
Failed
Covered entities must meaningfully consult with internal stakeholders (employees, ethics teams, responsible technology teams) and independent external stakeholders (impacted community representatives, civil society advocates, technology experts) when performing impact assessments, including through participatory design, independent auditing, or soliciting feedback.
US
Failed
Covered entities must support and perform ongoing training and education for all relevant employees, contractors, and agents regarding documented material negative impacts from similar automated decision systems and improved methods of performing impact assessments.
US
Failed
Covered entities must disclose their efforts to align the foundation model with the NIST AI Risk Management Framework or a similar Federal Government-approved consensus technical standard, as specified in FTC regulations.
US
Failed
The Director of OMB must issue guidance requiring all federal agencies to incorporate the NIST AI Risk Management Framework and NIST-issued guidelines into their AI risk management efforts, within 180 days of NIST issuing guidelines under subsection (b)(2).
US
Failed
NIST must, within one year of enactment, issue guidance for agencies to incorporate the AI Risk Management Framework, including standards for AI development, procurement, and use; cybersecurity strategies; supplier attestation standards; training recommendations; minimum profile requirements; and small business profiles.
US
Failed
The Director of OMB must provide a template for agency use on the OMB guidance that includes recommended procedures for implementation of the AI Risk Management Framework.
US
Failed
Each agency head must conform all policies, principles, practices, procedures, and guidelines governing the design, development, implementation, deployment, use, or evaluation of AI systems to the NIST AI Risk Management Framework and OMB guidance.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3593
Failed
The OMB Director must develop, issue, and periodically update government-wide policies, standards, and guidance governing the use of federal AI systems, including procurement policies, data protection, anti-discrimination best practices, training data identification, periodic system evaluations, and AI governance charter requirements, consistent with NIST standards.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must comply with the subchapter and OMB guidance, integrate AI management processes with agency strategic and budgetary planning, and ensure senior officials — including the CIO, Chief Data Officer, and senior privacy official — implement AI risk-reduction policies and periodically validate management controls.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must conduct regular training programs on federal AI system management and compliance for relevant agency officials, including those supporting CIO, Chief Data Officer, Evaluation Officer, and privacy official functions.
US
Failed
The OMB Director must issue implementing guidance within one year of enactment, in consultation with NIST, GSA, and OSTP, and must review and update the guidance biennially for the first ten years and periodically thereafter.
US
Failed
Each agency head must ensure responsible AI research, development, acquisition, application, governance, and use consistent with democratic values including privacy, civil rights, civil liberties, information security, nondiscrimination, transparency, and reliability.
US
Failed
Each agency head must hire or designate a Chief Artificial Intelligence Officer at the senior executive level (above GS-15) responsible for AI policy development, governmentwide compliance, risk management planning (including risk-level classification), rights-protective design and deployment, and participation in budget and acquisition decision processes.
US
Failed
The OMB Director must issue guidance within 120 days directing each CFO Act agency to establish an internal AI Governance Board — chaired by the CAIO and including designated senior officials (deputy head, CIO, chief acquisition officer, chief data officer, senior privacy official, civil rights official, and others) — to coordinate and govern the agency's AI issues.
US
Failed
Each agency head must establish an AI strategy for trustworthy AI adoption that includes (1) defined roles and responsibilities, (2) values and ethics principles, (3) trust and safety standards, (4) risk identification and mitigation processes, (5) algorithmic discrimination safeguards, (6) current and anticipated AI use domains, (7) workforce development steps, (8) conditions for public-facing AI use, (9) internal coordination processes, (10) interagency governance, (11) data governance, (12) procurement safeguards for rights and safety, and (13) specific implementation actions and desired outcomes.
US
Failed
The Director of OMB must, when updating AI guidance under the AI in Government Act of 2020, consider the NSCAI's recommended practices, Executive Order 13960 principles, input from the Privacy and Civil Liberties Oversight Board, relevant interagency councils, and external privacy and civil rights experts.
US
Failed
Critical-impact AI organizations must perform a documented TEVV-based risk management assessment no later than 30 days before making a critical-impact AI system publicly available, and biennially thereafter. The assessment must cover (1) organizational AI risk management policies and processes, (2) the system's structure, context, and capabilities, (3) quantitative and qualitative risk measurement methods and metrics, and (4) risk resource allocation and monitoring. Assessment reports must be submitted to the Secretary of Commerce within 90 days of completion in a format the Secretary determines.
US
US S 3554 (Financial AI Risk Reduction) § Sec. 7 / proposed 15 U.S.C. § 78a (Sec. 42)
Failed
Persons deploying AI models in securities contexts must establish, maintain, and enforce written policies and procedures reasonably designed to prevent violations of federal securities laws by those models, or face strict liability for all acts, practices, and conduct of the model as if the person had committed them directly.
UT
UT HB 452 (Mental Health Chatbots) § Utah Code § 58-60-118
Failed
Suppliers seeking the affirmative defense to unlicensed-practice liability must create, maintain, and implement a written policy that states the chatbot's intended purpose and limitations, and describes procedures for (1) involving licensed mental health therapists in development and review, (2) ensuring consistency with clinical best practices, (3) conducting pre-deployment and ongoing testing to ensure output poses no greater risk than therapy with a licensed therapist, (4) identifying foreseeable adverse outcomes, (5) providing a user harm-reporting mechanism, (6) implementing risk-assessment and response protocols, (7) responding in real time to acute risk of physical harm, (8) ensuring regular objective reviews of safety, accuracy, and efficacy, (9) providing safe-use instructions, (10) ensuring users understand they are interacting with AI, (11) ensuring users understand purpose, capabilities, and limitations, (12) prioritizing user safety over engagement metrics or profit, (13) implementing anti-discrimination measures, and (14) ensuring HIPAA-equivalent security and privacy compliance. Suppliers must also maintain documentation describing foundation models, training data, HIPAA compliance, data practices, and ongoing accuracy/safety efforts, and must comply with the filed policy at the time of any alleged violation.
UT
UT SB 180 (Law Enforcement AI Usage) § Utah Code § 53-25-602
Failed
Law enforcement agencies must adopt a written policy governing employee use of generative AI that specifies which technologies and tasks are permitted, emphasizes the importance of reviewing AI-generated content, and warns that violations may result in administrative discipline.
UT
UT SB 205 (Law Enforcement AI) § Utah Code § 53-25-902
Failed eff 2026-05-06
Law enforcement agencies must adopt and maintain a written policy governing employee use of generative AI and AI technology, covering authorized tools and settings, permissible uses, the importance of human review, and disciplinary consequences for violations.
VA
VA HB 249 (Law Enforcement AI Use) § Va. Code § 9.1-102(66)
Failed
The Department of Criminal Justice Services must establish a comprehensive framework — including formal policies and procedures — governing law-enforcement use of generative AI and machine learning systems in preparing legal instruments and public records, generating or acquiring evidence for legal proceedings or interrogations, and processing surveillance information.
VA
VA HB 249 (Law Enforcement AI Use) § Enactment Clause § 2
Failed
All criminal justice agencies in Virginia must adopt a policy for the use of generative AI and machine learning systems consistent with the model policy published by DCJS by July 1, 2025.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-605
Failed
Deployers must design and implement a risk management policy and program — at least as stringent as the NIST AI RMF or another nationally or internationally recognized framework — specifying the principles, processes, and personnel used to identify, mitigate, and document algorithmic discrimination risks. The program must be reasonable considering the deployer's size, system scope, data sensitivity, and implementation cost.
VT
Failed
Deployers must design, implement, and maintain a risk management policy and program for each high-risk AI system that is at least as stringent as the NIST AI RMF or another nationally or internationally recognized AI risk management framework, and is reasonable considering the deployer's size, the system's scope and data sensitivity, and the cost of implementation.
VT
Failed
Deployers must not deploy an inherently dangerous AI system or a system creating foreseeable risks under § 2495e unless they have designed, implemented, and maintained a risk management policy and program that specifies principles, processes, and personnel for identifying, mitigating, and documenting foreseeable deployment risks. The program must be at least as stringent as the NIST AI RMF and reasonable given the deployer's size, the system's scope, and the data it processes.
WA
Failed
Public agencies already using an automated decision system at the effective date must comply with all provisions and procedures in this chapter by January 1, 2023, or immediately cease use of the system until compliance is achieved.
WA
Failed
The Office of Privacy and Data Protection must develop guidelines for state agency use of artificial intelligence to ensure ethical, transparent, accountable, and responsible implementation and protection of personally identifiable information.
G-01.2
Ongoing program maintenance and update
Developers and/or deployers must review and update the AI risk-management program periodically and after material changes to the AI systems in scope or to the regulatory environment.
Enacted
5
Live
28
Failed
28
Total
61
CO
Enacted eff 2026-05-14
Developers must provide each deployer of a covered ADMT with notice of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation within a reasonable time. Public release notes containing the required information satisfy this obligation if the developer also provides direct notice of the public release to each deployer.
CO
Enacted eff 2026-02-01
Deployers must implement and maintain a risk management policy and program governing deployment of each high-risk AI system, specifying the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks. The program must be iteratively reviewed and updated over the system's life cycle and must be reasonable considering NIST AI RMF, ISO/IEC 42001, or an AG-designated framework, as well as the deployer's size, system scope, and data sensitivity.
CO
Enacted eff 2026-02-01
Deployers must implement a risk management policy and program governing their deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. It must be iterative — planned, implemented, and regularly and systematically reviewed and updated over the life cycle of the system. Reasonableness is assessed considering: the NIST AI RMF, ISO/IEC 42001, or another recognized framework (or any AG-designated framework); the deployer's size and complexity; the nature and scope of systems deployed; and the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Enacted eff 2024-10-01
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, United States Attorneys, or their designees.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–806
Enacted eff 2024-07-01
The Governor's AI Subcabinet must develop strategy and monitoring processes for responsible AI use, oversee the statewide AI inventory and impact assessments, monitor high-risk AI, ensure compliance with State AI policies, develop and implement a comprehensive action plan, and support AI innovation, workforce skills, and foundational infrastructure across State government.
NY
Engrossed
Each developer and deployer of high-risk AI systems must plan, document, and implement a risk management policy and program governing the development or deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative, with regular and systematic review and updates over the system's life cycle, including updates to documentation. Reasonableness is assessed considering: (1) the NIST AI RMF v1.0 or a substantially equivalent framework selected by the attorney general; (2) the entity's size and complexity; (3) the nature, scope, and intended uses of the system; and (4) the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems if sufficient.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5518
Engrossed eff 2026-07-01
Developers must update all required disclosures within 90 days after performing an intentional and substantial modification to any high-risk AI system to ensure the disclosures remain accurate.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must update all required disclosures within 90 days after the developer performs an intentional and substantial modification to any high-risk AI system to ensure the disclosures remain accurate.
GA
Introduced
Deployers must implement a risk management policy and program governing deployment of each automated decision system. The program must specify the principles, processes, and personnel the deployer uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative — planned, implemented, and regularly and systematically reviewed and updated over the system's lifecycle. The program must take into consideration (1) the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized or AG-designated AI risk management framework, (2) the size and complexity of the deployer, (3) the nature and scope of the systems deployed, and (4) the sensitivity and volume of data processed. A single program may cover multiple systems. Subject to small-deployer exemption in § 10-16-6.
IA
Introduced
Deployers must implement an iterative risk management policy and program governing their use of high-risk AI systems, specifying the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks. The program must consider NIST AI RMF, ISO/IEC 42001, or other recognized frameworks and attorney general-designated standards, and must be regularly and systematically reviewed and updated for the duration of the deployer's use of high-risk AI systems.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers must describe in their published safety plan how they incorporate national, international, and industry-consensus standards; how and when they update the plan (including criteria for triggering updates upon substantial model modifications); how they identify and respond to safety incidents; and how they institute internal governance practices to ensure plan implementation.
MA
Introduced
Deployers must implement a risk management policy and program governing their deployment of each high-risk AI system. The policy and program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. It must be iterative, planned, implemented, and regularly and systematically reviewed and updated over the system's life cycle. Reasonableness is assessed in light of the NIST AI RMF, ISO/IEC 42001, or an equivalent nationally or internationally recognized framework (or any AG-designated framework), the deployer's size and complexity, the nature and scope of deployed systems, and the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must conduct an annual review of the safety and security protocol to account for changes to the covered model's capabilities and industry best practices, and must modify the protocol as necessary.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must annually reevaluate all procedures, policies, protections, capabilities, and safeguards implemented under this section.
MN
MN HF 4532 (RAISE Act) § Minn. Stat. § 325M.41
Introduced
Developers must conduct an annual review of the safety and security protocol to account for changes to the AI model's capabilities and industry best practices, and must modify the protocol accordingly. If a material modification is made, the developer must republish the protocol with appropriate redactions and transmit a copy to the attorney general in the same manner required for the initial publication.
MN
Introduced
Developers must conduct an annual review of the safety and security protocol to account for changes to the AI model's capabilities and industry best practices, and must modify the protocol accordingly. If a material modification is made, the developer must republish the protocol in the same manner required for initial publication — conspicuous public publication with appropriate redactions and transmission to the attorney general.
NJ
Introduced
Large frontier developers must annually review and, as appropriate, update the technical and organizational protocols they use to assess and reduce catastrophic-harm risk.
NY
Introduced
Deployers must implement and maintain a risk management policy and program governing deployment of high-risk AI decision systems. The policy and program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. Both must be iterative, regularly and systematically reviewed and updated over the system lifecycle. Reasonableness is assessed considering: (1) the latest NIST AI RMF, ISO/IEC 42001, or a substantially equivalent framework; (2) the deployer's size and complexity; (3) the nature and scope of deployed systems; and (4) the sensitivity and volume of data processed. A single policy and program may cover multiple high-risk systems.
NY
Introduced
Developers of general-purpose AI models must: (1) create and maintain technical documentation covering training and testing processes, compliance evaluation results, intended tasks, target integration systems, acceptable use policies, release date, distribution methods, and input/output modalities and formats — reviewed and revised at least annually; and (2) create, implement, maintain, and make available to downstream integrators documentation that enables understanding of the model's capabilities and limitations, facilitates compliance with this article, discloses technical integration requirements and the information listed in (1), and is reviewed and revised at least annually. Trade secrets and legally protected information are exempt.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 112
Introduced
Covered developers and deployers must plan, document, and implement an iterative risk management policy and program — reasonable against the NIST AI RMF v1.0 or ISO 42001 — that identifies, documents, and mitigates foreseeable risks of algorithmic discrimination across the high-risk AI system's life cycle, with regular review and updates.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 110
Introduced
Developers and deployers must notify each affected individual prior to implementing any material change to the public disclosure, using direct electronic notification in each covered language. Developers and deployers must retain each previous version of the disclosure for at least 10 years after the last day on which the version was effective, publish each version on their website, and maintain a publicly available log describing the date and nature of each material change — sufficient for a reasonable individual to understand the material effect of each change.
NY
Introduced
Deployers must implement and maintain a risk management policy and program governing deployment of each high-risk AI decision system. The policy and program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. Both must be iterative, planned, implemented, and regularly and systematically reviewed and updated over the system's lifecycle. Reasonableness is assessed considering (1) alignment with the NIST AI RMF, ISO/IEC 42001, or a substantially equivalent framework; (2) the deployer's size and complexity; (3) the nature and scope of the deployed systems; and (4) the sensitivity and volume of data processed. A single risk management policy and program may cover multiple high-risk AI decision systems.
NY
Introduced
Developers of general-purpose AI models must create and maintain technical documentation covering: (1) training and testing processes; (2) evaluation results demonstrating article compliance; (3) as appropriate given size and risk profile — intended tasks, types of downstream AI systems the model is designed for, acceptable use policies, release date, distribution methods, and input/output modalities and formats. Documentation must be reviewed and revised at least annually or more frequently as necessary for accuracy. Developers must also create, implement, maintain, and make available to downstream integrators documentation enabling them to understand the model's capabilities and limitations, comply with the article, and integrate the model, including the technical means for integration and the information listed above. Integrator documentation must also be reviewed and revised at least annually.
