CA
Enacted eff 2026-01-01
When frontier developers publish documents to comply with this chapter, they may redact information necessary to protect trade secrets, cybersecurity, public safety, national security, or to comply with federal or state law. If a redaction is made, the developer must describe the character and justification of each redaction in the published version of the document to the extent permitted, and must retain the unredacted information for five years.
CO
Enacted eff 2026-05-14
Developers must retain records reasonably necessary to demonstrate compliance with § 6-1-1702 for at least three years after the creation of each record (or longer if required by other law). Records include system version identifiers, changelogs, and documentation and notices of material updates provided to deployers.
CO
Enacted eff 2026-05-14
Deployers must retain records reasonably necessary to demonstrate compliance with Part 17 for at least three years after the date of each consequential decision (or longer if required by other law). Records may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes.
KY
Enacted eff 2022-04-08
The working group must create and make publicly available by January 1, 2024, a model policy for law enforcement use of facial recognition technology covering authorized uses (including a prohibition on identifying persons in constitutionally protected activities absent probable cause), personnel authorization, documentation of use, secondary-examiner confirmation of findings, data integrity and retention, data security and data-sharing, training, image-source requirements, audit records, and privacy protections for nudity.
MD
Enacted eff 2024-10-01
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, United States Attorneys, or their designees.
MD
Enacted eff 2024-07-01
Each unit of State government must conduct an annual data inventory beginning December 1, 2024, identifying data necessary for operations or required by law, in a form prescribed by the Chief Data Officer, including notation of data used in artificial intelligence.
NY
Enacted eff 2025-12-19
Large developers must annually retain an independent third party to audit compliance with § 1421, beginning on the effective date of the article or 90 days after first qualifying as a large developer, whichever is later. The auditor must be granted access to unredacted materials and must produce a report including: (1) a detailed assessment of compliance steps; (2) identified instances of noncompliance and improvement recommendations; (3) assessment of internal controls, including designation and empowerment of senior personnel responsible for compliance; and (4) the lead auditor's certifying signature. The large developer must retain the unredacted report for deployment plus five years, conspicuously publish a redacted copy, transmit a redacted copy to DHSES, and grant DHSES or the attorney general access to the unredacted report upon request.
NY
Enacted eff 2027-01-01
Frontier developers that redact published documents for trade secret, cybersecurity, public safety, or national security reasons must describe the character and justification of each redaction in the published version and retain the unredacted information for five years.
VT
Enacted eff 2026-07-01
Suppliers of mental health chatbots must, to avail themselves of the affirmative defense against professional misconduct claims, create, maintain, and implement a comprehensive written policy that: states the chatbot's intended purposes, abilities, and limitations; ensures licensed mental health provider involvement in development and review; ensures clinical best practices compliance; describes pre-launch and ongoing testing procedures; identifies foreseeable adverse outcomes; provides user harm-reporting mechanisms; describes real-time risk response protocols; ensures regular safety, accuracy, and efficacy reviews (internal or external); provides safe-use instructions; ensures users understand they are interacting with AI and understand the chatbot's purpose, capabilities, and limitations; prioritizes user safety over engagement metrics; implements nondiscrimination measures; and ensures HIPAA-level privacy and security compliance. Suppliers must also maintain documentation describing foundation models, training tools, federal health privacy compliance, data practices, and ongoing accuracy and safety efforts.
CA
Engrossed
Developers must retain in unredacted form all performance evaluations, deployer documentation, auditor correspondence, and redaction records for as long as the developer deploys the covered ADS or makes it available to potential deployers, plus 10 years.
CA
Engrossed
Deployers must retain in unredacted form all developer documentation, subject disclosures, correction requests, opt-out requests, appeal requests, auditor correspondence, and redaction records for as long as the deployer uses the covered ADS, plus 10 years.
CA
Engrossed
Enrolled AI auditors must, after completing a covered audit, provide the auditee with an audit report containing (1) the scope and objectives of the audit, (2) audit results with supporting documentation, (3) steps to meet generally accepted industry standards, (4) steps to become compliant with state law, and (5) a signed and dated certification statement from each auditor.
CA
Engrossed
Enrolled AI auditors must retain all documentation provided to auditees and documentation necessary to demonstrate the basis of audit results for at least 10 years.
CA
Engrossed
Developers must retain all documentation required by this title for the commercial life of the GenAI system or model plus 10 years.
CA
Engrossed
MROs must retain all documents related to their activities under this chapter for ten years.
NH
Engrossed eff 2027-01-01
Health carriers must maintain records identifying the use of artificial intelligence tools in claims processing and must make such records available to the Insurance Department upon audit.
RI
Engrossed eff 2026-06-30
Insurers must maintain documentation of all AI decisions — including adverse benefit determinations where AI made or substantially influenced the determination — for at least five years.
VA
Engrossed
Carriers must maintain documentation of AI decisions for at least three years.
AZ
Introduced
Chatbot providers must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of personal data and chat logs maintained. The program must be made publicly available on the chatbot provider's website.
CA
Introduced
Employers must maintain an updated list of all workplace AI tools currently in use and provide that list to workers annually.
GA
Introduced
Deployers must establish and adhere to (1) written standards, policies, procedures, and protocols for the acquisition, use of, or reliance on automated decision systems developed by third-party developers, including reasonable contractual controls ensuring developer disclosures include all information necessary for the deployer to fulfill its obligations; (2) procedures for reporting incorrect information or evidence of algorithmic discrimination to the developer for investigation and mitigation; and (3) procedures to remediate and eliminate incorrect information from its automated decision systems.
GA
Introduced eff 2027-01-01
Covered entities must contemporaneously document each step of the compulsive-use risk-assessment process — including supporting experiments, evidence, and data — and retain the documentation for ten years, with all individual-consumer data de-identified and anonymized.
HI
Introduced eff 2028-07-01
Health care providers that use AI to make or substantially factor into consequential decisions must maintain: (A) an updated inventory of their AI systems; (B) documentation on the system design, intended use, and training data of the AI systems; (C) records of monitoring, performance evaluations, and oversight activities; and (D) documentation of findings and corrective actions taken to address deficiencies identified through monitoring or performance evaluations.