NY
Introduced
Deployers and developers must, as part of their governance program: (1) identify and implement discrimination-risk safeguards, (2) conduct impact assessments per §§ 752–753, (3) perform annual comprehensive compliance reviews, (4) retain impact assessment results for at least two years, and (5) make reasonable adjustments to safeguards in light of material changes in technology, risk, standards, or business operations.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must implement and maintain an iterative risk management policy and program covering principles, processes, and personnel for identifying, documenting, and mitigating algorithmic discrimination risks, conforming to NIST AI RMF, ISO/IEC 42001, or an equivalent framework, and regularly reviewed and updated over the system lifecycle.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must implement a risk management policy and program governing deployment of each high-risk AI system. The program must specify and incorporate the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative, regularly and systematically reviewed, and updated over the life cycle of the system. Reasonableness is assessed by reference to the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized or AG-designated risk management framework, the deployer's size and complexity, the nature and scope of deployed systems, and the sensitivity and volume of data processed. A single program may cover multiple high-risk AI systems. Small deployers with fewer than 50 employees that do not train the system on their own data are exempt if other conditions in subsection (F) are met.
US
Introduced
Covered entities must review all findings and suggestions from the AI/CDSS committee and all other feedback from health care professionals on AI/CDSS technology and policies, including patterns of incorrect or biased outputs requiring frequent override.
VT
Introduced eff 2025-07-01
Each developer or deployer must plan, document, and implement a risk management policy and program governing the development or deployment of automated decision systems used in consequential decisions. The program must specify and incorporate the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative, regularly and systematically reviewed and updated over the system's lifecycle, with documentation updates. Reasonableness is assessed against: (1) the NIST AI RMF version 1.0 (or a later version if the Attorney General determines it is at least as stringent); (2) the size and complexity of the entity; (3) the nature, scope, and intended uses of the system; and (4) the sensitivity and volume of data processed. A single program may cover multiple systems. The Attorney General may require disclosure in a prescribed form and evaluate the program for compliance.
WA
Introduced eff 2026-07-01
Deployers must implement and maintain a risk management policy and program governing the deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must include an iterative process that is planned, implemented, and regularly and systematically reviewed and updated over the lifecycle of the system. The program must be reasonable considering the deployer's size and complexity, the nature and scope of deployed systems, the sensitivity and volume of data processed, and adherence to a recognized risk management framework such as the NIST AI RMF, ISO/IEC 42001, or a framework designated by the attorney general. A single program may cover multiple high-risk AI systems.
WA
Introduced eff 2027-01-01
Developers must, no later than 90 days after performing an intentional and substantial modification to a high-risk AI system, update all disclosures required by Section 2 as necessary to ensure they remain accurate.
WA
Introduced eff 2027-01-01
Deployers must, no later than 30 days after being notified by the developer that the developer has performed an intentional and substantial modification to a high-risk AI system, update all deployer disclosures required by Section 3 as necessary to ensure they remain accurate.
WA
Introduced
Deployers must implement and maintain a risk management policy and program governing deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must include an iterative process that is planned, implemented, and regularly reviewed and updated over the system's lifecycle. The program's reasonableness is assessed based on the deployer's size and complexity, the nature and scope of deployed systems, the sensitivity and volume of data processed, and adherence to the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized AI risk management framework, or a framework designated by the attorney general. A single program may cover multiple high-risk AI systems.
WA
Introduced
Developers of high-risk AI systems with 50 or more full-time equivalent employees must implement and maintain a risk management policy and program governing deployment of each high-risk AI system. The program must specify the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must include an iterative, regularly reviewed process updated over the system's lifecycle. Reasonableness is assessed based on the developer's size, system scope, data sensitivity, and adherence to NIST AI RMF, ISO/IEC 42001, or an equivalent recognized framework. A developer that also serves as deployer is exempt from this section's documentation requirements unless the system is provided to an unaffiliated deployer.
AK
Failed
The Department of Administration must adopt regulations governing the development, procurement, implementation, use, and ongoing assessment of state agency AI systems for consequential decisions, including provisions ensuring pre-implementation impact assessments, non-discrimination safeguards, and ongoing system assessment.
AK
Failed
The Department of Administration must adopt regulations governing the development, procurement, implementation, use, and ongoing assessment of state agency generative AI systems for consequential decisions, including pre-implementation impact assessment requirements, anti-discrimination safeguards, ongoing assessment, and foreign adversary country designations.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable safeguards to manage algorithmic discrimination risks, proportionate to the tool's use and the entity's role and resources. The program must (1) designate at least one employee responsible for compliance oversight with authority to raise compliance concerns, (2) identify and implement anti-discrimination safeguards, (3) conduct annual comprehensive compliance reviews, (4) retain impact assessment results for five years after completion, and (5) adjust safeguards in light of material changes in technology, risk, or operations.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage algorithmic discrimination risks. The program must (1) designate at least one compliance employee with authority to raise compliance concerns and trigger prompt internal investigation, (2) identify and implement discrimination safeguards, (3) provide for required impact assessments, (4) conduct an annual comprehensive compliance review, (5) retain impact assessment results for two years, and (6) adjust safeguards in response to material changes in technology, risk, standards, or business operations.
CA
Failed
Covered deployers must identify and assess reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of records containing personal information, and establish a process for evaluating and improving the effectiveness of current safeguards, including: (1) ongoing employee and contractor education and training on proper use of security procedures and the importance of personal information security; (2) mandating employee compliance with program policies and procedures; (3) providing a means for detecting and preventing security system failures; (4) security policies for storage, access, and transportation of personal information records outside business premises; (5) disciplinary measures for program violations; (6) measures preventing terminated employees from accessing personal information records; (7) reasonable restrictions on physical access to personal information records including locked storage; and (8) regular monitoring to ensure the program prevents unauthorized access or use, with information safeguard upgrades as necessary.
CA
Failed
Covered deployers must conduct regular reviews of the scope of the program's security measures at least annually and whenever there is a material change in business practices that may reasonably affect the security or integrity of records containing personal information.
CO
Failed
Deployers must implement and maintain an iterative risk management policy and program that specifies the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and must regularly and systematically review and update the program over the AI system's life cycle.
CO
Failed
Deployers must implement and maintain a risk management policy and program specifying the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks, with regular and systematic review and updates over the system's life cycle.
CO
Failed eff 2025-05-05
Deployers must implement and maintain an iterative risk management policy and program specifying the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination, reviewed and updated regularly over the system's lifecycle. This obligation applies only to high-risk AI systems that are the principal basis of consequential decisions.
CO
Failed
Deployers must implement and maintain a risk management policy and program covering the principles, processes, and personnel used to identify, document, and mitigate algorithmic discrimination risks. The program must be iterative and regularly reviewed and updated over the system's life cycle. Effective June 30, 2026.
CT
Failed
Deployers must implement and maintain an iterative risk management policy and program covering principles, processes, and personnel for identifying, documenting, and mitigating algorithmic discrimination risks, calibrated to NIST AI RMF, ISO/IEC 42001, or an equivalent framework and to the deployer's size, system scope, and data sensitivity.
GA
Failed
Law enforcement agencies must (1) conduct quarterly random-sample audits of authorized facial recognition users to verify proper documentation is being maintained, (2) conduct at least annual random-sample audits to verify procedural compliance and that the authorized-user list is current, and (3) document and retain all audit records for at least two calendar years.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern the risks of algorithmic discrimination. The program must include discrimination safeguards, impact assessment procedures, an annual compliance review, two-year retention of impact assessment results, and ongoing adjustment of safeguards in light of material changes.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern reasonably foreseeable algorithmic discrimination risks associated with each automated decision tool. Safeguards must be proportionate to the tool's use, the deployer's role and size, the nature of the deployer's activities, and the technical feasibility and cost of available tools. The program must: (1) identify and implement safeguards for foreseeable discrimination risks; (2) support performance of impact assessments required by Section 10; (3) conduct an annual comprehensive compliance review; (4) retain impact assessment results for at least two years after completion; and (5) adapt safeguards in response to material changes in technology, risk, technical standards, or business operations. This obligation does not apply to deployers with fewer than 25 employees unless the tool impacted more than 999 people in the prior calendar year.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–806
Failed
The Governor's AI Subcabinet must develop AI strategy and monitoring processes, oversee AI inventories and impact assessments, ensure compliance with State AI policies, develop a comprehensive action plan, and build foundational AI infrastructure across State government.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5003
Failed
Deployers must implement a risk management policy governing deployment of each high-risk AI system that (1) identifies, documents, and mitigates algorithmic discrimination risks, (2) specifies principles, processes, and personnel, (3) spans the entire deployment period, and (4) is regularly and systematically reviewed and updated, drawing on the NIST AI RMF, ISO/IEC 42001, or an equivalent framework.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–505
Failed
Law enforcement agencies must complete an annual compliance audit beginning October 1, 2023, retain all audit materials for at least three years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorney, U.S. Attorney, or their designees.
MT
Failed
Third-party vendors must provide contracting government agencies with a written privacy policy that is easy to read and understandable to an average consumer, includes the date of last update, and must notify the agency of privacy policy changes within a reasonable period.
NM
Failed
Deployers must implement a risk management policy and program that specifies principles, processes, and personnel for identifying, documenting, and mitigating algorithmic discrimination risks, must be iterative and regularly updated over the system lifecycle, and must meet standards established by DOJ rule.
NY
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage foreseeable discrimination risks, scaled to the entity's role, size, and resources. The program must at minimum (1) identify and implement discrimination safeguards, (2) conduct annual comprehensive compliance reviews, (3) retain impact assessment results for two years, and (4) adjust safeguards in response to material changes in technology or business operations.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-5
Failed
The governance program must (1) identify and implement algorithmic-discrimination safeguards, (2) integrate impact-assessment obligations, (3) conduct an annual comprehensive compliance review, (4) retain impact-assessment results for two years after completion, and (5) make reasonable adjustments to safeguards in response to material changes in technology, risk, technical standards, or business operations.
US
Failed
Each agency head must conform all policies, principles, practices, procedures, and guidelines governing the design, development, implementation, deployment, use, or evaluation of AI systems to the NIST AI Risk Management Framework and OMB guidance.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3593
Failed
The OMB Director must develop, issue, and periodically update government-wide policies, standards, and guidance governing the use of federal AI systems, including procurement policies, data protection, anti-discrimination best practices, training data identification, periodic system evaluations, and AI governance charter requirements, consistent with NIST standards.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must comply with the subchapter and OMB guidance, integrate AI management processes with agency strategic and budgetary planning, and ensure senior officials — including the CIO, Chief Data Officer, and senior privacy official — implement AI risk-reduction policies and periodically validate management controls.
US
Failed
The OMB Director must issue implementing guidance within one year of enactment, in consultation with NIST, GSA, and OSTP, and must review and update the guidance biennially for the first ten years and periodically thereafter.
US
Failed
The Director of OMB must, when updating AI guidance under the AI in Government Act of 2020, consider the NSCAI's recommended practices, Executive Order 13960 principles, input from the Privacy and Civil Liberties Oversight Board, relevant interagency councils, and external privacy and civil rights experts.
US
Failed
Critical-impact AI organizations must perform a documented TEVV-based risk management assessment no later than 30 days before making a critical-impact AI system publicly available, and biennially thereafter. The assessment must cover (1) organizational AI risk management policies and processes, (2) the system's structure, context, and capabilities, (3) quantitative and qualitative risk measurement methods and metrics, and (4) risk resource allocation and monitoring. Assessment reports must be submitted to the Secretary of Commerce within 90 days of completion in a format the Secretary determines.
UT
UT SB 205 (Law Enforcement AI) § Utah Code § 53-25-902
Failed eff 2026-05-06
Law enforcement agencies must adopt and maintain a written policy governing employee use of generative AI and AI technology, covering authorized tools and settings, permissible uses, the importance of human review, and disciplinary consequences for violations.
G-01.3
Record keeping and audit trail
Developers and/or deployers must contemporaneously create and retain documentation of AI system design decisions, training-data characteristics, bias-testing results, safety-evaluation results, and/or deployment parameters.
Enacted
9
Live
119
Failed
72
Total
200
CA
CA SB 53 (Frontier AI Transparency) § Bus. & Prof. Code § 22757.12
Enacted eff 2026-01-01
When frontier developers publish documents to comply with this chapter, they may redact information necessary to protect trade secrets, cybersecurity, public safety, national security, or to comply with federal or state law. If a redaction is made, the developer must describe the character and justification of each redaction in the published version of the document to the extent permitted, and must retain the unredacted information for five years.
CO
Enacted eff 2026-05-14
Developers must retain records reasonably necessary to demonstrate compliance with § 6-1-1702 for at least three years after the creation of each record (or longer if required by other law). Records include system version identifiers, changelogs, and documentation and notices of material updates provided to deployers.
CO
Enacted eff 2026-05-14
Deployers must retain records reasonably necessary to demonstrate compliance with Part 17 for at least three years after the date of each consequential decision (or longer if required by other law). Records may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes.
KY
KY SB 176 (Facial Recognition Technology) § KRS Chapter 61, Section 1(3)
Enacted eff 2022-04-08
The working group must create and make publicly available by January 1, 2024, a model policy for law enforcement use of facial recognition technology covering authorized uses (including a prohibition on identifying persons in constitutionally protected activities absent probable cause), personnel authorization, documentation of use, secondary-examiner confirmation of findings, data integrity and retention, data security and data-sharing, training, image-source requirements, audit records, and privacy protections for nudity.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Enacted eff 2024-10-01
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, United States Attorneys, or their designees.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–318
Enacted eff 2024-07-01
Each unit of State government must conduct an annual data inventory beginning December 1, 2024, identifying data necessary for operations or required by law, in a form prescribed by the Chief Data Officer, including notation of data used in artificial intelligence.
NY
Enacted eff 2025-12-19
Large developers must annually retain an independent third party to audit compliance with § 1421, beginning on the effective date of the article or 90 days after first qualifying as a large developer, whichever is later. The auditor must be granted access to unredacted materials and must produce a report including: (1) a detailed assessment of compliance steps; (2) identified instances of noncompliance and improvement recommendations; (3) assessment of internal controls, including designation and empowerment of senior personnel responsible for compliance; and (4) the lead auditor's certifying signature. The large developer must retain the unredacted report for deployment plus five years, conspicuously publish a redacted copy, transmit a redacted copy to DHSES, and grant DHSES or the attorney general access to the unredacted report upon request.
NY
Enacted eff 2027-01-01
Frontier developers that redact published documents for trade secret, cybersecurity, public safety, or national security reasons must describe the character and justification of each redaction in the published version and retain the unredacted information for five years.
VT
Enacted eff 2026-07-01
Suppliers of mental health chatbots must, to avail themselves of the affirmative defense against professional misconduct claims, create, maintain, and implement a comprehensive written policy that: states the chatbot's intended purposes, abilities, and limitations; ensures licensed mental health provider involvement in development and review; ensures clinical best practices compliance; describes pre-launch and ongoing testing procedures; identifies foreseeable adverse outcomes; provides user harm-reporting mechanisms; describes real-time risk response protocols; ensures regular safety, accuracy, and efficacy reviews (internal or external); provides safe-use instructions; ensures users understand they are interacting with AI and understand the chatbot's purpose, capabilities, and limitations; prioritizes user safety over engagement metrics; implements nondiscrimination measures; and ensures HIPAA-level privacy and security compliance. Suppliers must also maintain documentation describing foundation models, training tools, federal health privacy compliance, data practices, and ongoing accuracy and safety efforts.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must retain in unredacted form all performance evaluations, deployer documentation, auditor correspondence, and redaction records for as long as the developer deploys the covered ADS or makes it available to potential deployers, plus 10 years.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must retain in unredacted form all developer documentation, subject disclosures, correction requests, opt-out requests, appeal requests, auditor correspondence, and redaction records for as long as the deployer uses the covered ADS, plus 10 years.
CA
CA AB 1405 (AI Auditor Enrollment) § Gov. Code § 11549.84
Engrossed
Enrolled AI auditors must, after completing a covered audit, provide the auditee with an audit report containing (1) the scope and objectives of the audit, (2) audit results with supporting documentation, (3) steps to meet generally accepted industry standards, (4) steps to become compliant with state law, and (5) a signed and dated certification statement from each auditor.
CA
CA AB 1405 (AI Auditor Enrollment) § Gov. Code § 11549.84
Engrossed
Enrolled AI auditors must retain all documentation provided to auditees and documentation necessary to demonstrate the basis of audit results for at least 10 years.
CA
Engrossed
Developers must retain all documentation required by this title for the commercial life of the GenAI system or model plus 10 years.
CA
Engrossed
MROs must retain all documents related to their activities under this chapter for ten years.
NH
Engrossed eff 2027-01-01
Health carriers must maintain records identifying the use of artificial intelligence tools in claims processing and must make such records available to the Insurance Department upon audit.
RI
RI SB 13 (Health Insurer AI Transparency) § R.I. Gen. Laws § 27-83-3
Engrossed eff 2026-06-30
Insurers must maintain documentation of all AI decisions — including adverse benefit determinations where AI made or substantially influenced the determination — for at least five years.
VA
VA SB 586 (Health Carrier AI Disclosures) § Va. Code § 38.2-3407.15(B)(15)
Engrossed
Carriers must maintain documentation of AI decisions for at least three years.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of personal data and chat logs maintained. The program must be made publicly available on the chatbot provider's website.
CA
CA AB 1898 (Workplace AI Tools) § Lab. Code § 1601
Introduced
Employers must maintain an updated list of all workplace AI tools currently in use and provide that list to workers annually.
GA
Introduced
Deployers must establish and adhere to (1) written standards, policies, procedures, and protocols for the acquisition, use of, or reliance on automated decision systems developed by third-party developers, including reasonable contractual controls ensuring developer disclosures include all information necessary for the deployer to fulfill its obligations; (2) procedures for reporting incorrect information or evidence of algorithmic discrimination to the developer for investigation and mitigation; and (3) procedures to remediate and eliminate incorrect information from its automated decision systems.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-973
Introduced eff 2027-01-01
Covered entities must contemporaneously document each step of the compulsive-use risk-assessment process — including supporting experiments, evidence, and data — and retain the documentation for ten years, with all individual-consumer data de-identified and anonymized.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Monitoring; performance evaluation; record keeping)
Introduced eff 2028-07-01
Health care providers that use AI to make or substantially factor into consequential decisions must maintain: (A) an updated inventory of their AI systems; (B) documentation on the system design, intended use, and training data of the AI systems; (C) records of monitoring, performance evaluations, and oversight activities; and (D) documentation of findings and corrective actions taken to address deficiencies identified through monitoring or performance evaluations.
HI
Introduced
Deployers must implement and maintain a written, risk-based risk management program before and throughout deployment of any high-risk AI system, including (1) governance and accountability with designated responsible personnel, (2) documented policies covering the full AI lifecycle, (3) data governance controls, (4) pre-deployment testing and ongoing monitoring for errors, drift, and discrimination, (5) vendor and third-party risk controls, and (6) recordkeeping sufficient to demonstrate compliance.
HI
Introduced
Deployers must retain impact assessments and risk management program documentation for at least five years after the system is retired or materially modified, whichever is later, and must make them available to the Executive Director of the Office of Consumer Protection or the Attorney General upon request. Confidential commercial information is protected to the extent permitted by law.
HI
Introduced
Deployers must maintain documentation sufficient to identify the AI system used, the nature of the output relied upon, and the decision process whenever an AI system output is a substantial factor in an adverse action, and must retain records adequate to support required disclosures and meaningful human review.
IA
Introduced
Health carriers must maintain per-claim documentation for every claim downcoded by an automated adjudication system — showing the submitted code, the adjusted code, the reason for the downcode, and whether a clinical reviewer conducted a review — and retain it for at least five years from the claim payment date.
IA
Introduced
Employers must maintain an updated list of all automated decision systems currently in use to facilitate implementation of the chapter's notice and employee-rights requirements.
ID
ID HB 945 (AI Medical Services Act) § Idaho Code § 54-6006
Introduced eff 2026-07-01
AAASPs must maintain immutable production-version snapshots of every deployed algorithm — including weights, decision logic, and prompt-engineering instructions — retain them for two years to allow retrospective replay during Board audits, and must not alter or delete snapshots related to any matter under investigation.
IL
Introduced
Developers must record and retain for at least 5 years all specific tests and test results from critical risk assessments, with sufficient detail to allow qualified third parties to replicate the testing.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers may redact published documents for trade secrets, cybersecurity, public safety, national security, or legal compliance, but must describe the character and justification of each redaction in the published version and must retain unredacted information for 5 years.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor (with corporate compliance and foundation model safety expertise) to assess (1) compliance with the public safety plan and instances of noncompliance, (2) plan clarity, and (3) reasonableness of redactions and accuracy of published statements. The developer must grant the auditor full access to compliance materials, retain the audit report for 5 years, and make the unredacted report available to the Attorney General on request.
IL
Introduced
Frontier developers that redact published documents for trade secret, cybersecurity, public safety, or national security reasons must describe the character and justification of each redaction in the published version and retain the unredacted information for 5 years.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers that redact information from publicly published documents must describe the character and justification of each redaction in the published version and retain the unredacted information for 5 years.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor — employing individuals with corporate compliance and foundation model safety expertise — to assess compliance with the public safety plan, evaluate clarity of plan language, and review redactions and public statements for reasonableness and truthfulness. Developers must grant the auditor full access to compliance materials, retain audit reports for 5 years, and allow the Attorney General to inspect unredacted reports upon request.
IL
Introduced
Frontier developers must describe the character and justification of any redaction in published documents to the extent permitted by the redaction rationale, and must retain unredacted information for 5 years.
IL
Introduced
Registered professional nurses must document in the treatment record the AI system name, version, and a brief description of the AI's role whenever AI is used in direct patient care.
KS
Introduced
Health insurers must establish written policies and procedures that (1) describe the process by which the health benefit plan prospectively, retrospectively, or concurrently reviews and approves, modifies and delays, or denies requests based in whole or in part on medical necessity, and (2) require that medical necessity decisions are consistent with criteria or guidelines supported by clinical principles and processes.
LA
Introduced
Employers must maintain an updated list of all automated decision systems currently in use.
LA
Introduced
Covered insurers must adopt written governance policies and procedures for the development, validation, deployment, monitoring, and retirement of algorithmic decision systems, addressing roles and responsibilities, pre-deployment disparate impact testing, ongoing monitoring, investigation and remediation procedures, documentation, and escalation.
LA
Introduced eff 2027-01-01
Frontier developers that redact information from published documents must describe the character and justification of each redaction in the published version and must retain the unredacted information for five years.
MA
Introduced
Covered entities and service providers must publish a detailed, accessible, reasonably understandable privacy policy on their homepage covering data categories, processing purposes, third-party transfers, retention periods, individual rights, data security practices, and effective date. Material changes require advance notice to affected individuals and an opportunity to withdraw consent.
MA
Introduced
Large data holders must retain and publish prior privacy policy versions for at least 10 years with a public change log, and must provide a short-form notice of no more than 500 words. Entities collecting biometric data or precise geolocation information must each maintain a separate privacy policy for those data types.
MA
Introduced
Covered entities must engage service providers only under written contracts specifying processing instructions, data types, purposes, duration, and mutual obligations. Service providers must adhere to covered entity instructions, assist with individual rights requests, maintain security safeguards, allow compliance assessments, delete or return data upon termination, and retain copies of all service provider contracts.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Introduced
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI under this section.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(e)
Introduced
Law enforcement agencies conducting an emergency facial recognition search must (1) immediately document the factual basis for the emergency belief, (2) narrowly tailor the search to address the emergency, and (3) within 48 hours of obtaining results, file a signed, sworn statement with the superior court setting forth the grounds for the search.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Introduced
The Department of State Police must document in writing every facial recognition search request made to the Federal Bureau of Investigation.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(e)
Introduced
Law enforcement agencies must (1) immediately document the factual basis for any emergency facial recognition search, (2) ensure the search is narrowly tailored to the emergency, and (3) within 48 hours of obtaining search results, file a signed, sworn statement by a supervisory official with the superior court in the relevant jurisdiction setting forth the emergency grounds.
MA
Introduced
Controllers must execute written contracts with processors specifying processing instructions, purpose, data types, duration, and obligations. Processors must maintain confidentiality, assist with consumer rights and security obligations, support data protection assessments, delete or return data at service end, not combine data across controllers, cooperate with compliance assessments, and maintain their own data security practices consistent with chapter 93H.
MA
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous and accurate records of all data collected via electronic monitoring, destroy monitoring data no later than 37 months after collection (absent employee consent), maintain reasonable data security practices, and honor employee requests to correct erroneous data.
MA
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool — including data sources, technical specifications, development personnel, and historical use data — with a historical record of tool versions. Documentation must be legible, accessible to auditors, and available to labor organizations as required by law.
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Introduced
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI under this section.
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(e)
Introduced
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency, (2) narrowly tailor the search to address the emergency, and (3) file a signed, sworn statement with the superior court within 48 hours of obtaining search results.
MA
Introduced
Frontier developers that redact published documents must describe the character and justification of each redaction in the published version and must retain unredacted information for five years.
MA
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of data collected via electronic monitoring tools to ensure compliance with employee or commissioner data requests. Employers must destroy employee information collected via electronic monitoring no later than thirty-seven months after collection unless the employee provides written informed consent to retention. Employers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of employee data. Employees have the right to request corrections to erroneous employee data.
MA
Introduced
Employers or their vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct an impact assessment, including source data, technical specifications, developer information, and historical use data. Documentation must include a historical version record enabling the employer to attest to the tool's specifications at the time of any disputed employment decision. Vendor-held documentation must be licensed to the employer and shareable with labor organizations and courts. Documentation must be stored per commissioner-specified requirements and must be legible and accessible to the auditor. Employee data collected for impact assessments must be processed and stored to protect privacy, must not be shared with the employer, and must not be shared with anyone unless strictly necessary for the assessment.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must retain an unredacted copy of the safety and security protocol, including records and dates of all updates or revisions, for at least five years after the covered model is no longer available for commercial, public, or foreseeably public use.
MI
Introduced eff 2026-01-01
Large developers must record and retain for five years all specific tests used and results obtained as part of any assessment of critical risk, with sufficient detail for qualified third parties to replicate the testing.
MI
Introduced
Employers must retain all documentation pertaining to the design, development, use, and data of electronic monitoring tools and automated decisions tools that may be necessary to conduct an impact assessment, including the data source, technical specifications, individuals involved in development, historical use data, and version history. Service providers must allow employers access to this documentation. Employers must share the documentation with labor organizations as required by law or court order. Documentation must be stored in a manner prescribed by the director to ensure legibility and accessibility for assessment purposes.
MI
Introduced
Employers must retain all design, development, use, and data documentation necessary to conduct impact assessments, store it in the director-prescribed accessible manner, obtain access to service-provider documentation, and share it with labor organizations as required by law or in litigation.
MN
Introduced
Employers must maintain records of all worker data collected, used, or produced by an automated decision system — including all ADS input/output data and human reviewer corroborating evidence — for 36 months after the data's most recent collection, production, or use. Employers must destroy this data no later than 37 months after most recent collection, production, or use, unless the worker provides written and informed consent to longer retention. Employers must protect the confidentiality, integrity, and accessibility of worker data using data security practices consistent with applicable privacy and cybersecurity laws and appropriate to the volume and nature of the data.
MN
Introduced
Employers must retain data collected through electronic monitoring tools for 36 months, destroy it no later than 37 months after collection absent worker consent, and protect the confidentiality, integrity, and accessibility of worker data using security practices consistent with applicable data and cyber privacy laws.
MN
MN HF 4532 (RAISE Act) § Minn. Stat. § 325M.41
Introduced
Developers must record and retain information on the specific tests and test results used in any assessment of the AI model required under section 325M.41 or by the developer's safety and security protocol. Records must provide sufficient detail for third parties to replicate the testing procedure and must be retained for the entire deployment period plus five years.
MN
Introduced
IVOs must retain all documentation used in annual reports and all documentation relating to the assessment and verification of AI models and applications — including ongoing monitoring and corrective actions — for ten years after the relevant activity.
MN
Introduced
Developers must retain an unredacted copy of the safety and security protocol, including records and dates of all updates or revisions, for the entire deployment period plus five years. Developers must also record and retain information on the specific tests and test results used in any assessment of the AI model, with sufficient detail for third parties to replicate the testing procedure, for the entire deployment period plus five years.
MN
Introduced
Licensed IVOs must retain all documentation used in annual reports and all documentation relating to AI model and application assessments, verification activities, ongoing monitoring, and corrective actions for ten years after the relevant activity.
MN
Introduced eff 2027-01-01
Employers must retain electronic monitoring data for 36 months, destroy it by 37 months absent written worker consent, protect its confidentiality and integrity using data security practices appropriate to the volume and nature of data collected, and maintain it in a form producible to workers and the Commissioner of Labor and Industry.
MN
Introduced eff 2027-01-01
Employers must retain all worker data collected, used, or produced by an automated decision system — including inputs, outputs, and corroborating evidence used by human reviewers — for 36 months after the data's most recent collection, production, or use, in a form that can be produced to workers or the Commissioner of Labor and Industry.
MO
Introduced
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur when the initial purpose for collecting the data has been satisfied or within one year of the individual's last interaction with the entity, whichever occurs first. The entity must comply with its own established retention schedule and destruction guidelines absent a valid warrant or subpoena.
MO
Introduced eff 2027-01-01
Developers and deployers must maintain usage logs for all AI system content distributed for public consumption, including: (1) date and time of content generation, (2) identity of the user or entity generating the content, (3) input parameters or prompts used, (4) description of the output (type, file size, intended platform), and (5) metadata linking the log to the specific AI system and version.
MO
Introduced eff 2027-01-01
Developers and deployers must retain usage logs for a minimum of seven years from the date of content generation, unless otherwise required by law.
MO
Introduced eff 2027-01-01
Developers and deployers must store usage logs with encryption and control access to the logs to prevent unauthorized access.
MO
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous and accurate records of each employee's individual work performance data, aggregated work performance data for similar employees, the work performance standard provided to each employee, and written termination notices.
NJ
Introduced
Employers and public entities must maintain true and accurate records of all EMT-collected data, AEDS inputs and outputs, performance evaluations, validation results, and impact assessments for not less than three years. Data must be destroyed no later than 37 months after collection unless the individual provides uncoerced written consent for continued retention.
NY
Introduced
Employers must maintain an updated list of all automated decision systems currently in use.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 524
Introduced
Every licensed high-risk advanced AI system must automatically generate a log each time it operates. Logs must conform to Secretary-prescribed standards covering event types, format, access permissions, encryption, cybersecurity protocols, and preservation/disposal procedures. All logs must be preserved for ten years from the date of generation and must be available for regulatory inspection.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 527
Introduced
Every operator must maintain all books, records, source code, and logs as the Secretary requires. At minimum, operators must maintain a copy of all logs generated from the system and a backup of every version of the system, stored in a safe manner prescribed by the Secretary.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an AEDT that may be necessary to conduct an impact assessment for a period of three years, to ensure compliance with Commissioner requests for data.
NY
NY AB 6031 (Biometric Privacy Act) § Gen. Bus. Law § 676-b
Introduced
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy that establishes a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur within a reasonable time — but no later than 60 days — after the data is no longer necessary for the permissible purpose identified in the notice or for which the individual provided authorization, or within three years of the individual's last interaction with the private entity, whichever occurs first. Absent a valid warrant or subpoena, the entity must comply with its established retention schedule and destruction guidelines.
NY
Introduced
Developers of general-purpose AI models must: (1) create and maintain technical documentation covering training and testing processes, compliance evaluation results, intended tasks, target integration systems, acceptable use policies, release date, distribution methods, and input/output modalities and formats — reviewed and revised at least annually; and (2) create, implement, maintain, and make available to downstream integrators documentation that enables understanding of the model's capabilities and limitations, facilitates compliance with this article, discloses technical integration requirements and the information listed in (1), and is reviewed and revised at least annually. Trade secrets and legally protected information are exempt.
NY
Introduced
Covered entities must retain the full impact assessment and summary for seven years and must produce them to the Department of Financial Services within seven days upon notice from the Superintendent.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 108
Introduced
Developers that do not intend their AI system to be used as high-risk must (1) contractually bar high-risk use with each authorized deployer, (2) implement reasonable technical safeguards against high-risk use, (3) prominently disclose the prohibition on their website, in marketing, and in licensing agreements, and (4) retain deployer agreements for at least five years.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 112
Introduced
Covered developers and deployers must plan, document, and implement an iterative risk management policy and program — reasonable against the NIST AI RMF v1.0 or ISO 42001 — that identifies, documents, and mitigates foreseeable risks of algorithmic discrimination across the high-risk AI system's life cycle, with regular review and updates.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 107
Introduced
Developers must enter written contracts with deployers that: (1) set forth data processing procedures for collection, processing, and transfer on behalf of the deployer; (2) include instructions for data handling, intended deployment, nature/purpose/type/duration of data processing, and mutual rights and obligations including material-change notification; (3) do not relieve either party of statutory obligations; (4) prohibit commingling of data received from the counterparty with data from other parties; and (5) do not prohibit either party from raising concerns to enforcement agencies. Developers must retain copies of all deployer contracts for at least 10 years.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 110
Introduced
Developers and deployers must notify each affected individual prior to implementing any material change to the public disclosure, using direct electronic notification in each covered language. Developers and deployers must retain each previous version of the disclosure for at least 10 years after the last day on which the version was effective, publish each version on their website, and maintain a publicly available log describing the date and nature of each material change — sufficient for a reasonable individual to understand the material effect of each change.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct an impact assessment for a period of three years.