HI
Introduced
Deployers must implement and maintain a written, risk-based risk management program before and throughout deployment of any high-risk AI system, including (1) governance and accountability with designated responsible personnel, (2) documented policies covering the full AI lifecycle, (3) data governance controls, (4) pre-deployment testing and ongoing monitoring for errors, drift, and discrimination, (5) vendor and third-party risk controls, and (6) recordkeeping sufficient to demonstrate compliance.
HI
Introduced
Deployers must retain impact assessments and risk management program documentation for at least five years after the system is retired or materially modified, whichever is later, and must make them available to the Executive Director of the Office of Consumer Protection or the Attorney General upon request. Confidential commercial information is protected to the extent permitted by law.
HI
Introduced
Deployers must maintain documentation sufficient to identify the AI system used, the nature of the output relied upon, and the decision process whenever an AI system output is a substantial factor in an adverse action, and must retain records adequate to support required disclosures and meaningful human review.
IA
Introduced
Health carriers must maintain per-claim documentation for every claim downcoded by an automated adjudication system — showing the submitted code, the adjusted code, the reason for the downcode, and whether a clinical reviewer conducted a review — and retain it for at least five years from the claim payment date.
IA
Introduced
Employers must maintain an updated list of all automated decision systems currently in use to facilitate implementation of the chapter's notice and employee-rights requirements.
ID
Introduced eff 2026-07-01
AAASPs must maintain immutable production-version snapshots of every deployed algorithm — including weights, decision logic, and prompt-engineering instructions — retain them for two years to allow retrospective replay during Board audits, and must not alter or delete snapshots related to any matter under investigation.
IL
Introduced
Developers must record and retain for at least 5 years all specific tests and test results from critical risk assessments, with sufficient detail to allow qualified third parties to replicate the testing.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers may redact published documents for trade secrets, cybersecurity, public safety, national security, or legal compliance, but must describe the character and justification of each redaction in the published version and must retain unredacted information for 5 years.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor (with corporate compliance and foundation model safety expertise) to assess (1) compliance with the public safety plan and instances of noncompliance, (2) plan clarity, and (3) reasonableness of redactions and accuracy of published statements. The developer must grant the auditor full access to compliance materials, retain the audit report for 5 years, and make the unredacted report available to the Attorney General on request.
IL
Introduced
Frontier developers that redact published documents for trade secret, cybersecurity, public safety, or national security reasons must describe the character and justification of each redaction in the published version and retain the unredacted information for 5 years.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers that redact information from publicly published documents must describe the character and justification of each redaction in the published version and retain the unredacted information for 5 years.
IL
Introduced eff 2027-01-01
Large frontier developers must annually retain a reputable third-party auditor — employing individuals with corporate compliance and foundation model safety expertise — to assess compliance with the public safety plan, evaluate clarity of plan language, and review redactions and public statements for reasonableness and truthfulness. Developers must grant the auditor full access to compliance materials, retain audit reports for 5 years, and allow the Attorney General to inspect unredacted reports upon request.
IL
Introduced
Frontier developers must describe the character and justification of any redaction in published documents to the extent permitted by the redaction rationale, and must retain unredacted information for 5 years.
IL
Introduced
Registered professional nurses must document in the treatment record the AI system name, version, and a brief description of the AI's role whenever AI is used in direct patient care.
KS
Introduced
Health insurers must establish written policies and procedures that (1) describe the process by which the health benefit plan prospectively, retrospectively, or concurrently reviews and approves, modifies and delays, or denies requests based in whole or in part on medical necessity, and (2) require that medical necessity decisions are consistent with criteria or guidelines supported by clinical principles and processes.
LA
Introduced
Employers must maintain an updated list of all automated decision systems currently in use.
LA
Introduced
Covered insurers must adopt written governance policies and procedures for the development, validation, deployment, monitoring, and retirement of algorithmic decision systems, addressing roles and responsibilities, pre-deployment disparate impact testing, ongoing monitoring, investigation and remediation procedures, documentation, and escalation.
LA
Introduced eff 2027-01-01
Frontier developers that redact information from published documents must describe the character and justification of each redaction in the published version and must retain the unredacted information for five years.
MA
Introduced
Covered entities and service providers must publish a detailed, accessible, reasonably understandable privacy policy on their homepage covering data categories, processing purposes, third-party transfers, retention periods, individual rights, data security practices, and effective date. Material changes require advance notice to affected individuals and an opportunity to withdraw consent.
MA
Introduced
Large data holders must retain and publish prior privacy policy versions for at least 10 years with a public change log, and must provide a short-form notice of no more than 500 words. Entities collecting biometric data or precise geolocation information must each maintain a separate privacy policy for those data types.
MA
Introduced
Covered entities must engage service providers only under written contracts specifying processing instructions, data types, purposes, duration, and mutual obligations. Service providers must adhere to covered entity instructions, assist with individual rights requests, maintain security safeguards, allow compliance assessments, delete or return data upon termination, and retain copies of all service provider contracts.
MA
Introduced
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI under this section.
MA
Introduced
Law enforcement agencies conducting an emergency facial recognition search must (1) immediately document the factual basis for the emergency belief, (2) narrowly tailor the search to address the emergency, and (3) within 48 hours of obtaining results, file a signed, sworn statement with the superior court setting forth the grounds for the search.
MA
Introduced
The Department of State Police must document in writing every facial recognition search request made to the Federal Bureau of Investigation.
MA
Introduced
Law enforcement agencies must (1) immediately document the factual basis for any emergency facial recognition search, (2) ensure the search is narrowly tailored to the emergency, and (3) within 48 hours of obtaining search results, file a signed, sworn statement by a supervisory official with the superior court in the relevant jurisdiction setting forth the emergency grounds.
MA
Introduced
Controllers must execute written contracts with processors specifying processing instructions, purpose, data types, duration, and obligations. Processors must maintain confidentiality, assist with consumer rights and security obligations, support data protection assessments, delete or return data at service end, not combine data across controllers, cooperate with compliance assessments, and maintain their own data security practices consistent with chapter 93H.
MA
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous and accurate records of all data collected via electronic monitoring, destroy monitoring data no later than 37 months after collection (absent employee consent), maintain reasonable data security practices, and honor employee requests to correct erroneous data.
MA
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool — including data sources, technical specifications, development personnel, and historical use data — with a historical record of tool versions. Documentation must be legible, accessible to auditors, and available to labor organizations as required by law.
MA
Introduced
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI under this section.