NY
Introduced
Large frontier developers must retain the third-party verifier's report for a minimum of five years and must allow the state office or the Attorney General to inspect an unredacted version upon request.
NY
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of all data collected via electronic monitoring tools. Employers must destroy employee data collected via electronic monitoring no later than 37 months after collection unless the employee has provided written and informed consent to continued retention.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an AEDT necessary to conduct an impact assessment, including data sources, technical specifications, developer identities, historical use data, and a historical record of tool versions sufficient to attest to the tool's specifications at the time of any disputed employment decision. Documentation must be stored per Commissioner-specified requirements and be legible and accessible to auditors.
NY
Introduced
Developers of general-purpose AI models must create and maintain technical documentation covering: (1) training and testing processes; (2) evaluation results demonstrating article compliance; (3) as appropriate given size and risk profile — intended tasks, types of downstream AI systems the model is designed for, acceptable use policies, release date, distribution methods, and input/output modalities and formats. Documentation must be reviewed and revised at least annually or more frequently as necessary for accuracy. Developers must also create, implement, maintain, and make available to downstream integrators documentation enabling them to understand the model's capabilities and limitations, comply with the article, and integrate the model, including the technical means for integration and the information listed above. Integrator documentation must also be reviewed and revised at least annually.
NY
NY SB 2414 (Political AI Disclaimer) § Election Law § 14-106(2-b)
Introduced
Committees must keep records of their use of synthetic media during each campaign cycle, including the types of synthetic media utilized, the number of voters contacted with each type, and the amount of funds expended toward synthetic media.
NY
Introduced
Deployers and developers must, as part of their governance program: (1) identify and implement discrimination-risk safeguards, (2) conduct impact assessments per §§ 752–753, (3) perform annual comprehensive compliance reviews, (4) retain impact assessment results for at least two years, and (5) make reasonable adjustments to safeguards in light of material changes in technology, risk, standards, or business operations.
NY
Introduced
Covered entities must retain the full impact assessment and summary for seven years and produce them to the Department of Financial Services within seven days of notice from the superintendent.
OH
Introduced
Licensed IVOs must retain all documentation used to prepare their annual reports for ten years following submission.
OK
Introduced eff 2025-11-01
Deployers must ensure all documentation complies with state and federal medical record-keeping requirements and is accessible for regulatory review. Deployers must maintain documentation of relevant instances where a qualified end-user overrides or disagrees with AI device-generated outputs through a summary report indicating the frequency and nature of overrides, including the percentage or number of such overrides or disagreements.
OK
Introduced eff 2025-11-01
Deployers must maintain an updated inventory of all deployed AI devices, including device instructions for use and any relevant safety and effectiveness documentation, and make all such documentation accessible to all qualified end-users of each device.
OK
Introduced eff 2025-11-01
Deployers must document the use case and user training procedure for each deployed AI device.
OK
OK HB 3299 (Synthetic Media & Deepfakes) § 21 Okl. St. § 1629(B)
Introduced
Media advertising agencies must require all content creators to sign an attestation certifying whether advertisements contain digitized or synthetically altered content, retain those attestations for at least 24 months, and make them available upon request to the appropriate enforcement authority.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(J)
Introduced eff 2026-11-01
Contractors and vendors handling student data must (1) sign a Parent Data Privacy Agreement, (2) employ industry-standard encryption, multi-factor authentication, and secure data storage, (3) delete or return all data within ninety days of contract termination, and (4) submit to random privacy and security audits by the Department or an independent third-party auditor. Vendors in violation may be debarred from state contracts for up to five years.
PA
Introduced
Social media companies must maintain documentation of how express parental or guardian consent was obtained for each minor account holder. Documentation may be deleted when the minor reaches age 16 or within the company's established data retention timeframe.
PA
Introduced
Facilities must retain records related to AI algorithms for the period determined by the Department of Health's record retention policy.
PA
Introduced
Insurers must retain AI-related records for the period determined by the Insurance Department's record retention policy.
PA
Introduced
MA or CHIP managed care plans must retain AI-related records for the period determined by the Department of Human Services' record retention policy.
PA
Introduced
Suppliers must maintain documentation regarding the development and implementation of the chatbot describing: (1) foundation models used in development; (2) training data used; (3) compliance with federal and state privacy law; (4) consumer data collection and sharing practices; and (5) ongoing efforts to ensure accuracy, reliability, fairness, and safety.
PA
Introduced
Facilities must retain records related to AI algorithms for a period to be determined by the Department of Health through a record retention policy. The department will establish the specific retention period.
PA
Introduced
Insurers must retain records related to AI algorithms for a period to be determined by the Insurance Department through a record retention policy.
PA
Introduced
MA or CHIP managed care plans must retain records related to AI algorithms for a period to be determined by the Department of Human Services through a record retention policy.
PA
Introduced
Participants must retain all records, documents, and data produced in the ordinary course of business regarding the tested product or service, submit quarterly reports including customer complaint information, and make records available for inspection upon the Office's request.
RI
RI HB 5172 (Health Insurer AI Transparency) § R.I. Gen. Laws § 27-83-3
Introduced
Insurers must maintain documentation of AI decisions for at least five years.
RI
RI HB 7190 (AI Use by Health Insurers) § R.I. Gen. Laws § 27-84-3
Introduced
Insurers must maintain documentation of all artificial intelligence decisions for at least five years, including adverse benefit determinations where AI made or was a substantial factor in the determination.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must establish, maintain, and preserve for five years contemporaneous, true, and accurate records of data gathered through electronic monitoring and used in hiring, promotion, termination, disciplinary, or compensation decisions. Employers must destroy employee information collected via an electronic monitoring tool no later than 61 months after collection unless the employee has provided written and informed consent to retention. Employers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of employee data, appropriate to the volume and nature of the data. Employees have the right to request corrections to erroneous employee data.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-6
Introduced eff 2025-10-01
Developers of general-purpose AI models must create and maintain technical documentation covering training and testing processes, intended tasks, integration targets, acceptable use policies, release date, distribution methods, input/output modalities, and a detailed training data description including data type and provenance, curation methodologies, selection methods, unsuitable data source identification, and bias detection methods. Documentation must be reviewed and revised at least annually.
TX
TX HB 1265 (AI Mental Health Services) § Health & Safety Code § 616.006
Introduced eff 2025-09-01
Persons providing AI mental health services must maintain records of service provision in the same manner required by the applicable professional licensing statute.
US
Introduced
Covered entities must create and maintain contemporaneous documentation of their impact assessments, including baseline process evaluations, stakeholder consultation records, privacy and security testing, development and deployment milestones, improvement needs, and documentation of any assessment requirements that were infeasible to complete along with the rationale for noncompliance.
US
Introduced
Developers must make compliance information (including pre-deployment evaluation reports and annual reviews) available to deployers on request, and must cooperate with deployer audits or arrange independent auditor assessments. Developer-deployer contracts must specify data processing procedures, deployment instructions, data types, processing duration, and party obligations; must not relieve either party of liability; must prohibit data commingling; and must preserve enforcement reporting rights. Developers must retain contracts for 10 years.
US
Introduced
Employers must make, keep, preserve, and make available to the Secretary of Labor records pertaining to compliance with the Act, in accordance with FLSA § 11(c) and any regulations or orders issued by the Secretary, and must file annual or special reports upon the Secretary's request.
US
Introduced
Covered entities must maintain documentation of all impact assessments performed, including the information described in Section 4(a), for 3 years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Introduced
Covered entities must document all stakeholder consultations performed during impact assessments, including points of contact, dates, legal or financial agreements, materials reviewed by stakeholders, recommendations adopted, and recommendations rejected with rationale.
US
Introduced
Covered entities must maintain ongoing documentation of the development and deployment process (milestones, dates, responsible teams), identify needed improvements in capabilities, tools, standards, or resources across performance, fairness, transparency, privacy, safety, efficiency, and cost, document any impact assessment requirements that were infeasible to complete with corresponding rationale, and perform any additional studies the FTC determines appropriate.
US
Introduced
Sandbox participants must retain all records, documents, and data directly related to their participation in the Program and make them available for inspection upon request by the Director.
US
Introduced
Developers must, upon deployer request, provide information necessary for deployer compliance, including pre-deployment evaluation reports and annual review results. Developers must either cooperate with deployer-conducted assessments or arrange an independent auditor assessment of the developer's practices and share the report.
US
Introduced
Developers must include in written contracts with deployers: data processing procedures, deployment instructions, data types and processing duration, both parties' rights and obligations with a material-change notification method, a prohibition on cross-party data combination, and a prohibition on suppressing enforcement-agency complaints. Contracts may not relieve either party of statutory obligations. Developers must retain all contracts for 10 years.
VA
VA HB 1294 (Law Enforcement AI Disclosure) § Va. Code § 19.2-11.14(E)
Introduced
Law-enforcement agencies must retain the first draft of any report or record created in whole or in part using generative AI for as long as the final report is retained. The program used to generate the report must maintain an audit trail that, at a minimum, identifies: (i) the person who used AI to create or edit the report, (ii) any changes made to the report following the initial draft, and (iii) the video and audio footage used to create the report, if any.
VA
Introduced
Developers must keep detailed records of all training datasets used to train a generative AI system or service. Compliance is deemed satisfied by adherence to the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized AI risk management framework.
VA
Introduced
Media outlets accepting electioneering communications for publication or broadcast must require and retain for one year proof of identity of the person submitting the communication, verified either via government-issued photo ID in person or via telephone verification of identifying information submitted remotely.
VA
Introduced
Media outlets accepting electioneering communications must require and retain for one year a copy of proof of identity of the person submitting the communication, verified either in person via government-issued ID or remotely via telephone verification.
WA
Introduced eff 2028-07-01
Employers must maintain records of all electronic monitoring notices provided to employees for at least three years and produce them to the Department of Labor and Industries upon request.
WV
WV HB 5567 (Biometric Information Privacy) § W. Va. Code § 15-17-3
Introduced
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur when the initial purpose for collecting or obtaining the data has been satisfied or within three years of the individual's last interaction with the private entity, whichever occurs first. The entity must comply with its established retention schedule and destruction guidelines absent a valid warrant or subpoena.
CA
CA AB 2811 (Attorney AI Disclosure Affidavit) § Bus. & Prof. Code § 6068.1
Failed
Attorneys must execute and retain for seven years an affidavit certifying, for each document filed or intended to be filed in a California state or federal court, whether generative AI was used in drafting the document and, if so, that all AI-generated text, citations, and legal analysis has been reviewed for accuracy and approved by a human.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable safeguards to manage algorithmic discrimination risks, proportionate to the tool's use and the entity's role and resources. The program must (1) designate at least one employee responsible for compliance oversight with authority to raise compliance concerns, (2) identify and implement anti-discrimination safeguards, (3) conduct annual comprehensive compliance reviews, (4) retain impact assessment results for five years after completion, and (5) adjust safeguards in light of material changes in technology, risk, or operations.
CA
CA AB 3211 (Digital Content Provenance Standards) § Bus. & Prof. Code § 22949.90.4
Failed
Generative AI system providers, generative AI system distributors, and large online platforms must, beginning January 1, 2026, and annually thereafter, produce a Risk Assessment and Mitigation Report assessing synthetic content risks and harms — including AI-generated CSAM, NCII, election and public health disinformation, and plagiarism. The report must be audited by qualified independent auditors using state-of-the-art techniques and applicable national and international AI auditing standards.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage algorithmic discrimination risks. The program must (1) designate at least one compliance employee with authority to raise compliance concerns and trigger prompt internal investigation, (2) identify and implement discrimination safeguards, (3) provide for required impact assessments, (4) conduct an annual comprehensive compliance review, (5) retain impact assessment results for two years, and (6) adjust safeguards in response to material changes in technology, risk, standards, or business operations.
CA
Failed
Covered deployers must document responsive actions taken in connection with any security breach incident, including a mandatory post-incident review of each event and any changes made to business practices for the protection of personal information in response.
CA
Failed
Employers must maintain an updated list of all automated decision systems currently in use.
CT
Failed
Developers of general-purpose AI models must create, maintain, and annually revise technical documentation covering training and testing processes, intended tasks, integration contexts, acceptable-use policies, release dates, distribution methods, input/output modalities, and detailed training data descriptions (type, provenance, curation methods, selection criteria, bias detection methods). Developers must also establish and maintain a copyright compliance policy.
FL
Failed eff 2026-07-01
Workers' compensation carriers must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed eff 2026-07-01
Insurers must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed eff 2026-07-01
Health maintenance organizations must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed
Insurers must maintain detailed records of all actions taken by qualified human professionals when adjusting, denying, or reviewing claim decisions, including: (1) the name and title of each qualified human professional who made or reviewed a claim decision; (2) the date and time of each claim decision and review; and (3) documentation of the basis for any denial, including any information provided by an algorithm, AI system, or machine learning system.
FL
Failed
Insurers that use an algorithm, AI system, or machine learning system as part of their claims-handling process must detail in their claims-handling manual (1) the manner in which such systems are to be used and (2) the manner in which the insurer complies with this section.
GA
Failed
Facial recognition specialists must (1) use the software only for official law enforcement business, (2) log in with assigned credentials, (3) record the case number and law enforcement reason for each search in the incident report, (4) use only lawfully collected probe images, (5) use only agency-approved software, and (6) ensure every search request and its results are documented in the incident report.
GA
Failed
Law enforcement agencies seeking to use another agency's facial recognition software must submit a written request from a supervisory-level official, obtain supervisory-level approval from the providing agency, and execute a signed interagency agreement or MOU containing eight enumerated acknowledgments covering legal compliance, use limitations, anti-surveillance commitments, corroboration requirements, confidentiality, and lawful probe-image sourcing.
GA
Failed
Law enforcement agencies must (1) conduct quarterly random-sample audits of authorized facial recognition users to verify proper documentation is being maintained, (2) conduct at least annual random-sample audits to verify procedural compliance and that the authorized-user list is current, and (3) document and retain all audit records for at least two calendar years.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern the risks of algorithmic discrimination. The program must include discrimination safeguards, impact assessment procedures, an annual compliance review, two-year retention of impact assessment results, and ongoing adjustment of safeguards in light of material changes.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern reasonably foreseeable algorithmic discrimination risks associated with each automated decision tool. Safeguards must be proportionate to the tool's use, the deployer's role and size, the nature of the deployer's activities, and the technical feasibility and cost of available tools. The program must: (1) identify and implement safeguards for foreseeable discrimination risks; (2) support performance of impact assessments required by Section 10; (3) conduct an annual comprehensive compliance review; (4) retain impact assessment results for at least two years after completion; and (5) adapt safeguards in response to material changes in technology, risk, technical standards, or business operations. This obligation does not apply to deployers with fewer than 25 employees unless the tool impacted more than 999 people in the prior calendar year.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(d)
Failed
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(e)
Failed
Law enforcement agencies must immediately document the factual basis for any emergency facial recognition search, ensure the search is narrowly tailored, and within 48 hours of obtaining results file a signed, sworn statement from a supervisory official with the superior court setting forth the grounds for the emergency search.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Failed
The department of state police must document in writing every facial recognition search request made to the FBI under this section.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(e)
Failed
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency, (2) ensure the search is narrowly tailored to the emergency, and (3) file a signed, sworn statement by a supervisory official with the superior court within 48 hours of receiving search results.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(d)
Failed
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI under this section.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(e)
Failed
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency belief, (2) ensure the search is narrowly tailored, and (3) within 48 hours of obtaining results, file a signed, sworn statement with the superior court setting forth the grounds for the search.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–318
Failed
Each unit of State government must conduct an annual data inventory by December 1 each year, identifying data necessary for operations or required by law, in the form prescribed by the Chief Data Officer, including flagging data used in artificial intelligence.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Failed
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, U.S. Attorneys, or their designees.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–505
Failed
Law enforcement agencies must complete an annual compliance audit beginning October 1, 2023, retain all audit materials for at least three years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorney, U.S. Attorney, or their designees.