MA
Introduced
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency, (2) narrowly tailor the search to address the emergency, and (3) file a signed, sworn statement with the superior court within 48 hours of obtaining search results.
MA
Introduced
Frontier developers that redact published documents must describe the character and justification of each redaction in the published version and must retain unredacted information for five years.
MA
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of data collected via electronic monitoring tools to ensure compliance with employee or commissioner data requests. Employers must destroy employee information collected via electronic monitoring no later than thirty-seven months after collection unless the employee provides written informed consent to retention. Employers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of employee data. Employees have the right to request corrections to erroneous employee data.
MA
Introduced
Employers or their vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct an impact assessment, including source data, technical specifications, developer information, and historical use data. Documentation must include a historical version record enabling the employer to attest to the tool's specifications at the time of any disputed employment decision. Vendor-held documentation must be licensed to the employer and shareable with labor organizations and courts. Documentation must be stored per commissioner-specified requirements and must be legible and accessible to the auditor. Employee data collected for impact assessments must be processed and stored to protect privacy, must not be shared with the employer, and must not be shared with anyone unless strictly necessary for the assessment.
MA
Introduced
Developers must retain an unredacted copy of the safety and security protocol, including records and dates of all updates or revisions, for at least five years after the covered model is no longer available for commercial, public, or foreseeably public use.
MI
Introduced eff 2026-01-01
Large developers must record and retain for five years all specific tests used and results obtained as part of any assessment of critical risk, with sufficient detail for qualified third parties to replicate the testing.
MI
Introduced
Employers must retain all documentation pertaining to the design, development, use, and data of electronic monitoring tools and automated decisions tools that may be necessary to conduct an impact assessment, including the data source, technical specifications, individuals involved in development, historical use data, and version history. Service providers must allow employers access to this documentation. Employers must share the documentation with labor organizations as required by law or court order. Documentation must be stored in a manner prescribed by the director to ensure legibility and accessibility for assessment purposes.
MI
Introduced
Employers must retain all design, development, use, and data documentation necessary to conduct impact assessments, store it in the director-prescribed accessible manner, obtain access to service-provider documentation, and share it with labor organizations as required by law or in litigation.
MN
Introduced
Employers must maintain records of all worker data collected, used, or produced by an automated decision system — including all ADS input/output data and human reviewer corroborating evidence — for 36 months after the data's most recent collection, production, or use. Employers must destroy this data no later than 37 months after most recent collection, production, or use, unless the worker provides written and informed consent to longer retention. Employers must protect the confidentiality, integrity, and accessibility of worker data using data security practices consistent with applicable privacy and cybersecurity laws and appropriate to the volume and nature of the data.
MN
Introduced
Employers must retain data collected through electronic monitoring tools for 36 months, destroy it no later than 37 months after collection absent worker consent, and protect the confidentiality, integrity, and accessibility of worker data using security practices consistent with applicable data and cyber privacy laws.
MN
Introduced
Developers must record and retain information on the specific tests and test results used in any assessment of the AI model required under section 325M.41 or by the developer's safety and security protocol. Records must provide sufficient detail for third parties to replicate the testing procedure and must be retained for the entire deployment period plus five years.
MN
Introduced
IVOs must retain all documentation used in annual reports and all documentation relating to the assessment and verification of AI models and applications — including ongoing monitoring and corrective actions — for ten years after the relevant activity.
MN
Introduced
Developers must retain an unredacted copy of the safety and security protocol, including records and dates of all updates or revisions, for the entire deployment period plus five years. Developers must also record and retain information on the specific tests and test results used in any assessment of the AI model, with sufficient detail for third parties to replicate the testing procedure, for the entire deployment period plus five years.
MN
Introduced
Licensed IVOs must retain all documentation used in annual reports and all documentation relating to AI model and application assessments, verification activities, ongoing monitoring, and corrective actions for ten years after the relevant activity.
MN
Introduced eff 2027-01-01
Employers must retain electronic monitoring data for 36 months, destroy it by 37 months absent written worker consent, protect its confidentiality and integrity using data security practices appropriate to the volume and nature of data collected, and maintain it in a form producible to workers and the Commissioner of Labor and Industry.
MN
Introduced eff 2027-01-01
Employers must retain all worker data collected, used, or produced by an automated decision system — including inputs, outputs, and corroborating evidence used by human reviewers — for 36 months after the data's most recent collection, production, or use, in a form that can be produced to workers or the Commissioner of Labor and Industry.
MO
Introduced
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur when the initial purpose for collecting the data has been satisfied or within one year of the individual's last interaction with the entity, whichever occurs first. The entity must comply with its own established retention schedule and destruction guidelines absent a valid warrant or subpoena.
MO
Introduced eff 2027-01-01
Developers and deployers must maintain usage logs for all AI system content distributed for public consumption, including: (1) date and time of content generation, (2) identity of the user or entity generating the content, (3) input parameters or prompts used, (4) description of the output (type, file size, intended platform), and (5) metadata linking the log to the specific AI system and version.
MO
Introduced eff 2027-01-01
Developers and deployers must retain usage logs for a minimum of seven years from the date of content generation, unless otherwise required by law.
MO
Introduced eff 2027-01-01
Developers and deployers must store usage logs with encryption and control access to the logs to prevent unauthorized access.
MO
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous and accurate records of each employee's individual work performance data, aggregated work performance data for similar employees, the work performance standard provided to each employee, and written termination notices.
NJ
Introduced
Employers and public entities must maintain true and accurate records of all EMT-collected data, AEDS inputs and outputs, performance evaluations, validation results, and impact assessments for not less than three years. Data must be destroyed no later than 37 months after collection unless the individual provides uncoerced written consent for continued retention.
NY
Introduced
Employers must maintain an updated list of all automated decision systems currently in use.
NY
Introduced
Every licensed high-risk advanced AI system must automatically generate a log each time it operates. Logs must conform to Secretary-prescribed standards covering event types, format, access permissions, encryption, cybersecurity protocols, and preservation/disposal procedures. All logs must be preserved for ten years from the date of generation and must be available for regulatory inspection.
NY
Introduced
Every operator must maintain all books, records, source code, and logs as the Secretary requires. At minimum, operators must maintain a copy of all logs generated from the system and a backup of every version of the system, stored in a safe manner prescribed by the Secretary.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an AEDT that may be necessary to conduct an impact assessment for a period of three years, to ensure compliance with Commissioner requests for data.
NY
Introduced
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy that establishes a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur within a reasonable time — but no later than 60 days — after the data is no longer necessary for the permissible purpose identified in the notice or for which the individual provided authorization, or within three years of the individual's last interaction with the private entity, whichever occurs first. Absent a valid warrant or subpoena, the entity must comply with its established retention schedule and destruction guidelines.
NY
Introduced
Developers of general-purpose AI models must: (1) create and maintain technical documentation covering training and testing processes, compliance evaluation results, intended tasks, target integration systems, acceptable use policies, release date, distribution methods, and input/output modalities and formats — reviewed and revised at least annually; and (2) create, implement, maintain, and make available to downstream integrators documentation that enables understanding of the model's capabilities and limitations, facilitates compliance with this article, discloses technical integration requirements and the information listed in (1), and is reviewed and revised at least annually. Trade secrets and legally protected information are exempt.
NY
Introduced
Covered entities must retain the full impact assessment and summary for seven years and must produce them to the Department of Financial Services within seven days upon notice from the Superintendent.
NY
Introduced
Developers that do not intend their AI system to be used as high-risk must (1) contractually bar high-risk use with each authorized deployer, (2) implement reasonable technical safeguards against high-risk use, (3) prominently disclose the prohibition on their website, in marketing, and in licensing agreements, and (4) retain deployer agreements for at least five years.
NY
Introduced
Covered developers and deployers must plan, document, and implement an iterative risk management policy and program — reasonable against the NIST AI RMF v1.0 or ISO 42001 — that identifies, documents, and mitigates foreseeable risks of algorithmic discrimination across the high-risk AI system's life cycle, with regular review and updates.
NY
Introduced
Developers must enter written contracts with deployers that: (1) set forth data processing procedures for collection, processing, and transfer on behalf of the deployer; (2) include instructions for data handling, intended deployment, nature/purpose/type/duration of data processing, and mutual rights and obligations including material-change notification; (3) do not relieve either party of statutory obligations; (4) prohibit commingling of data received from the counterparty with data from other parties; and (5) do not prohibit either party from raising concerns to enforcement agencies. Developers must retain copies of all deployer contracts for at least 10 years.
NY
Introduced
Developers and deployers must notify each affected individual prior to implementing any material change to the public disclosure, using direct electronic notification in each covered language. Developers and deployers must retain each previous version of the disclosure for at least 10 years after the last day on which the version was effective, publish each version on their website, and maintain a publicly available log describing the date and nature of each material change — sufficient for a reasonable individual to understand the material effect of each change.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct an impact assessment for a period of three years.
NY
Introduced
Large frontier developers must retain the third-party verifier's report for a minimum of five years and must allow the state office or the Attorney General to inspect an unredacted version upon request.
NY
Introduced
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of all data collected via electronic monitoring tools. Employers must destroy employee data collected via electronic monitoring no later than 37 months after collection unless the employee has provided written and informed consent to continued retention.
NY
Introduced
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an AEDT necessary to conduct an impact assessment, including data sources, technical specifications, developer identities, historical use data, and a historical record of tool versions sufficient to attest to the tool's specifications at the time of any disputed employment decision. Documentation must be stored per Commissioner-specified requirements and be legible and accessible to auditors.
NY
Introduced
Developers of general-purpose AI models must create and maintain technical documentation covering: (1) training and testing processes; (2) evaluation results demonstrating article compliance; (3) as appropriate given size and risk profile — intended tasks, types of downstream AI systems the model is designed for, acceptable use policies, release date, distribution methods, and input/output modalities and formats. Documentation must be reviewed and revised at least annually or more frequently as necessary for accuracy. Developers must also create, implement, maintain, and make available to downstream integrators documentation enabling them to understand the model's capabilities and limitations, comply with the article, and integrate the model, including the technical means for integration and the information listed above. Integrator documentation must also be reviewed and revised at least annually.
NY
Introduced
Committees must keep records of their use of synthetic media during each campaign cycle, including the types of synthetic media utilized, the number of voters contacted with each type, and the amount of funds expended toward synthetic media.
NY
Introduced
Deployers and developers must, as part of their governance program: (1) identify and implement discrimination-risk safeguards, (2) conduct impact assessments per §§ 752–753, (3) perform annual comprehensive compliance reviews, (4) retain impact assessment results for at least two years, and (5) make reasonable adjustments to safeguards in light of material changes in technology, risk, standards, or business operations.
NY
Introduced
Covered entities must retain the full impact assessment and summary for seven years and produce them to the Department of Financial Services within seven days of notice from the superintendent.
OH
Introduced
Licensed IVOs must retain all documentation used to prepare their annual reports for ten years following submission.
OK
Introduced eff 2025-11-01
Deployers must ensure all documentation complies with state and federal medical record-keeping requirements and is accessible for regulatory review. Deployers must maintain documentation of relevant instances where a qualified end-user overrides or disagrees with AI device-generated outputs through a summary report indicating the frequency and nature of overrides, including the percentage or number of such overrides or disagreements.
OK
Introduced eff 2025-11-01
Deployers must maintain an updated inventory of all deployed AI devices, including device instructions for use and any relevant safety and effectiveness documentation, and make all such documentation accessible to all qualified end-users of each device.
OK
Introduced eff 2025-11-01
Deployers must document the use case and user training procedure for each deployed AI device.
OK
Introduced
Media advertising agencies must require all content creators to sign an attestation certifying whether advertisements contain digitized or synthetically altered content, retain those attestations for at least 24 months, and make them available upon request to the appropriate enforcement authority.
OK
Introduced eff 2026-11-01
Contractors and vendors handling student data must (1) sign a Parent Data Privacy Agreement, (2) employ industry-standard encryption, multi-factor authentication, and secure data storage, (3) delete or return all data within ninety days of contract termination, and (4) submit to random privacy and security audits by the Department or an independent third-party auditor. Vendors in violation may be debarred from state contracts for up to five years.
PA
Introduced
Social media companies must maintain documentation of how express parental or guardian consent was obtained for each minor account holder. Documentation may be deleted when the minor reaches age 16 or within the company's established data retention timeframe.
PA
Introduced
Facilities must retain records related to AI algorithms for the period determined by the Department of Health's record retention policy.
PA
Introduced
Insurers must retain AI-related records for the period determined by the Insurance Department's record retention policy.