NC
Failed
Manufacturers and importers of licensed chatbots must establish and maintain records, and make reports to the Director, as the Director may by regulation reasonably require to assure the safety and effectiveness of the chatbot.
NC
Failed
Covered platforms must store all chatbot conversations that do not include sensitive personal information for at least 60 days.
NC
Failed
Licensees must implement industry-standard encryption for data in transit and at rest, maintain detailed access logs, and conduct regular security audits no less than once every six months.
NC
Failed
Manufacturers and importers of licensed chatbots must establish and maintain records and submit reports to the Director as required by regulation to assure the safety and effectiveness of such devices.
NC
Failed
Covered platforms must store all chatbot conversations that do not include sensitive personal information for at least 60 days.
NE
Failed eff 2027-01-01
Large frontier developers and large chatbot providers that redact published plan documents for trade secrets, cybersecurity, public safety, national security, or legal compliance must describe the character and justification of each redaction in the published version to the extent permitted by the concerns justifying the redaction, and must retain the unredacted information for five years.
NV
Failed eff 2026-01-01
Insurers must develop, implement, and maintain a written plan for responsible AI use that includes a plan for acquiring, using, or relying upon third-party AI systems, covering contractual cooperation with regulatory inquiries and audit rights to confirm third-party compliance.
NY
Failed
Large developers must, before deploying a frontier model, record (as and when reasonably possible) and retain for as long as the frontier model is deployed plus five years information on the specific tests and test results used in any assessment of the frontier model, in sufficient detail for third parties to replicate the testing procedure.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 424
Failed
Licensees must ensure their system automatically generates a log every time it operates, conforming to standards set by the secretary, and must preserve all logs for ten years from the date of generation.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 427
Failed
Operators must maintain all books, records, source code, and logs as the secretary requires, including at minimum all system-generated logs and a backup of every version of the system, stored safely as prescribed.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of automated employment decision tools, including data sources, technical specifications, individuals involved in development, historical use data, and a version history sufficient to attest to the tool's specifications at the time of any employment decision. Documentation must be stored in a legible and accessible format for auditors.
NY
Failed
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of all data collected via electronic monitoring tools to ensure compliance with employee and commissioner data requests. Employers must destroy monitoring data no later than 37 months after collection unless the employee provides written, informed consent to continued retention.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of each AEDT — including training data sources, technical specifications, developer identities, historical use data, and a historical record of tool versions — sufficient to reconstruct the tool's state at the time of any disputed employment decision. Documentation must be stored per commissioner-specified requirements and be legible and accessible to auditors conducting impact assessments.
NY
Failed
When frontier developers redact published documents for trade secrets, cybersecurity, public safety, or national security, they must describe the character and justification of each redaction in the published version and must retain unredacted originals for five years.
NY
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage foreseeable discrimination risks, scaled to the entity's role, size, and resources. The program must at minimum (1) identify and implement discrimination safeguards, (2) conduct annual comprehensive compliance reviews, (3) retain impact assessment results for two years, and (4) adjust safeguards in response to material changes in technology or business operations.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct a bias audit, including data sources, technical specifications, developer identities, historical use data, and a version history sufficient to reconstruct the tool as it existed at the time of any disputed employment decision. Documentation must be legible and accessible to auditors.
OK
Failed
Deployers must maintain (1) updated inventories of deployed AI systems, (2) documentation on system design, intended use, and training data, and (3) records of audits, risk assessments, and oversight activities.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-5
Failed
The governance program must (1) identify and implement algorithmic-discrimination safeguards, (2) integrate impact-assessment obligations, (3) conduct an annual comprehensive compliance review, (4) retain impact-assessment results for two years after completion, and (5) make reasonable adjustments to safeguards in response to material changes in technology, risk, technical standards, or business operations.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must provide deployers with the technical capability to access documentation reasonably necessary for the deployer's impact assessment, including the CAIDS's capabilities, known limitations, and intended-use guidelines. Trade secrets and confidential information are not required to be disclosed.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must provide deployers with the technical capability to access information reasonably necessary to perform impact assessments, including documentation of the CAIDS's capabilities, known limitations, and guidelines for intended use. Trade secrets and confidential information need not be disclosed.
TX
TX HB 4695 (AI Mental Health Services) § Health & Safety Code § 616.006
Failed
Persons providing AI mental health services must maintain service records in the same manner required by the professional licensing statute applicable to a licensed mental health professional providing the same service.
US
Failed
Online platforms must retain for five years (extendable to eight by the FTC) a de-identified record describing each algorithmic process's data inputs, weighting methodology, development methodology (including training data and bias testing), and — for non-small-business platforms using algorithms in housing, education, employment, insurance, credit, or public accommodations — a disparate-impact assessment. Records must be produced to the FTC on request.
US
Failed
Online platforms must retain for five years (extendable to eight by FTC determination) a de-identified record for each algorithmic process describing the personal information categories used, the weighting/ranking method, the development data and training data, testing methodology for accuracy, fairness, bias, and discrimination, and — for non-small-business platforms using algorithmic processes in housing, education, employment, insurance, credit, or public accommodations — an assessment of whether the process produces disparate outcomes across protected characteristics.
US
Failed
Covered entities must maintain documentation of all impact assessments, including all information described in the assessment requirements, for three years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Failed
Covered entities must document in the impact assessment: (1) the baseline decision process being replaced and its known harms, (2) the intended benefits and purpose of the new augmented critical decision process, (3) all stakeholder consultations including contacts, dates, agreements, and recommendations adopted or rejected, (4) the development and deployment timeline, (5) resource needs identified, and (6) any assessment requirements that were infeasible and the rationale.
US
Failed
Law enforcement agencies whose officers use facial recognition must log all uses of facial recognition to the extent necessary to comply with the Act's reporting and audit requirements.
US
Failed
Covered entities must maintain documentation of all impact assessments, including the information described in Sec. 4(a), for three years beyond the duration of deployment of each automated decision system or augmented critical decision process.
US
Failed
Covered entities must, as part of the impact assessment for a new augmented critical decision process, evaluate and document the previously existing decision-making process (including baseline description, known harms, intended benefits, and intended purpose), and document all stakeholder consultations including contacts, dates, and terms of engagement.
US
Failed
Covered entities must document the development and deployment lifecycle (milestones, responsible teams), identify needed improvements in performance, fairness, transparency, privacy, safety, and cost, and document any impact assessment requirements that were infeasible to complete with rationale.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must oversee the creation of AI governance charters for all covered federal AI systems, ensure they are regularly updated, publish them on the agency's public webpage, submit them to the Federal Register within 30 days of establishment or termination, and submit them to GSA for inclusion in the Federal AI System Inventory.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3595
Failed
Each agency head must establish and maintain an accurate AI governance charter for every federal AI system that is high-risk or that uses, is trained on, or produces individual records, documenting at minimum: system purpose and responsible officials, development and funding details, training data and testing information, ongoing oversight cadence, system usage including AI-assisted determinations, output data descriptions, and Privacy Act system-of-records information. Charters must be updated within 30 days of any significant system change.
US
Failed
Online platforms must retain for 5 years (extendable to 8 by FTC determination) a de-identified record of each algorithmic process describing: data categories used, ranking methodology, development method including training data and ongoing training, testing methodology for accuracy, fairness, bias, and discrimination, and — for non-small-business platforms using algorithms in housing, education, employment, insurance, credit, or public accommodations — an assessment of whether the process produces disparate outcomes across protected characteristics.
US
Failed
Each agency head must establish an AI strategy for trustworthy AI adoption that includes (1) defined roles and responsibilities, (2) values and ethics principles, (3) trust and safety standards, (4) risk identification and mitigation processes, (5) algorithmic discrimination safeguards, (6) current and anticipated AI use domains, (7) workforce development steps, (8) conditions for public-facing AI use, (9) internal coordination processes, (10) interagency governance, (11) data governance, (12) procurement safeguards for rights and safety, and (13) specific implementation actions and desired outcomes.
US
Failed
Online platforms must retain for five years (extendable to eight) a de-identified record describing each algorithmic process, including personal information categories used, weighting methods, development data, training data, and testing for accuracy, fairness, bias, and discrimination. Non-small-business platforms using algorithms related to housing, education, employment, insurance, credit, or public accommodations must include a disparate-impact assessment across protected characteristics. Records must be produced to the FTC upon request.
US
Failed
Covered entities must maintain documentation of each impact assessment, including all information described in Sec. 4(a), for 3 years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Failed
Covered entities must, as part of the impact assessment, evaluate any previously existing decision-making process being replaced, document stakeholder consultations (including points of contact, dates, legal agreements, materials reviewed, and recommendations adopted or rejected with rationale), and document the baseline, known harms, intended benefits, and purpose of the new system.
US
Failed
Covered entities must maintain ongoing documentation of the development and deployment process (including milestone dates and responsible teams), identify needed capabilities and tools for improvement across performance, fairness, transparency, privacy, safety, efficiency, and cost, and document any impact assessment requirements that were infeasible to complete along with corresponding rationale.
US
Failed
Critical-impact AI organizations must perform a documented TEVV-based risk management assessment no later than 30 days before making a critical-impact AI system publicly available, and biennially thereafter. The assessment must cover (1) organizational AI risk management policies and processes, (2) the system's structure, context, and capabilities, (3) quantitative and qualitative risk measurement methods and metrics, and (4) risk resource allocation and monitoring. Assessment reports must be submitted to the Secretary of Commerce within 90 days of completion in a format the Secretary determines.
US
Failed
Covered entities must maintain documentation of all impact assessments, including the information described in Section 4(a), for three years beyond the duration of the system's deployment.
US
Failed
Covered entities must, as part of their impact assessment, create and maintain contemporaneous documentation covering: (1) evaluation of previously existing decision processes, (2) stakeholder consultation records, (3) development and deployment milestones, (4) identified resource and capability needs, and (5) any requirements that could not be met with corresponding rationale.
US
Failed
Developers must enter into written contracts with deployers that specify data processing procedures, deployment instructions, data types, processing duration, rights and obligations including material-change notification, and must prohibit cross-party data combination. Contracts may not relieve either party of Act liability or prohibit reporting to enforcement agencies. Developers must retain each deployer contract for 10 years.
UT
UT HB 286 (AI Transparency Act) § Utah Code § 13-72b-105
Failed eff 2026-05-06
When a frontier developer redacts published compliance documents, it must describe the character and justification of each redaction in the published version and retain the unredacted information for five years.
UT
UT HB 452 (Mental Health Chatbots) § Utah Code § 58-60-118
Failed
Suppliers seeking the affirmative defense to unlicensed-practice liability must create, maintain, and implement a written policy that states the chatbot's intended purpose and limitations, and describes procedures for (1) involving licensed mental health therapists in development and review, (2) ensuring consistency with clinical best practices, (3) conducting pre-deployment and ongoing testing to ensure output poses no greater risk than therapy with a licensed therapist, (4) identifying foreseeable adverse outcomes, (5) providing a user harm-reporting mechanism, (6) implementing risk-assessment and response protocols, (7) responding in real time to acute risk of physical harm, (8) ensuring regular objective reviews of safety, accuracy, and efficacy, (9) providing safe-use instructions, (10) ensuring users understand they are interacting with AI, (11) ensuring users understand purpose, capabilities, and limitations, (12) prioritizing user safety over engagement metrics or profit, (13) implementing anti-discrimination measures, and (14) ensuring HIPAA-equivalent security and privacy compliance. Suppliers must also maintain documentation describing foundation models, training data, HIPAA compliance, data practices, and ongoing accuracy/safety efforts, and must comply with the filed policy at the time of any alleged violation.
UT
UT SB 149 (AI Policy Act) § Utah Code § 13-70-304
Failed
Learning Laboratory participants must retain records as required by Office rule or the participation agreement.
WA
Failed
Each algorithmic accountability report must include clear and understandable statements covering: system name, vendor, and version; general capabilities and weapons potential; data inputs, generation, collection, and processing methods; bias testing status; purpose and proposed use; compliance plans for Section 4 requirements; constitutional-rights impact; civil rights and disparate impact analysis with mitigation plan; statutory decision criteria; and a comprehensive use and data management policy covering deployment protocols, access rules, data security, personnel training, community engagement, and fiscal impact.
WA
Failed
Each algorithmic accountability report must include 15 categories of clear and understandable statements covering: system name, vendor, and version; general capabilities (including weapon use); purpose and proposed use; data inputs and outputs; bias and inaccuracy examination results; known errors; appeal processes; community engagement; algorithm availability; compliance plans; legal-rights impacts; protected-class differential treatment; statutorily mandated criteria; data management policies and protocols; and fiscal impact.
G-01.4
Regulatory production of records
Records must be organized and maintained in a form that can be produced to regulatory authorities upon request within a reasonable timeframe.
Enacted
4
Live
75
Failed
39
Total
118
CO
Enacted eff 2026-05-14
Deployers must retain records reasonably necessary to demonstrate compliance with Part 17 for at least three years after the date of each consequential decision (or longer if required by other law). Records may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes.
KY
KY SB 176 (Facial Recognition Technology) § KRS Chapter 61, Section 1(3)
Enacted eff 2022-04-08
The working group must create and make publicly available by January 1, 2024, a model policy for law enforcement use of facial recognition technology covering authorized uses (including a prohibition on identifying persons in constitutionally protected activities absent probable cause), personnel authorization, documentation of use, secondary-examiner confirmation of findings, data integrity and retention, data security and data-sharing, training, image-source requirements, audit records, and privacy protections for nudity.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Enacted eff 2024-10-01
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, United States Attorneys, or their designees.
NY
Enacted eff 2025-12-19
Large developers must annually retain an independent third party to audit compliance with § 1421, beginning on the effective date of the article or 90 days after first qualifying as a large developer, whichever is later. The auditor must be granted access to unredacted materials and must produce a report including: (1) a detailed assessment of compliance steps; (2) identified instances of noncompliance and improvement recommendations; (3) assessment of internal controls, including designation and empowerment of senior personnel responsible for compliance; and (4) the lead auditor's certifying signature. The large developer must retain the unredacted report for deployment plus five years, conspicuously publish a redacted copy, transmit a redacted copy to DHSES, and grant DHSES or the attorney general access to the unredacted report upon request.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must retain in unredacted form all performance evaluations, deployer documentation, auditor correspondence, and redaction records for as long as the developer deploys the covered ADS or makes it available to potential deployers, plus 10 years.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must retain in unredacted form all developer documentation, subject disclosures, correction requests, opt-out requests, appeal requests, auditor correspondence, and redaction records for as long as the deployer uses the covered ADS, plus 10 years.
CA
CA AB 1405 (AI Auditor Enrollment) § Gov. Code § 11549.84
Engrossed
Enrolled AI auditors must retain all documentation provided to auditees and documentation necessary to demonstrate the basis of audit results for at least 10 years.
CA
Engrossed
MROs must retain all documents related to their activities under this chapter for ten years.
NH
Engrossed eff 2027-01-01
Health carriers must maintain records identifying the use of artificial intelligence tools in claims processing and must make such records available to the Insurance Department upon audit.
RI
RI SB 13 (Health Insurer AI Transparency) § R.I. Gen. Laws § 27-83-3
Engrossed eff 2026-06-30
Insurers must maintain documentation of all AI decisions — including adverse benefit determinations where AI made or substantially influenced the determination — for at least five years.
VA
VA SB 586 (Health Carrier AI Disclosures) § Va. Code § 38.2-3407.15(B)(15)
Engrossed
Carriers must maintain documentation of AI decisions for at least three years.
CA
CA AB 1898 (Workplace AI Tools) § Lab. Code § 1601
Introduced
Employers must maintain an updated list of all workplace AI tools currently in use and provide that list to workers annually.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-973
Introduced eff 2027-01-01
Covered entities must contemporaneously document each step of the compulsive-use risk-assessment process — including supporting experiments, evidence, and data — and retain the documentation for ten years, with all individual-consumer data de-identified and anonymized.
HI
Introduced
Deployers must retain impact assessments and risk management program documentation for at least five years after the system is retired or materially modified, whichever is later, and must make them available to the Executive Director of the Office of Consumer Protection or the Attorney General upon request. Confidential commercial information is protected to the extent permitted by law.
IA
Introduced
Health carriers must maintain per-claim documentation for every claim downcoded by an automated adjudication system — showing the submitted code, the adjusted code, the reason for the downcode, and whether a clinical reviewer conducted a review — and retain it for at least five years from the claim payment date.