PA
Introduced
MA or CHIP managed care plans must retain AI-related records for the period determined by the Department of Human Services' record retention policy.
PA
Introduced
Suppliers must maintain documentation regarding the development and implementation of the chatbot describing: (1) foundation models used in development; (2) training data used; (3) compliance with federal and state privacy law; (4) consumer data collection and sharing practices; and (5) ongoing efforts to ensure accuracy, reliability, fairness, and safety.
PA
Introduced
Facilities must retain records related to AI algorithms for a period to be determined by the Department of Health through a record retention policy. The department will establish the specific retention period.
PA
Introduced
Insurers must retain records related to AI algorithms for a period to be determined by the Insurance Department through a record retention policy.
PA
Introduced
MA or CHIP managed care plans must retain records related to AI algorithms for a period to be determined by the Department of Human Services through a record retention policy.
PA
Introduced
Participants must retain all records, documents, and data produced in the ordinary course of business regarding the tested product or service, submit quarterly reports including customer complaint information, and make records available for inspection upon the Office's request.
RI
Introduced
Insurers must maintain documentation of AI decisions for at least five years.
RI
Introduced
Insurers must maintain documentation of all artificial intelligence decisions for at least five years, including adverse benefit determinations where AI made or was a substantial factor in the determination.
RI
Introduced
Employers must establish, maintain, and preserve for five years contemporaneous, true, and accurate records of data gathered through electronic monitoring and used in hiring, promotion, termination, disciplinary, or compensation decisions. Employers must destroy employee information collected via an electronic monitoring tool no later than 61 months after collection unless the employee has provided written and informed consent to retention. Employers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of employee data, appropriate to the volume and nature of the data. Employees have the right to request corrections to erroneous employee data.
RI
Introduced eff 2025-10-01
Developers of general-purpose AI models must create and maintain technical documentation covering training and testing processes, intended tasks, integration targets, acceptable use policies, release date, distribution methods, input/output modalities, and a detailed training data description including data type and provenance, curation methodologies, selection methods, unsuitable data source identification, and bias detection methods. Documentation must be reviewed and revised at least annually.
TX
Introduced eff 2025-09-01
Persons providing AI mental health services must maintain records of service provision in the same manner required by the applicable professional licensing statute.
US
Introduced
Covered entities must create and maintain contemporaneous documentation of their impact assessments, including baseline process evaluations, stakeholder consultation records, privacy and security testing, development and deployment milestones, improvement needs, and documentation of any assessment requirements that were infeasible to complete along with the rationale for noncompliance.
US
Introduced
Developers must make compliance information (including pre-deployment evaluation reports and annual reviews) available to deployers on request, and must cooperate with deployer audits or arrange independent auditor assessments. Developer-deployer contracts must specify data processing procedures, deployment instructions, data types, processing duration, and party obligations; must not relieve either party of liability; must prohibit data commingling; and must preserve enforcement reporting rights. Developers must retain contracts for 10 years.
US
Introduced
Employers must make, keep, preserve, and make available to the Secretary of Labor records pertaining to compliance with the Act, in accordance with FLSA § 11(c) and any regulations or orders issued by the Secretary, and must file annual or special reports upon the Secretary's request.
US
Introduced
Covered entities must maintain documentation of all impact assessments performed, including the information described in Section 4(a), for 3 years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Introduced
Covered entities must document all stakeholder consultations performed during impact assessments, including points of contact, dates, legal or financial agreements, materials reviewed by stakeholders, recommendations adopted, and recommendations rejected with rationale.
US
Introduced
Covered entities must maintain ongoing documentation of the development and deployment process (milestones, dates, responsible teams), identify needed improvements in capabilities, tools, standards, or resources across performance, fairness, transparency, privacy, safety, efficiency, and cost, document any impact assessment requirements that were infeasible to complete with corresponding rationale, and perform any additional studies the FTC determines appropriate.
US
Introduced
Sandbox participants must retain all records, documents, and data directly related to their participation in the Program and make them available for inspection upon request by the Director.
US
Introduced
Developers must, upon deployer request, provide information necessary for deployer compliance, including pre-deployment evaluation reports and annual review results. Developers must either cooperate with deployer-conducted assessments or arrange an independent auditor assessment of the developer's practices and share the report.
US
Introduced
Developers must include in written contracts with deployers: data processing procedures, deployment instructions, data types and processing duration, both parties' rights and obligations with a material-change notification method, a prohibition on cross-party data combination, and a prohibition on suppressing enforcement-agency complaints. Contracts may not relieve either party of statutory obligations. Developers must retain all contracts for 10 years.
VA
Introduced
Law-enforcement agencies must retain the first draft of any report or record created in whole or in part using generative AI for as long as the final report is retained. The program used to generate the report must maintain an audit trail that, at a minimum, identifies: (i) the person who used AI to create or edit the report, (ii) any changes made to the report following the initial draft, and (iii) the video and audio footage used to create the report, if any.
VA
Introduced
Developers must keep detailed records of all training datasets used to train a generative AI system or service. Compliance is deemed satisfied by adherence to the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized AI risk management framework.
VA
Introduced
Media outlets accepting electioneering communications for publication or broadcast must require and retain for one year proof of identity of the person submitting the communication, verified either via government-issued photo ID in person or via telephone verification of identifying information submitted remotely.
VA
Introduced
Media outlets accepting electioneering communications must require and retain for one year a copy of proof of identity of the person submitting the communication, verified either in person via government-issued ID or remotely via telephone verification.
WA
Introduced eff 2028-07-01
Employers must maintain records of all electronic monitoring notices provided to employees for at least three years and produce them to the Department of Labor and Industries upon request.
WV
Introduced
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur when the initial purpose for collecting or obtaining the data has been satisfied or within three years of the individual's last interaction with the private entity, whichever occurs first. The entity must comply with its established retention schedule and destruction guidelines absent a valid warrant or subpoena.
CA
Failed
Attorneys must execute and retain for seven years an affidavit certifying, for each document filed or intended to be filed in a California state or federal court, whether generative AI was used in drafting the document and, if so, that all AI-generated text, citations, and legal analysis has been reviewed for accuracy and approved by a human.