ID
ID HB 945 (AI Medical Services Act) § Idaho Code § 54-6006
Introduced eff 2026-07-01
AAASPs must maintain immutable production-version snapshots of every deployed algorithm — including weights, decision logic, and prompt-engineering instructions — retain them for two years to allow retrospective replay during Board audits, and must not alter or delete snapshots related to any matter under investigation.
IL
Introduced
Developers must record and retain for at least 5 years all specific tests and test results from critical risk assessments, with sufficient detail to allow qualified third parties to replicate the testing.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers may redact published documents for trade secrets, cybersecurity, public safety, national security, or legal compliance, but must describe the character and justification of each redaction in the published version and must retain unredacted information for 5 years.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor (with corporate compliance and foundation model safety expertise) to assess (1) compliance with the public safety plan and instances of noncompliance, (2) plan clarity, and (3) reasonableness of redactions and accuracy of published statements. The developer must grant the auditor full access to compliance materials, retain the audit report for 5 years, and make the unredacted report available to the Attorney General on request.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor — employing individuals with corporate compliance and foundation model safety expertise — to assess compliance with the public safety plan, evaluate clarity of plan language, and review redactions and public statements for reasonableness and truthfulness. Developers must grant the auditor full access to compliance materials, retain audit reports for 5 years, and allow the Attorney General to inspect unredacted reports upon request.
IL
Introduced
Deployers earn a rebuttable presumption of non-defectiveness by designing and implementing a risk management policy that (1) specifies principles, processes, and personnel for identifying, mitigating, and documenting foreseeable risks (especially to users under 17); (2) is consistent with NIST AI RMF; (3) is reasonable given the deployer's size, the system's scope and inputs, and modifications made by the deployer; and (4) is electronically available to employees and to the Attorney General upon request.
IL
Introduced
Deployers may earn a rebuttable presumption of non-defectiveness by designing and implementing a risk management policy that (1) specifies principles, processes, and personnel for identifying, mitigating, and documenting foreseeable risks — with particular attention to impacts on individuals under 17; (2) is consistent with NIST AI RMF; (3) is proportionate to the deployer's size, system scope, and data inputs; and (4) is electronically available to employees and the Attorney General on request.
MA
Introduced
Large data holders must retain and publish prior privacy policy versions for at least 10 years with a public change log, and must provide a short-form notice of no more than 500 words. Entities collecting biometric data or precise geolocation information must each maintain a separate privacy policy for those data types.
MA
Introduced
Covered entities must engage service providers only under written contracts specifying processing instructions, data types, purposes, duration, and mutual obligations. Service providers must adhere to covered entity instructions, assist with individual rights requests, maintain security safeguards, allow compliance assessments, delete or return data upon termination, and retain copies of all service provider contracts.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(e)
Introduced
Law enforcement agencies must (1) immediately document the factual basis for any emergency facial recognition search, (2) ensure the search is narrowly tailored to the emergency, and (3) within 48 hours of obtaining search results, file a signed, sworn statement by a supervisory official with the superior court in the relevant jurisdiction setting forth the emergency grounds.
MA
Introduced
Controllers must execute written contracts with processors specifying processing instructions, purpose, data types, duration, and obligations. Processors must maintain confidentiality, assist with consumer rights and security obligations, support data protection assessments, delete or return data at service end, not combine data across controllers, cooperate with compliance assessments, and maintain their own data security practices consistent with chapter 93H.
MA
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous and accurate records of all data collected via electronic monitoring, destroy monitoring data no later than 37 months after collection (absent employee consent), maintain reasonable data security practices, and honor employee requests to correct erroneous data.
MA
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool — including data sources, technical specifications, development personnel, and historical use data — with a historical record of tool versions. Documentation must be legible, accessible to auditors, and available to labor organizations as required by law.
MA
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of data collected via electronic monitoring tools to ensure compliance with employee or commissioner data requests. Employers must destroy employee information collected via electronic monitoring no later than thirty-seven months after collection unless the employee provides written informed consent to retention. Employers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of employee data. Employees have the right to request corrections to erroneous employee data.
MA
Introduced
Employers or their vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct an impact assessment, including source data, technical specifications, developer information, and historical use data. Documentation must include a historical version record enabling the employer to attest to the tool's specifications at the time of any disputed employment decision. Vendor-held documentation must be licensed to the employer and shareable with labor organizations and courts. Documentation must be stored per commissioner-specified requirements and must be legible and accessible to the auditor. Employee data collected for impact assessments must be processed and stored to protect privacy, must not be shared with the employer, and must not be shared with anyone unless strictly necessary for the assessment.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must retain an unredacted copy of the safety and security protocol, including records and dates of all updates or revisions, for at least five years after the covered model is no longer available for commercial, public, or foreseeably public use.
MD
MD HB 712 (AI Product Liability) § Md. Code, Cts. & Jud. Proc. § 3–2703
Introduced eff 2026-10-01
Deployers may establish a rebuttable presumption of non-defectiveness by implementing and adhering to a risk management policy that (1) specifies how the deployer will identify, document, and mitigate foreseeable risks, especially to minor users, (2) is consistent with industry best practices, (3) is reasonable in light of the deployer's size, complexity, the product's nature and scope, and the data the system processes, and (4) is electronically available to employees and to the Attorney General on request.
MI
Introduced eff 2026-01-01
Large developers must record and retain for five years all specific tests used and results obtained as part of any assessment of critical risk, with sufficient detail for qualified third parties to replicate the testing.
MI
Introduced
Employers must retain all documentation pertaining to the design, development, use, and data of electronic monitoring tools and automated decisions tools that may be necessary to conduct an impact assessment, including the data source, technical specifications, individuals involved in development, historical use data, and version history. Service providers must allow employers access to this documentation. Employers must share the documentation with labor organizations as required by law or court order. Documentation must be stored in a manner prescribed by the director to ensure legibility and accessibility for assessment purposes.
MI
Introduced
Employers must retain all design, development, use, and data documentation necessary to conduct impact assessments, store it in the director-prescribed accessible manner, obtain access to service-provider documentation, and share it with labor organizations as required by law or in litigation.
MI
Introduced
For unionized workforces, employers must give notice and an opportunity to bargain over intended tool use, and must provide the bargaining representative necessary information — including data collected, impact assessments, and breach records — at least 30 days before bargaining begins.
MN
Introduced
Employers must maintain records of all worker data collected, used, or produced by an automated decision system — including all ADS input/output data and human reviewer corroborating evidence — for 36 months after the data's most recent collection, production, or use. Employers must destroy this data no later than 37 months after most recent collection, production, or use, unless the worker provides written and informed consent to longer retention. Employers must protect the confidentiality, integrity, and accessibility of worker data using data security practices consistent with applicable privacy and cybersecurity laws and appropriate to the volume and nature of the data.
MN
Introduced
Employers must retain data collected through electronic monitoring tools for 36 months, destroy it no later than 37 months after collection absent worker consent, and protect the confidentiality, integrity, and accessibility of worker data using security practices consistent with applicable data and cyber privacy laws.
MN
MN HF 4532 (RAISE Act) § Minn. Stat. § 325M.41
Introduced
Developers must record and retain information on the specific tests and test results used in any assessment of the AI model required under section 325M.41 or by the developer's safety and security protocol. Records must provide sufficient detail for third parties to replicate the testing procedure and must be retained for the entire deployment period plus five years.
MN
Introduced
IVOs must retain all documentation used in annual reports and all documentation relating to the assessment and verification of AI models and applications — including ongoing monitoring and corrective actions — for ten years after the relevant activity.
MN
Introduced
Developers must retain an unredacted copy of the safety and security protocol, including records and dates of all updates or revisions, for the entire deployment period plus five years. Developers must also record and retain information on the specific tests and test results used in any assessment of the AI model, with sufficient detail for third parties to replicate the testing procedure, for the entire deployment period plus five years.
MN
Introduced
Licensed IVOs must retain all documentation used in annual reports and all documentation relating to AI model and application assessments, verification activities, ongoing monitoring, and corrective actions for ten years after the relevant activity.
MN
Introduced eff 2027-01-01
Employers must retain electronic monitoring data for 36 months, destroy it by 37 months absent written worker consent, protect its confidentiality and integrity using data security practices appropriate to the volume and nature of data collected, and maintain it in a form producible to workers and the Commissioner of Labor and Industry.
MN
Introduced eff 2027-01-01
Employers must retain all worker data collected, used, or produced by an automated decision system — including inputs, outputs, and corroborating evidence used by human reviewers — for 36 months after the data's most recent collection, production, or use, in a form that can be produced to workers or the Commissioner of Labor and Industry.
MO
Introduced
The state board of education must audit each local educational agency at least once every three years, with spot checks as needed, to confirm compliance with statewide digital privacy agreement and academic-effectiveness verification requirements. The board must also review vendor compliance, including verification of unauthorized third-party data disclosures.
MO
Introduced eff 2027-01-01
Developers and deployers must anonymize personal data in usage logs and protect it under applicable law. Logs may only be disclosed to law enforcement upon issuance of a warrant or subpoena specifying the scope of the request, and must be provided within fourteen business days of receipt unless expedited by court order.
MO
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous and accurate records of each employee's individual work performance data, aggregated work performance data for similar employees, the work performance standard provided to each employee, and written termination notices.
NJ
Introduced
Employers and public entities must maintain true and accurate records of all EMT-collected data, AEDS inputs and outputs, performance evaluations, validation results, and impact assessments for not less than three years. Data must be destroyed no later than 37 months after collection unless the individual provides uncoerced written consent for continued retention.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 524
Introduced
Every licensed high-risk advanced AI system must automatically generate a log each time it operates. Logs must conform to Secretary-prescribed standards covering event types, format, access permissions, encryption, cybersecurity protocols, and preservation/disposal procedures. All logs must be preserved for ten years from the date of generation and must be available for regulatory inspection.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 527
Introduced
Every operator must maintain all books, records, source code, and logs as the Secretary requires. At minimum, operators must maintain a copy of all logs generated from the system and a backup of every version of the system, stored in a safe manner prescribed by the Secretary.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an AEDT that may be necessary to conduct an impact assessment for a period of three years, to ensure compliance with Commissioner requests for data.
NY
Introduced
Covered entities must retain the full impact assessment and summary for seven years and must produce them to the Department of Financial Services within seven days upon notice from the Superintendent.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 107
Introduced
Developers must, upon reasonable deployer request: (1) make available pre-deployment evaluation reports or annual assessment reviews; (2) provide information necessary for the deployer to conduct and document its own evaluations and assessments; and (3) either allow and cooperate with reasonable deployer or deployer-designated auditor assessments, or arrange for an independent auditor to assess the developer's practices using an accepted control standard and provide the resulting report to the deployer upon request.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct an impact assessment for a period of three years.
NY
Introduced
Large frontier developers must grant the third-party verifier access to all materials submitted to the state office, unredacted versions of all publicly published documents, and any other materials reasonably necessary to perform the compliance assessment.
NY
Introduced
Large frontier developers must retain the third-party verifier's report for a minimum of five years and must allow the state office or the Attorney General to inspect an unredacted version upon request.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an AEDT necessary to conduct an impact assessment, including data sources, technical specifications, developer identities, historical use data, and a historical record of tool versions sufficient to attest to the tool's specifications at the time of any disputed employment decision. Documentation must be stored per Commissioner-specified requirements and be legible and accessible to auditors.
NY
Introduced
Covered entities must retain the full impact assessment and summary for seven years and produce them to the Department of Financial Services within seven days of notice from the superintendent.
OH
Introduced
Licensed IVOs must retain all documentation used to prepare their annual reports for ten years following submission.
OK
Introduced eff 2025-11-01
Deployers must ensure all documentation complies with state and federal medical record-keeping requirements and is accessible for regulatory review. Deployers must maintain documentation of relevant instances where a qualified end-user overrides or disagrees with AI device-generated outputs through a summary report indicating the frequency and nature of overrides, including the percentage or number of such overrides or disagreements.
OK
OK HB 3299 (Synthetic Media & Deepfakes) § 21 Okl. St. § 1629(B)
Introduced
Media advertising agencies must require all content creators to sign an attestation certifying whether advertisements contain digitized or synthetically altered content, retain those attestations for at least 24 months, and make them available upon request to the appropriate enforcement authority.
PA
Introduced
Facilities must retain records related to AI algorithms for the period determined by the Department of Health's record retention policy.
PA
Introduced
Insurers must retain AI-related records for the period determined by the Insurance Department's record retention policy.
PA
Introduced
MA or CHIP managed care plans must retain AI-related records for the period determined by the Department of Human Services' record retention policy.
PA
Introduced
Facilities must retain records related to AI algorithms for a period to be determined by the Department of Health through a record retention policy. The department will establish the specific retention period.
PA
Introduced
Insurers must retain records related to AI algorithms for a period to be determined by the Insurance Department through a record retention policy.
PA
Introduced
MA or CHIP managed care plans must retain records related to AI algorithms for a period to be determined by the Department of Human Services through a record retention policy.
PA
Introduced
Participants must retain all records, documents, and data produced in the ordinary course of business regarding the tested product or service, submit quarterly reports including customer complaint information, and make records available for inspection upon the Office's request.
RI
RI HB 7190 (AI Use by Health Insurers) § R.I. Gen. Laws § 27-84-3
Introduced
Insurers must maintain documentation of all artificial intelligence decisions for at least five years, including adverse benefit determinations where AI made or was a substantial factor in the determination.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must establish, maintain, and preserve for five years contemporaneous, true, and accurate records of data gathered through electronic monitoring and used in hiring, promotion, termination, disciplinary, or compensation decisions. Employers must destroy employee information collected via an electronic monitoring tool no later than 61 months after collection unless the employee has provided written and informed consent to retention. Employers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of employee data, appropriate to the volume and nature of the data. Employees have the right to request corrections to erroneous employee data.
US
Introduced
Developers must make compliance information (including pre-deployment evaluation reports and annual reviews) available to deployers on request, and must cooperate with deployer audits or arrange independent auditor assessments. Developer-deployer contracts must specify data processing procedures, deployment instructions, data types, processing duration, and party obligations; must not relieve either party of liability; must prohibit data commingling; and must preserve enforcement reporting rights. Developers must retain contracts for 10 years.
US
Introduced
Employers must make, keep, preserve, and make available to the Secretary of Labor records pertaining to compliance with the Act, in accordance with FLSA § 11(c) and any regulations or orders issued by the Secretary, and must file annual or special reports upon the Secretary's request.
US
Introduced
Covered entities must maintain documentation of all impact assessments performed, including the information described in Section 4(a), for 3 years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Introduced
Sandbox participants must retain all records, documents, and data directly related to their participation in the Program and make them available for inspection upon request by the Director.
US
Introduced
Developers must, upon deployer request, provide information necessary for deployer compliance, including pre-deployment evaluation reports and annual review results. Developers must either cooperate with deployer-conducted assessments or arrange an independent auditor assessment of the developer's practices and share the report.
VA
VA HB 1294 (Law Enforcement AI Disclosure) § Va. Code § 19.2-11.14(E)
Introduced
Law-enforcement agencies must retain the first draft of any report or record created in whole or in part using generative AI for as long as the final report is retained. The program used to generate the report must maintain an audit trail that, at a minimum, identifies: (i) the person who used AI to create or edit the report, (ii) any changes made to the report following the initial draft, and (iii) the video and audio footage used to create the report, if any.
VT
Introduced eff 2025-07-01
Each developer or deployer must plan, document, and implement a risk management policy and program governing the development or deployment of automated decision systems used in consequential decisions. The program must specify and incorporate the principles, processes, and personnel used to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The program must be iterative, regularly and systematically reviewed and updated over the system's lifecycle, with documentation updates. Reasonableness is assessed against: (1) the NIST AI RMF version 1.0 (or a later version if the Attorney General determines it is at least as stringent); (2) the size and complexity of the entity; (3) the nature, scope, and intended uses of the system; and (4) the sensitivity and volume of data processed. A single program may cover multiple systems. The Attorney General may require disclosure in a prescribed form and evaluate the program for compliance.
VT
VT HB 792 (AI Products Liability) § 9 V.S.A. § 4193d
Introduced eff 2026-07-01
Deployers seeking the safe-harbor presumption of non-defectiveness must design and implement a risk management policy that specifies principles, processes, and personnel for identifying, mitigating, and documenting foreseeable risks (with emphasis on risks to minors), is consistent with industry best practices, is proportionate to the deployer's size and the system's nature, and is electronically available to employees and to the Attorney General upon request.