CA
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable safeguards to manage algorithmic discrimination risks, proportionate to the tool's use and the entity's role and resources. The program must (1) designate at least one employee responsible for compliance oversight with authority to raise compliance concerns, (2) identify and implement anti-discrimination safeguards, (3) conduct annual comprehensive compliance reviews, (4) retain impact assessment results for five years after completion, and (5) adjust safeguards in light of material changes in technology, risk, or operations.
CA
Failed
Generative AI system providers, generative AI system distributors, and large online platforms must, beginning January 1, 2026, and annually thereafter, produce a Risk Assessment and Mitigation Report assessing synthetic content risks and harms — including AI-generated CSAM, NCII, election and public health disinformation, and plagiarism. The report must be audited by qualified independent auditors using state-of-the-art techniques and applicable national and international AI auditing standards.
CA
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage algorithmic discrimination risks. The program must (1) designate at least one compliance employee with authority to raise compliance concerns and trigger prompt internal investigation, (2) identify and implement discrimination safeguards, (3) provide for required impact assessments, (4) conduct an annual comprehensive compliance review, (5) retain impact assessment results for two years, and (6) adjust safeguards in response to material changes in technology, risk, standards, or business operations.
CA
Failed
Covered deployers must document responsive actions taken in connection with any security breach incident, including a mandatory post-incident review of each event and any changes made to business practices for the protection of personal information in response.
CA
Failed
Employers must maintain an updated list of all automated decision systems currently in use.
CT
Failed
Developers of general-purpose AI models must create, maintain, and annually revise technical documentation covering training and testing processes, intended tasks, integration contexts, acceptable-use policies, release dates, distribution methods, input/output modalities, and detailed training data descriptions (type, provenance, curation methods, selection criteria, bias detection methods). Developers must also establish and maintain a copyright compliance policy.
FL
Failed eff 2026-07-01
Workers' compensation carriers must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed eff 2026-07-01
Insurers must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed eff 2026-07-01
Health maintenance organizations must maintain detailed records of every qualified-human-professional review of an AI-assisted adverse claim decision, including (1) the reviewer's name, title, business address, and unique identifier; (2) the date and time of the decision; and (3) documentation of the basis for the reduction or denial, including any information provided by the algorithm, AI system, or machine learning system.
FL
Failed
Insurers must maintain detailed records of all actions taken by qualified human professionals when adjusting, denying, or reviewing claim decisions, including: (1) the name and title of each qualified human professional who made or reviewed a claim decision; (2) the date and time of each claim decision and review; and (3) documentation of the basis for any denial, including any information provided by an algorithm, AI system, or machine learning system.
FL
Failed
Insurers that use an algorithm, AI system, or machine learning system as part of their claims-handling process must detail in their claims-handling manual (1) the manner in which such systems are to be used and (2) the manner in which the insurer complies with this section.
GA
Failed
Facial recognition specialists must (1) use the software only for official law enforcement business, (2) log in with assigned credentials, (3) record the case number and law enforcement reason for each search in the incident report, (4) use only lawfully collected probe images, (5) use only agency-approved software, and (6) ensure every search request and its results are documented in the incident report.
GA
Failed
Law enforcement agencies seeking to use another agency's facial recognition software must submit a written request from a supervisory-level official, obtain supervisory-level approval from the providing agency, and execute a signed interagency agreement or MOU containing eight enumerated acknowledgments covering legal compliance, use limitations, anti-surveillance commitments, corroboration requirements, confidentiality, and lawful probe-image sourcing.
GA
Failed
Law enforcement agencies must (1) conduct quarterly random-sample audits of authorized facial recognition users to verify proper documentation is being maintained, (2) conduct at least annual random-sample audits to verify procedural compliance and that the authorized-user list is current, and (3) document and retain all audit records for at least two calendar years.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern the risks of algorithmic discrimination. The program must include discrimination safeguards, impact assessment procedures, an annual compliance review, two-year retention of impact assessment results, and ongoing adjustment of safeguards in light of material changes.
IL
Failed
Deployers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to map, measure, manage, and govern reasonably foreseeable algorithmic discrimination risks associated with each automated decision tool. Safeguards must be proportionate to the tool's use, the deployer's role and size, the nature of the deployer's activities, and the technical feasibility and cost of available tools. The program must: (1) identify and implement safeguards for foreseeable discrimination risks; (2) support performance of impact assessments required by Section 10; (3) conduct an annual comprehensive compliance review; (4) retain impact assessment results for at least two years after completion; and (5) adapt safeguards in response to material changes in technology, risk, technical standards, or business operations. This obligation does not apply to deployers with fewer than 25 employees unless the tool impacted more than 999 people in the prior calendar year.
MA
Failed
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI.
MA
Failed
Law enforcement agencies must immediately document the factual basis for any emergency facial recognition search, ensure the search is narrowly tailored, and within 48 hours of obtaining results file a signed, sworn statement from a supervisory official with the superior court setting forth the grounds for the emergency search.
MA
Failed
The department of state police must document in writing every facial recognition search request made to the FBI under this section.
MA
Failed
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency, (2) ensure the search is narrowly tailored to the emergency, and (3) file a signed, sworn statement by a supervisory official with the superior court within 48 hours of receiving search results.
MA
Failed
The Department of State Police must document in writing every facial recognition search performed and every search request made to the FBI under this section.
MA
Failed
Law enforcement agencies conducting emergency facial recognition searches must (1) immediately document the factual basis for the emergency belief, (2) ensure the search is narrowly tailored, and (3) within 48 hours of obtaining results, file a signed, sworn statement with the superior court setting forth the grounds for the search.
MD
Failed
Each unit of State government must conduct an annual data inventory by December 1 each year, identifying data necessary for operations or required by law, in the form prescribed by the Chief Data Officer, including flagging data used in artificial intelligence.
MD
Failed
Law enforcement agencies must complete an annual compliance audit by October 1 each year, retain all audit materials for at least 3 years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorneys, U.S. Attorneys, or their designees.
MD
Failed
Law enforcement agencies must complete an annual compliance audit beginning October 1, 2023, retain all audit materials for at least three years, and disclose audit results upon request to the Attorney General, Public Defender, State's Attorney, U.S. Attorney, or their designees.
NC
Failed
Manufacturers and importers of licensed chatbots must establish and maintain records, and make reports to the Director, as the Director may by regulation reasonably require to assure the safety and effectiveness of the chatbot.
NC
Failed
Covered platforms must store all chatbot conversations that do not include sensitive personal information for at least 60 days.
NC
Failed
Licensees must implement industry-standard encryption for data in transit and at rest, maintain detailed access logs, and conduct regular security audits no less than once every six months.
NC
Failed
Manufacturers and importers of licensed chatbots must establish and maintain records and submit reports to the Director as required by regulation to assure the safety and effectiveness of such devices.
NC
Failed
Covered platforms must store all chatbot conversations that do not include sensitive personal information for at least 60 days.
NE
Failed eff 2027-01-01
Large frontier developers and large chatbot providers that redact published plan documents for trade secrets, cybersecurity, public safety, national security, or legal compliance must describe the character and justification of each redaction in the published version to the extent permitted by the concerns justifying the redaction, and must retain the unredacted information for five years.
NV
Failed eff 2026-01-01
Insurers must develop, implement, and maintain a written plan for responsible AI use that includes a plan for acquiring, using, or relying upon third-party AI systems, covering contractual cooperation with regulatory inquiries and audit rights to confirm third-party compliance.
NY
Failed
Large developers must, before deploying a frontier model, record (as and when reasonably possible) and retain for as long as the frontier model is deployed plus five years information on the specific tests and test results used in any assessment of the frontier model, in sufficient detail for third parties to replicate the testing procedure.
NY
Failed
Licensees must ensure their system automatically generates a log every time it operates, conforming to standards set by the secretary, and must preserve all logs for ten years from the date of generation.
NY
Failed
Operators must maintain all books, records, source code, and logs as the secretary requires, including at minimum all system-generated logs and a backup of every version of the system, stored safely as prescribed.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of automated employment decision tools, including data sources, technical specifications, individuals involved in development, historical use data, and a version history sufficient to attest to the tool's specifications at the time of any employment decision. Documentation must be stored in a legible and accessible format for auditors.
NY
Failed
Employers must establish, maintain, and preserve for three years contemporaneous, true, and accurate records of all data collected via electronic monitoring tools to ensure compliance with employee and commissioner data requests. Employers must destroy monitoring data no later than 37 months after collection unless the employee provides written, informed consent to continued retention.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of each AEDT — including training data sources, technical specifications, developer identities, historical use data, and a historical record of tool versions — sufficient to reconstruct the tool's state at the time of any disputed employment decision. Documentation must be stored per commissioner-specified requirements and be legible and accessible to auditors conducting impact assessments.
NY
Failed
When frontier developers redact published documents for trade secrets, cybersecurity, public safety, or national security, they must describe the character and justification of each redaction in the published version and must retain unredacted originals for five years.
NY
Failed
Deployers and developers must establish, document, implement, and maintain a governance program with reasonable administrative and technical safeguards to manage foreseeable discrimination risks, scaled to the entity's role, size, and resources. The program must at minimum (1) identify and implement discrimination safeguards, (2) conduct annual comprehensive compliance reviews, (3) retain impact assessment results for two years, and (4) adjust safeguards in response to material changes in technology or business operations.
NY
Failed
Employers and vendors must retain all documentation pertaining to the design, development, use, and data of an automated employment decision tool necessary to conduct a bias audit, including data sources, technical specifications, developer identities, historical use data, and a version history sufficient to reconstruct the tool as it existed at the time of any disputed employment decision. Documentation must be legible and accessible to auditors.
OK
Failed
Deployers must maintain (1) updated inventories of deployed AI systems, (2) documentation on system design, intended use, and training data, and (3) records of audits, risk assessments, and oversight activities.
RI
Failed
The governance program must (1) identify and implement algorithmic-discrimination safeguards, (2) integrate impact-assessment obligations, (3) conduct an annual comprehensive compliance review, (4) retain impact-assessment results for two years after completion, and (5) make reasonable adjustments to safeguards in response to material changes in technology, risk, technical standards, or business operations.
RI
Failed
Developers must provide deployers with the technical capability to access documentation reasonably necessary for the deployer's impact assessment, including the CAIDS's capabilities, known limitations, and intended-use guidelines. Trade secrets and confidential information are not required to be disclosed.
RI
Failed
Developers must provide deployers with the technical capability to access information reasonably necessary to perform impact assessments, including documentation of the CAIDS's capabilities, known limitations, and guidelines for intended use. Trade secrets and confidential information need not be disclosed.
TX
Failed
Persons providing AI mental health services must maintain service records in the same manner required by the professional licensing statute applicable to a licensed mental health professional providing the same service.
US
Failed
Online platforms must retain for five years (extendable to eight by the FTC) a de-identified record describing each algorithmic process's data inputs, weighting methodology, development methodology (including training data and bias testing), and — for non-small-business platforms using algorithms in housing, education, employment, insurance, credit, or public accommodations — a disparate-impact assessment. Records must be produced to the FTC on request.
US
Failed
Online platforms must retain for five years (extendable to eight by FTC determination) a de-identified record for each algorithmic process describing the personal information categories used, the weighting/ranking method, the development data and training data, testing methodology for accuracy, fairness, bias, and discrimination, and — for non-small-business platforms using algorithmic processes in housing, education, employment, insurance, credit, or public accommodations — an assessment of whether the process produces disparate outcomes across protected characteristics.
US
Failed
Covered entities must maintain documentation of all impact assessments, including all information described in the assessment requirements, for three years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Failed
Covered entities must document in the impact assessment: (1) the baseline decision process being replaced and its known harms, (2) the intended benefits and purpose of the new augmented critical decision process, (3) all stakeholder consultations including contacts, dates, agreements, and recommendations adopted or rejected, (4) the development and deployment timeline, (5) resource needs identified, and (6) any assessment requirements that were infeasible and the rationale.
US
Failed
Law enforcement agencies whose officers use facial recognition must log all uses of facial recognition to the extent necessary to comply with the Act's reporting and audit requirements.
US
Failed
Covered entities must maintain documentation of all impact assessments, including the information described in Sec. 4(a), for three years beyond the duration of deployment of each automated decision system or augmented critical decision process.
US
Failed
Covered entities must, as part of the impact assessment for a new augmented critical decision process, evaluate and document the previously existing decision-making process (including baseline description, known harms, intended benefits, and intended purpose), and document all stakeholder consultations including contacts, dates, and terms of engagement.
US
Failed
Covered entities must document the development and deployment lifecycle (milestones, responsible teams), identify needed improvements in performance, fairness, transparency, privacy, safety, and cost, and document any impact assessment requirements that were infeasible to complete with rationale.