WA
Introduced eff 2028-07-01
Employers must maintain records of all electronic monitoring notices provided to employees for at least three years and produce them to the Department of Labor and Industries upon request.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable safeguards to manage algorithmic discrimination risks, proportionate to the tool's use and the entity's role and resources. The program must (1) designate at least one employee responsible for compliance oversight with authority to raise compliance concerns, (2) identify and implement anti-discrimination safeguards, (3) conduct annual comprehensive compliance reviews, (4) retain impact assessment results for five years after completion, and (5) adjust safeguards in light of material changes in technology, risk, or operations.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage algorithmic discrimination risks. The program must (1) designate at least one compliance employee with authority to raise compliance concerns and trigger prompt internal investigation, (2) identify and implement discrimination safeguards, (3) provide for required impact assessments, (4) conduct an annual comprehensive compliance review, (5) retain impact assessment results for two years, and (6) adjust safeguards in response to material changes in technology, risk, standards, or business operations.
FL
Failed eff 2026-07-01
Workers' compensation carriers must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed eff 2026-07-01
Insurers must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed eff 2026-07-01
Health maintenance organizations must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed
Insurers must maintain detailed records of all actions taken by qualified human professionals when adjusting, denying, or reviewing claim decisions, including: (1) the name and title of each qualified human professional who made or reviewed a claim decision; (2) the date and time of each claim decision and review; and (3) documentation of the basis for any denial, including any information provided by an algorithm, AI system, or machine learning system.
GA
Failed
Facial recognition specialists must (1) use the software only for official law enforcement business, (2) log in with assigned credentials, (3) record the case number and law enforcement reason for each search in the incident report, (4) use only lawfully collected probe images, (5) use only agency-approved software, and (6) ensure every search request and its results are documented in the incident report.
GA
Failed
Law enforcement agencies must (1) conduct quarterly random-sample audits of authorized facial recognition users to verify proper documentation is being maintained, (2) conduct at least annual random-sample audits to verify procedural compliance and that the authorized-user list is current, and (3) document and retain all audit records for at least two calendar years.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern the risks of algorithmic discrimination. The program must include discrimination safeguards, impact assessment procedures, an annual compliance review, two-year retention of impact assessment results, and ongoing adjustment of safeguards in light of material changes.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(e)
Failed
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency, (2) ensure the search is narrowly tailored to the emergency, and (3) file a signed, sworn statement by a supervisory official with the superior court within 48 hours of receiving search results.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(e)
Failed
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency belief, (2) ensure the search is narrowly tailored, and (3) within 48 hours of obtaining results, file a signed, sworn statement with the superior court setting forth the grounds for the search.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–318
Failed
Each unit of State government must conduct an annual data inventory by December 1 each year, identifying data necessary for operations or required by law, in the form prescribed by the Chief Data Officer, including flagging data used in artificial intelligence.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Failed
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, U.S. Attorneys, or their designees.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–505
Failed
Law enforcement agencies must complete an annual compliance audit beginning October 1, 2023, retain all audit materials for at least three years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorney, U.S. Attorney, or their designees.
NC
Failed
Manufacturers and importers of licensed chatbots must establish and maintain records, and make reports to the Director, as the Director may by regulation reasonably require to assure the safety and effectiveness of the chatbot.
NC
Failed
Manufacturers and importers of licensed chatbots must establish and maintain records and submit reports to the Director as required by regulation to assure the safety and effectiveness of such devices.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 424
Failed
Licensees must ensure their system automatically generates a log every time it operates, conforming to standards set by the secretary, and must preserve all logs for ten years from the date of generation.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 427
Failed
Operators must maintain all books, records, source code, and logs as the secretary requires, including at minimum all system-generated logs and a backup of every version of the system, stored safely as prescribed.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of automated employment decision tools, including data sources, technical specifications, individuals involved in development, historical use data, and a version history sufficient to attest to the tool's specifications at the time of any employment decision. Documentation must be stored in a legible and accessible format for auditors.
NY
Failed
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of all data collected via electronic monitoring tools to ensure compliance with employee and commissioner data requests. Employers must destroy monitoring data no later than 37 months after collection unless the employee provides written, informed consent to continued retention.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of each AEDT — including training data sources, technical specifications, developer identities, historical use data, and a historical record of tool versions — sufficient to reconstruct the tool's state at the time of any disputed employment decision. Documentation must be stored per commissioner-specified requirements and be legible and accessible to auditors conducting impact assessments.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct a bias audit, including data sources, technical specifications, developer identities, historical use data, and a version history sufficient to reconstruct the tool as it existed at the time of any disputed employment decision. Documentation must be legible and accessible to auditors.
OK
Failed
Deployers must maintain (1) updated inventories of deployed AI systems, (2) documentation on system design, intended use, and training data, and (3) records of audits, risk assessments, and oversight activities.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-5
Failed
The governance program must (1) identify and implement algorithmic-discrimination safeguards, (2) integrate impact-assessment obligations, (3) conduct an annual comprehensive compliance review, (4) retain impact-assessment results for two years after completion, and (5) make reasonable adjustments to safeguards in response to material changes in technology, risk, technical standards, or business operations.
US
Failed
Online platforms must retain for five years (extendable to eight by the FTC) a de-identified record describing each algorithmic process's data inputs, weighting methodology, development methodology (including training data and bias testing), and — for non-small-business platforms using algorithms in housing, education, employment, insurance, credit, or public accommodations — a disparate-impact assessment. Records must be produced to the FTC on request.
US
Failed
Online platforms must retain for five years (extendable to eight by FTC determination) a de-identified record for each algorithmic process describing the personal information categories used, the weighting/ranking method, the development data and training data, testing methodology for accuracy, fairness, bias, and discrimination, and — for non-small-business platforms using algorithmic processes in housing, education, employment, insurance, credit, or public accommodations — an assessment of whether the process produces disparate outcomes across protected characteristics.
US
Failed
Covered entities must maintain documentation of all impact assessments, including all information described in the assessment requirements, for three years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Failed
Law enforcement agencies whose officers use facial recognition must log all uses of facial recognition to the extent necessary to comply with the Act's reporting and audit requirements.
US
Failed
Federal law enforcement agencies using facial recognition must annually submit use data to the GAO for compliance audit. If violations are found, the agency must cease using facial recognition until all violations are corrected and must notify the public of the suspension.
US
Failed
State and local law enforcement agencies using facial recognition must annually submit use data to an independent state agency for compliance audit. If violations are found, the agency must cease using facial recognition until all violations are corrected and must notify the public of the suspension. Audit data must be disaggregated by race, ethnicity, gender, and age when feasible.
US
Failed
Covered entities must maintain documentation of all impact assessments, including the information described in Sec. 4(a), for three years beyond the duration of deployment of each automated decision system or augmented critical decision process.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must oversee the creation of AI governance charters for all covered federal AI systems, ensure they are regularly updated, publish them on the agency's public webpage, submit them to the Federal Register within 30 days of establishment or termination, and submit them to GSA for inclusion in the Federal AI System Inventory.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3595
Failed
Each agency head must establish and maintain an accurate AI governance charter for every federal AI system that is high-risk or that uses, is trained on, or produces individual records, documenting at minimum: system purpose and responsible officials, development and funding details, training data and testing information, ongoing oversight cadence, system usage including AI-assisted determinations, output data descriptions, and Privacy Act system-of-records information. Charters must be updated within 30 days of any significant system change.
US
Failed
Online platforms must retain for five years (extendable to eight) a de-identified record describing each algorithmic process, including personal information categories used, weighting methods, development data, training data, and testing for accuracy, fairness, bias, and discrimination. Non-small-business platforms using algorithms related to housing, education, employment, insurance, credit, or public accommodations must include a disparate-impact assessment across protected characteristics. Records must be produced to the FTC upon request.
US
Failed
Covered entities must maintain documentation of each impact assessment, including all information described in Sec. 4(a), for 3 years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Failed
Critical-impact AI organizations must perform a documented TEVV-based risk management assessment no later than 30 days before making a critical-impact AI system publicly available, and biennially thereafter. The assessment must cover (1) organizational AI risk management policies and processes, (2) the system's structure, context, and capabilities, (3) quantitative and qualitative risk measurement methods and metrics, and (4) risk resource allocation and monitoring. Assessment reports must be submitted to the Secretary of Commerce within 90 days of completion in a format the Secretary determines.
US
Failed
Covered entities must maintain documentation of all impact assessments, including the information described in Section 4(a), for three years beyond the duration of the system's deployment.
US
Failed
Developers must, upon reasonable deployer request, make available compliance information including pre-deployment evaluation reports and annual reviews, and must either cooperate with deployer-conducted assessments or arrange for an independent auditor assessment of the developer's practices and provide that report to the deployer.
UT
UT SB 149 (AI Policy Act) § Utah Code § 13-70-304
Failed
Learning Laboratory participants must retain records as required by Office rule or the participation agreement.
G-01.5
Third-party audit and certification
High-risk AI systems must be submitted to a qualified independent auditor for evaluation, and results disclosed to regulators or publicly.
Enacted
1
Live
23
Failed
19
Total
43
NY
Enacted eff 2025-12-19
Large developers must annually retain an independent third party to audit compliance with § 1421, beginning on the effective date of the article or 90 days after first qualifying as a large developer, whichever is later. The auditor must be granted access to unredacted materials and must produce a report including: (1) a detailed assessment of compliance steps; (2) identified instances of noncompliance and improvement recommendations; (3) assessment of internal controls, including designation and empowerment of senior personnel responsible for compliance; and (4) the lead auditor's certifying signature. The large developer must retain the unredacted report for deployment plus five years, conspicuously publish a redacted copy, transmit a redacted copy to DHSES, and grant DHSES or the attorney general access to the unredacted report upon request.
CA
CA SB 1119 (Companion Chatbot Child Safety) § Bus. & Prof. Code § 22614
Engrossed eff 2027-07-01
Operators must submit to an annual independent audit assessing compliance with this chapter, conducted by an auditor certified by the Attorney General, beginning 180 days after the AG adopts implementing regulations. Within 90 days of completing each audit, the auditor must submit an AI child safety audit report to the Attorney General. Audit reports are confidential, except that the AG may disclose specific information to: (1) government agencies or public prosecutors for enforcement; (2) qualified researchers under confidentiality agreements; and (3) independent child safety organizations for developing safety standards or educational resources, subject to confidentiality protections.
NY
Engrossed
Developers of high-risk AI systems must cause independent third-party audits to be conducted on the following schedule: (1) a first audit within six months after completion of development and initial offering to a deployer (or initial deployment if the developer deploys), and (2) annually thereafter. Developer audits must include an evaluation of whether the developer took reasonable care to prevent foreseeable algorithmic discrimination and an evaluation of the developer's risk management policy and program for conformity with § 89. The auditor must be independent — no prior services to the commissioning company in the past 12 months, no competitive AI business within five years, and no contingent fees or bonuses for audit results. Audits may use AI assistance for controlled testing and pattern detection but may not be completed entirely by AI, and auditors may not use a separate high-risk AI system or draft audits without meaningful human review. Auditors must have complete and unredacted copies of all previously filed § 88 reports. Audits completed under other applicable laws that meet all requirements of this section are deemed to satisfy its requirements.
NY
Engrossed
Deployers of high-risk AI systems must cause independent third-party audits to be conducted on the following schedule: (1) a first audit within six months after initial deployment, (2) a second audit within one year after the first, and (3) biennially thereafter. Deployer audits must include an evaluation of whether the deployer took reasonable care to prevent foreseeable algorithmic discrimination, an evaluation of system accuracy and reliability for intended and actual use cases, and an evaluation of the deployer's risk management policy and program for conformity with § 89. The same auditor independence, AI-use restrictions, and compliance-equivalence rules applicable to developer audits under this section apply to deployer audits.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-973
Introduced eff 2027-01-01
Covered entities must annually submit all compulsive-use risk-assessment records to an independent auditor, who must assess compliance with § 10-1-973 and recommend remediation.
ID
ID HB 945 (AI Medical Services Act) § Idaho Code § 54-6007
Introduced eff 2026-07-01
Sandbox applicants must submit a determination to the Board ethicist on whether their data collection constitutes human-subjects research under 45 CFR 46, and if so (or if elected for federal-research purposes) must obtain IRB approval — from the state-centralized IRB or an accredited external IRB — before commencing data collection.
IL
Introduced
Developers must retain a reputable third-party auditor at least annually to assess protocol compliance, protocol clarity, and potential truthfulness or redaction violations. Developers must grant auditors access to all compliance materials, and must conspicuously publish the audit report within 90 days of completion.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor (with corporate compliance and foundation model safety expertise) to assess (1) compliance with the public safety plan and instances of noncompliance, (2) plan clarity, and (3) reasonableness of redactions and accuracy of published statements. The developer must grant the auditor full access to compliance materials, retain the audit report for 5 years, and make the unredacted report available to the Attorney General on request.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor — employing individuals with corporate compliance and foundation model safety expertise — to assess compliance with the public safety plan, evaluate clarity of plan language, and review redactions and public statements for reasonableness and truthfulness. Developers must grant the auditor full access to compliance materials, retain audit reports for 5 years, and allow the Attorney General to inspect unredacted reports upon request.
IL
Introduced eff 2027-01-01
Covered businesses must, at their own expense and at least annually, obtain an independent audit of all long-term holdout assessments and the holdout assessment disclosure, and must provide the independent auditor full cooperation and access to information and operations.
LA
Introduced eff 2027-01-01
Large frontier developers must, beginning July 1, 2028, and annually thereafter, retain an independent third-party auditor (with no financial interest in the developer beyond audit fees) to produce a certified report assessing whether the developer substantially complied with its frontier AI framework and identifying any material deviations. The developer must publish a high-level summary of the audit findings on its website within 30 days of receiving the report.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must annually retain an independent third-party investigator to conduct a compliance investigation and produce a detailed report covering the developer's compliance steps, any noncompliance, internal controls, and senior personnel designation, certified by the lead investigator's signature.
MI
Introduced eff 2026-01-01
Large developers must retain a reputable third-party auditor at least once per year, beginning January 1, 2026, to produce a report assessing: (1) whether the developer complied with its safety and security protocol and any instances of noncompliance; (2) any instance where the protocol was not stated clearly enough to determine compliance; and (3) any instance the auditor believes the developer violated the truthfulness, publication, or redaction requirements. The developer must grant the auditor access to all materials produced under this act and any other materials reasonably necessary for the assessment. The auditor must employ or contract at least one individual with corporate compliance expertise and at least one individual with technical expertise in foundation model safety.
MI
Introduced
After a security breach, the employer must contract with a third party to perform an audit of the compromised electronic monitoring tool or automated decisions tool to ensure that all vulnerabilities have been fixed.
MN
MN HF 3980 (Online Platform Algorithmic Transparency) § Minn. Stat. § 325M.35, subd. 6
Introduced
Covered businesses must at least annually obtain, at their own expense, an independent audit of their long-term holdout assessments and disclosures, and must provide the auditor with full cooperation and access to information and operations needed for a comprehensive and accurate report.
MN
MN SF 4380 (Online Platform Metrics) § Minn. Stat. § 325M.35, subd. 6
Introduced
Covered businesses must at least annually obtain, at their own expense, an independent audit of the long-term holdout assessments and the holdout assessment disclosure, providing the auditor full cooperation and access to all information and operations needed to ensure the audit is comprehensive and accurate.
MO
Introduced
Vendors must complete an independent academic-effectiveness review by a qualified evaluator with no financial relationship to the vendor, using transparent and publicly available methods. The evaluation must demonstrate measurable improvement in student learning, alignment with Missouri standards, absence of addictive design features, and positive, reliable, and replicable academic outcomes. Contracting entities must obtain the evaluation documentation before software is made available for student use.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 516
Introduced
Every operator of a licensed high-risk advanced AI system must establish an ethics and risk management board composed of at least five individuals who are independent — no board member may be a member, officer, or director of the operator's entity. The board must assessthe ethical implications of all possible use cases (intended and unintended, likely and unlikely) and the current operational outcomes of the system. The board must adopt self-governing rules for its decision-making processes. Operators with multiple licensed systems under supplemental licenses are not required to maintain more than one board.
NY
Introduced
Large frontier developers must annually engage an independent third-party verifier to produce a report assessing (1) compliance with the developer's frontier AI framework, (2) framework adequacy, (3) propriety of any redactions in published documents, and (4) consistency of public statements about catastrophic risk with the verifier's findings.
NY
Introduced
Large frontier developers must not condition any payment or compensation to a third-party verifier upon the results of the verifier's assessment.