US
Failed
Each agency head must oversee the creation of AI governance charters for all covered federal AI systems, ensure they are regularly updated, publish them on the agency's public webpage, submit them to the Federal Register within 30 days of establishment or termination, and submit them to GSA for inclusion in the Federal AI System Inventory.
US
Failed
Each agency head must establish and maintain an accurate AI governance charter for every federal AI system that is high-risk or that uses, is trained on, or produces individual records, documenting at minimum: system purpose and responsible officials, development and funding details, training data and testing information, ongoing oversight cadence, system usage including AI-assisted determinations, output data descriptions, and Privacy Act system-of-records information. Charters must be updated within 30 days of any significant system change.
US
Failed
Online platforms must retain for 5 years (extendable to 8 by FTC determination) a de-identified record of each algorithmic process describing: data categories used, ranking methodology, development method including training data and ongoing training, testing methodology for accuracy, fairness, bias, and discrimination, and — for non-small-business platforms using algorithms in housing, education, employment, insurance, credit, or public accommodations — an assessment of whether the process produces disparate outcomes across protected characteristics.
US
Failed
Each agency head must establish an AI strategy for trustworthy AI adoption that includes (1) defined roles and responsibilities, (2) values and ethics principles, (3) trust and safety standards, (4) risk identification and mitigation processes, (5) algorithmic discrimination safeguards, (6) current and anticipated AI use domains, (7) workforce development steps, (8) conditions for public-facing AI use, (9) internal coordination processes, (10) interagency governance, (11) data governance, (12) procurement safeguards for rights and safety, and (13) specific implementation actions and desired outcomes.
US
Failed
Online platforms must retain for five years (extendable to eight) a de-identified record describing each algorithmic process, including personal information categories used, weighting methods, development data, training data, and testing for accuracy, fairness, bias, and discrimination. Non-small-business platforms using algorithms related to housing, education, employment, insurance, credit, or public accommodations must include a disparate-impact assessment across protected characteristics. Records must be produced to the FTC upon request.
US
Failed
Covered entities must maintain documentation of each impact assessment, including all information described in Sec. 4(a), for 3 years beyond the duration of deployment of the automated decision system or augmented critical decision process.
US
Failed
Covered entities must, as part of the impact assessment, evaluate any previously existing decision-making process being replaced, document stakeholder consultations (including points of contact, dates, legal agreements, materials reviewed, and recommendations adopted or rejected with rationale), and document the baseline, known harms, intended benefits, and purpose of the new system.
US
Failed
Covered entities must maintain ongoing documentation of the development and deployment process (including milestone dates and responsible teams), identify needed capabilities and tools for improvement across performance, fairness, transparency, privacy, safety, efficiency, and cost, and document any impact assessment requirements that were infeasible to complete along with corresponding rationale.
US
Failed
Critical-impact AI organizations must perform a documented TEVV-based risk management assessment no later than 30 days before making a critical-impact AI system publicly available, and biennially thereafter. The assessment must cover (1) organizational AI risk management policies and processes, (2) the system's structure, context, and capabilities, (3) quantitative and qualitative risk measurement methods and metrics, and (4) risk resource allocation and monitoring. Assessment reports must be submitted to the Secretary of Commerce within 90 days of completion in a format the Secretary determines.
US
Failed
Covered entities must maintain documentation of all impact assessments, including the information described in Section 4(a), for three years beyond the duration of the system's deployment.
US
Failed
Covered entities must, as part of their impact assessment, create and maintain contemporaneous documentation covering: (1) evaluation of previously existing decision processes, (2) stakeholder consultation records, (3) development and deployment milestones, (4) identified resource and capability needs, and (5) any requirements that could not be met with corresponding rationale.
US
Failed
Developers must enter into written contracts with deployers that specify data processing procedures, deployment instructions, data types, processing duration, rights and obligations including material-change notification, and must prohibit cross-party data combination. Contracts may not relieve either party of Act liability or prohibit reporting to enforcement agencies. Developers must retain each deployer contract for 10 years.
UT
Failed eff 2026-05-06
When a frontier developer redacts published compliance documents, it must describe the character and justification of each redaction in the published version and retain the unredacted information for five years.
UT
Failed
Suppliers seeking the affirmative defense to unlicensed-practice liability must create, maintain, and implement a written policy that states the chatbot's intended purpose and limitations, and describes procedures for (1) involving licensed mental health therapists in development and review, (2) ensuring consistency with clinical best practices, (3) conducting pre-deployment and ongoing testing to ensure output poses no greater risk than therapy with a licensed therapist, (4) identifying foreseeable adverse outcomes, (5) providing a user harm-reporting mechanism, (6) implementing risk-assessment and response protocols, (7) responding in real time to acute risk of physical harm, (8) ensuring regular objective reviews of safety, accuracy, and efficacy, (9) providing safe-use instructions, (10) ensuring users understand they are interacting with AI, (11) ensuring users understand purpose, capabilities, and limitations, (12) prioritizing user safety over engagement metrics or profit, (13) implementing anti-discrimination measures, and (14) ensuring HIPAA-equivalent security and privacy compliance. Suppliers must also maintain documentation describing foundation models, training data, HIPAA compliance, data practices, and ongoing accuracy/safety efforts, and must comply with the filed policy at the time of any alleged violation.
UT
Failed
Learning Laboratory participants must retain records as required by Office rule or the participation agreement.
WA
Failed
Each algorithmic accountability report must include clear and understandable statements covering: system name, vendor, and version; general capabilities and weapons potential; data inputs, generation, collection, and processing methods; bias testing status; purpose and proposed use; compliance plans for Section 4 requirements; constitutional-rights impact; civil rights and disparate impact analysis with mitigation plan; statutory decision criteria; and a comprehensive use and data management policy covering deployment protocols, access rules, data security, personnel training, community engagement, and fiscal impact.
WA
Failed
Each algorithmic accountability report must include 15 categories of clear and understandable statements covering: system name, vendor, and version; general capabilities (including weapon use); purpose and proposed use; data inputs and outputs; bias and inaccuracy examination results; known errors; appeal processes; community engagement; algorithm availability; compliance plans; legal-rights impacts; protected-class differential treatment; statutorily mandated criteria; data management policies and protocols; and fiscal impact.