NY
Introduced
Prior to January 1, 2029, large frontier developers may choose their own third-party verifier but must not engage a verifier with a mutual financial stake — the developer may not retain a verifier that has a financial stake in the developer, nor a verifier in which the developer has a financial stake.
NY
Introduced
On and after January 1, 2029, large frontier developers must use only third-party verifiers accredited by the state office for the annual compliance assessment report.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(J)
Introduced eff 2026-11-01
Contractors and vendors handling student data must (1) sign a Parent Data Privacy Agreement, (2) employ industry-standard encryption, multi-factor authentication, and secure data storage, (3) delete or return all data within ninety days of contract termination, and (4) submit to random privacy and security audits by the Department or an independent third-party auditor. Vendors in violation may be debarred from state contracts for up to five years.
US
Introduced
Providers of covered platforms must engage an independent third-party auditor for an annual audit covering minor-user access, usage metrics, harm-mitigation policies, safeguard and parental-tool usage counts, harm-report volumes by category, personal-information collection practices, and design-feature impact processes, and must submit audit results to the FTC within 30 days of completion.
CA
CA AB 3211 (Digital Content Provenance Standards) § Bus. & Prof. Code § 22949.90.4
Failed
Generative AI system providers, generative AI system distributors, and large online platforms must, beginning January 1, 2026, and annually thereafter, produce a Risk Assessment and Mitigation Report assessing synthetic content risks and harms — including AI-generated CSAM, NCII, election and public health disinformation, and plagiarism. The report must be audited by qualified independent auditors using state-of-the-art techniques and applicable national and international AI auditing standards.
IL
Failed eff 2027-01-01
Operators must obtain an independent, third-party audit assessing the operator's compliance with this Act at least once every two years. Operators must make publicly available on their website a high-level summary of the audit's findings, excluding confidential or proprietary information.
MD
MD HB 1240 (AI in Health Care Decisions) § Health – General § 24–2503
Failed
Health care providers that use AI to determine or influence health care decisions must undergo an annual third-party audit, by July 1 beginning in 2026, evaluating whether AI-driven decisions align with medical care standards, meet ethical standards, or excessively delay care. Providers must submit proof of audit completion to the Department upon request.
MD
MD HB 1240 (AI in Health Care Decisions) § Insurance § 15–147
Failed
Carriers that use AI to determine or influence health care decisions must undergo an annual third-party audit, by July 1 beginning in 2026, evaluating whether AI-driven decisions align with medical care standards, meet ethical standards, or excessively delay care. Carriers must submit proof of audit completion to the Commissioner upon request.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Failed
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, U.S. Attorneys, or their designees.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–505
Failed
Law enforcement agencies must complete an annual compliance audit beginning October 1, 2023, retain all audit materials for at least three years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorney, U.S. Attorney, or their designees.
MT
Failed
The criminal intelligence information section must adopt an audit process to ensure facial recognition technology is used only for legitimate law enforcement purposes, including auditing uses and requests by law enforcement agencies.
NC
Failed
Licensees must conduct regular inspections and perform an annual third-party audit of their chatbot operations. Results of all inspections and audits must be made available to the Department.
NC
Failed
Licensees must conduct regular inspections and perform an annual third-party audit, and make all inspection and audit results available to the Department.
NY
Failed
Large developers must annually retain an independent third party to perform a compliance audit of the requirements of this section, beginning on the effective date of the article or 90 days after the developer first qualifies as a large developer, whichever is later. The auditor must be granted access to unredacted materials and must produce a report that includes: (1) a detailed assessment of the developer's compliance steps, (2) identified instances of noncompliance and improvement recommendations, (3) a detailed assessment of internal controls including designation and empowerment of senior compliance personnel, and (4) the lead auditor's certifying signature. The developer must retain an unredacted copy of the report for the deployment period plus five years, conspicuously publish a redacted copy, transmit the redacted report to the Division of Homeland Security and Emergency Services, and grant the Division or the Attorney General access to the full report (with redactions only as required by federal law) upon request.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 416
Failed
Operators must establish an independent ethics and risk management board of at least five members — none of whom may be a member, officer, or director of the operator — to assess the ethical implications and operational outcomes of all use cases of each licensed high-risk AI system.
OK
Failed
Deployers must subject high-risk AI systems to annual independent audits to ensure compliance with legal and ethical standards.
US
Failed
Federal law enforcement agencies using facial recognition must annually submit use data to the GAO for compliance audit. If violations are found, the agency must cease using facial recognition until all violations are corrected and must notify the public of the suspension.
US
Failed
State and local law enforcement agencies using facial recognition must annually submit use data to an independent state agency for compliance audit. If violations are found, the agency must cease using facial recognition until all violations are corrected and must notify the public of the suspension. Audit data must be disaggregated by race, ethnicity, gender, and age when feasible.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3597
Failed
Each agency's Inspector General must perform an independent biennial evaluation of the agency's AI governance compliance — including the completeness and timeliness of AI governance charters — and submit a report to the agency head, OMB Director, and appropriate congressional committees.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3597
Failed
The Comptroller General must periodically evaluate and report to Congress on the effectiveness of agency AI governance, implementation of the subchapter, and whether requirements reflect technology advancements, including legislative recommendations.
US
Failed
Covered platforms subject to the transparency report requirement must cooperate with the independent third-party auditor by providing all relevant information, material, and system access, and must not misrepresent any relevant fact.
UT
UT HB 438 (AI Companion Chatbot Safety) § Utah Code § 13-72b-202
Failed eff 2026-05-06
Suppliers must, beginning May 1, 2027, facilitate independent evaluation of safety protocols by either (1) commissioning an independent assessment from a qualified third party applying standards at least as rigorous as the NIST AI RMF, with no prior consulting relationship or financial interest, or (2) providing reasonable accommodations for independent research evaluations.
WA
Failed
Each algorithmic accountability review office must conduct selective audits of filed reports during the transitional period (effective date through January 1, 2024), and beginning January 1, 2024 must conduct annual audits covering compliance with approved reports, known or suspected policy violations, systematic bias or disproportionate-impact issues, and recommendations for legislative revision. The state CIO must establish audit-scope guidelines by January 1, 2022. Annual audits must be published on the review office's website by March 1 each year.
G-01.6
Designated AI accountability role
A specific individual or office must be formally designated as responsible for AI governance, with defined responsibilities, authority, and resources. SPublic disclosure of the designated role may be required.
Enacted
2
Live
14
Failed
23
Total
39
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Enacted eff 2024-10-01
Law enforcement agencies using FRT must designate an employee responsible for overseeing and administering FRT use in compliance with this subtitle and applicable local laws, regulations, and policies.
NE
Enacted eff 2026-01-01
Each covered online service must designate one or more officers to be responsible for the service's compliance with the Age-Appropriate Online Design Code Act.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must designate at least one employee to oversee compliance with the chapter and require that employee to conduct a prompt and comprehensive review of any credible compliance issue raised to them.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must designate at least one employee to oversee compliance with the chapter and require that employee to conduct a prompt and comprehensive review of any credible compliance issue related to the deployer's use of a covered ADS.
HI
Introduced
Deployers must implement and maintain a written, risk-based risk management program before and throughout deployment of any high-risk AI system, including (1) governance and accountability with designated responsible personnel, (2) documented policies covering the full AI lifecycle, (3) data governance controls, (4) pre-deployment testing and ongoing monitoring for errors, drift, and discrimination, (5) vendor and third-party risk controls, and (6) recordkeeping sufficient to demonstrate compliance.
ID
ID HB 945 (AI Medical Services Act) § Idaho Code § 54-6007
Introduced eff 2026-07-01
Every AAASP must designate and maintain on file with the Board a current designated responsible official authorized to bind the entity for compliance and receive legal process. L2 and L3 AAASPs must additionally designate a licensed Idaho physician as medical director responsible for clinical scope, safety protocols, escalation procedures, and quality assurance.
LA
Introduced
Covered insurers must designate a senior officer with responsibility for AI governance and compliance with this Act.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must ensure the safety and security protocol is implemented as written and must designate senior personnel responsible for monitoring and enforcing compliance by employees and contractors working on covered models and derivatives.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must designate staff responsible for compliance with the algorithmic system requirements of this section.
NJ
Introduced
Each State entity that utilizes, funds, or oversees algorithms must designate an algorithmic civil rights liaison to the Office of Algorithmic Civil Rights.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 516
Introduced
Every operator of a licensed high-risk advanced AI system must establish an ethics and risk management board composed of at least five individuals who are independent — no board member may be a member, officer, or director of the operator's entity. The board must assessthe ethical implications of all possible use cases (intended and unintended, likely and unlikely) and the current operational outcomes of the system. The board must adopt self-governing rules for its decision-making processes. Operators with multiple licensed systems under supplemental licenses are not required to maintain more than one board.
NY
Introduced
Deployers and developers must designate one or more employees responsible for overseeing and maintaining the governance program and compliance with this article. Designated employees may raise good-faith compliance concerns, and the employer must conduct a prompt and complete assessment of any issue raised.
OK
Introduced eff 2025-11-01
Deployers must establish an AI governance group with representation from qualified end-users. The governance group is responsible for overseeing compliance with this act.
US
Introduced
Each covered agency must maintain an office of civil rights staffed with experts and technologists focused on bias, discrimination, and other harms from covered algorithms with respect to protected characteristics.
US
Introduced
Covered entities must establish and maintain an AI/CDSS committee with at least equal non-manager representation and labor organization membership that convenes within 120 days of enactment or AI/CDSS adoption, provides consultation on AI/CDSS policies, and meets at least quarterly to review policy implementation and report findings and improvement suggestions to the entity.
US
Introduced
Each covered agency must maintain an office of civil rights that employs experts and technologists focused on bias, discrimination, and other harms from covered algorithms affecting individuals based on protected characteristics.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable safeguards to manage algorithmic discrimination risks, proportionate to the tool's use and the entity's role and resources. The program must (1) designate at least one employee responsible for compliance oversight with authority to raise compliance concerns, (2) identify and implement anti-discrimination safeguards, (3) conduct annual comprehensive compliance reviews, (4) retain impact assessment results for five years after completion, and (5) adjust safeguards in light of material changes in technology, risk, or operations.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.4
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage algorithmic discrimination risks. The program must (1) designate at least one compliance employee with authority to raise compliance concerns and trigger prompt internal investigation, (2) identify and implement discrimination safeguards, (3) provide for required impact assessments, (4) conduct an annual comprehensive compliance review, (5) retain impact assessment results for two years, and (6) adjust safeguards in response to material changes in technology, risk, standards, or business operations.
CA
Failed
Covered deployers must designate one or more employees to maintain the comprehensive information security program.
HI
Failed
Each state agency, department, and branch of government must appoint senior-level personnel responsible for maintaining and updating the high-risk AI use inventory.
IL
Failed
Deployers must designate at least one employee to oversee and maintain the governance program and compliance with the Act. That employee must have authority to raise compliance concerns in good faith, and the employer must promptly and completely assess any compliance issue the designated employee raises.
IL
Failed
Deployers must designate at least one employee to oversee and maintain the governance program and ensure compliance with the Act. The designated employee must have authority to assert a good faith belief that the design, production, or use of an automated decision tool does not comply with the Act. The employer must promptly and completely assess any compliance issue raised by the designated employee.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must designate staff to be responsible for compliance with the algorithmic system requirements of this section.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Failed
Law enforcement agencies that use or contract for facial recognition technology must designate an employee responsible for overseeing and administering FRT use in compliance with the subtitle and applicable local laws, regulations, and policies.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–505
Failed
Law enforcement agencies that use or contract for facial recognition technology must designate an employee responsible for overseeing and administering the use of the technology in compliance with the subtitle and applicable local laws, regulations, and policies.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 416
Failed
Operators must establish an independent ethics and risk management board of at least five members — none of whom may be a member, officer, or director of the operator — to assess the ethical implications and operational outcomes of all use cases of each licensed high-risk AI system.
NY
Failed
Deployers and developers must designate one or more employees responsible for overseeing and maintaining the governance program and compliance with this article. Designated employees may assert good-faith compliance concerns, and the employer must conduct a prompt and complete assessment of any compliance issue so raised.
OK
Failed
Deployers must establish governance groups to oversee the classification, deployment, and monitoring of high-risk AI systems.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-5
Failed
Deployers and developers must designate at least one employee responsible for overseeing the governance program and chapter compliance, with authority to raise good-faith compliance concerns; the employer must promptly and completely assess any issue raised by the designated employee.
US
Failed
Each covered agency must establish and maintain an office of civil rights that employs experts and technologists focused on bias, discrimination, and other harms resulting from covered algorithms.
US
Failed
Online platforms must certify under oath — signed by the CEO, CPO, COO, CISO, or equivalent senior officer attesting to personal knowledge — the accuracy and completeness of each required disclosure within 30 days of the disclosure and annually thereafter, plus upon any material change.
US
Failed
Each covered agency must establish and publicly post on its website within 90 days of enactment a policy governing its use of facial recognition systems to ensure officer compliance with the Act.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must delegate primary AI compliance authority and accountability to the agency Chief Information Officer (or comparable official).
US
Failed
Online platforms must certify under oath — through a senior executive (CEO, CPO, COO, CISO, or equivalent) — the accuracy and completeness of all algorithmic process, content moderation, and advertisement library disclosures within 30 days of making each disclosure, annually thereafter, and upon any material change.
US
Failed
The OMB Director must establish a Chief Artificial Intelligence Officers Council within 90 days of enactment, comprising CAIOs from CFO Act agencies and other designated members, to coordinate interagency AI practices, share best practices, and manage AI-related risks across the federal government.
US
Failed
Each agency head must hire or designate a Chief Artificial Intelligence Officer at the senior executive level (above GS-15) responsible for AI policy development, governmentwide compliance, risk management planning (including risk-level classification), rights-protective design and deployment, and participation in budget and acquisition decision processes.
US
Failed
The OMB Director must issue guidance within 120 days directing each CFO Act agency to establish an internal AI Governance Board — chaired by the CAIO and including designated senior officials (deputy head, CIO, chief acquisition officer, chief data officer, senior privacy official, civil rights official, and others) — to coordinate and govern the agency's AI issues.
US
Failed
The Director of OMB must establish the Artificial Intelligence Hygiene Working Group within 45 days of enactment and appoint its members from appropriate interagency councils.
US
Failed
Covered agencies must establish and maintain an office of civil rights that employs experts and technologists focused on bias, discrimination, and other harms resulting from covered algorithms.
G-01.7
AI System Operator Training
Deployers using AI systems in consequential decision-making contexts must train personnel who operate or rely on the system on its inputs, outputs, known biases, limitations, potential adverse effects, applicable appeals processes, and inappropriate or out-of-scope uses.
Enacted
1
Live
4
Failed
4
Total
9
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-505
Enacted eff 2024-10-01
Law enforcement personnel authorized to use FRT must annually complete training administered by the Department of Public Safety and Correctional Services, including training on cultural diversity and implicit bias.
IL
Introduced
Health care entities must provide registered professional nurses with training on the intended use, data limitations, and known failure modes of each AI system deployed in direct patient care.
IL
Introduced
Health care entities must provide registered professional nurses with training on the intended use, data limits, and known failure modes of each AI system deployed in direct patient care.
IN
Introduced eff 2026-07-01
Employers must train every individual or entity that operates the automated decision system or uses its output on: (1) the input information used by the system; (2) the appeals process for the output; (3) potential biases in automated decision systems; (4) limitations of the system; (5) potential adverse effects to covered individuals; (6) potential errors or problems related to the system; and (7) examples of inappropriate uses of the system.
US
Introduced
Covered entities must provide training to health care professionals on how to use AI/CDSS, circumstances where override is appropriate, how to override outputs, AI/CDSS development processes and data inputs, and potential limitations and biases of the AI/CDSS.
US
Failed
Employers must train all individuals or entities that operate or use an automated decision system on the system's input data, appeals process, potential biases, limitations, potential adverse effects on workers, potential errors, and examples of inappropriate uses.
US
Failed
Employers must train any individual or entity that operates or uses an automated decision system's output on the system's inputs, appeals process, potential biases, limitations, potential adverse effects, potential errors, and examples of inappropriate uses.
VA
Failed
State agencies must train all staff who use the automated decision system for employment decisions to comply with applicable federal and state law and to ensure the system does not result in algorithmic discrimination.
VA
Failed
Local government entities must train staff who use the automated decision system for employment decisions to comply with applicable federal and state law and to ensure the system does not result in algorithmic discrimination.