CA
Enacted eff 2026-01-01
All frontier developers must, before or concurrently with deploying a new frontier model or a substantially modified version, publish a transparency report on their internet website containing: (1) the developer's website; (2) a mechanism for natural persons to communicate with the developer; (3) the model's release date; (4) supported languages; (5) supported output modalities; (6) intended uses; and (7) generally applicable restrictions or conditions on use. Large frontier developers must additionally include in the transparency report summaries of: (A) catastrophic risk assessments conducted under the frontier AI framework; (B) the results of those assessments; (C) the extent of third-party evaluator involvement; and (D) other steps taken to fulfill the framework requirements. Publishing the required information as part of a system card or model card satisfies compliance.
CO
Enacted eff 2026-02-01
Developers must make available to deployers comprehensive documentation covering foreseeable uses, training data summaries, known limitations, algorithmic discrimination risks, pre-deployment bias evaluation methods, data governance measures, intended outputs, mitigation steps, and monitoring guidance — including model cards, dataset cards, or impact assessments sufficient for the deployer to complete its own impact assessment.
CO
Enacted eff 2026-02-01
Developers must make available to deployers or other developers comprehensive documentation including: (1) a general statement of reasonably foreseeable uses and known harmful uses; (2) high-level training data summaries; (3) known limitations including algorithmic discrimination risks; (4) system purpose and intended benefits; (5) all information necessary for the deployer to comply with deployer obligations; (6) how the system was evaluated for performance and discrimination mitigation pre-release; (7) data governance measures covering training datasets, data source suitability, possible biases, and mitigation; (8) intended outputs; (9) discrimination risk mitigation measures; (10) how the system should and should not be used and monitored by individuals making consequential decisions; and (11) any additional documentation reasonably necessary for the deployer to understand outputs and monitor discrimination risk. Trade secrets and legally protected information need not be disclosed.
CO
Enacted eff 2026-02-01
Developers must make available to deployers or other developers, to the extent feasible, documentation and information through artifacts such as model cards, dataset cards, or other impact assessments necessary for the deployer or a third party contracted by the deployer to complete an impact assessment. A developer that also serves as deployer is not required to generate this documentation unless the system is provided to an unaffiliated entity acting as deployer.
CT
Enacted eff 2026-07-01
Developers of automated employment-related decision technologies deployed in Connecticut on or after October 1, 2027, must provide deployers with all information needed for the deployer to perform its disclosure duties, unless the technology was not advertised or configured for employment-decision use. Developers may contractually assume the deployer's disclosure duties.
NY
Enacted eff 2027-01-01
Frontier developers must publish on their website a transparency report before or concurrently with deploying a new or substantially modified frontier model, containing: developer website, a contact mechanism, model release date, supported languages, supported output modalities, intended uses, and generally applicable use restrictions or conditions. Publication via a system card or model card satisfies this requirement.
VA
Enacted eff 2026-07-01
Developers must not provide a high-risk AI system to a deployer or other developer without making available (1) a statement of intended uses, (2) documentation disclosing known limitations, algorithmic discrimination risks, system purpose, performance evaluation methods, mitigation measures, and monitoring guidance, (3) additional documentation describing intended outputs, usage and non-usage guidelines, and how a human should monitor the system for consequential decisions, and (4) any further documentation reasonably necessary for the deployer to understand and monitor the system.
VA
Enacted eff 2026-07-01
Developers must provide deployers with information and documentation through artifacts such as system cards or predeployment impact assessments — including risk management policies and completed impact assessments — sufficient to enable the deployer or a third party to complete the impact assessment required by § 59.1-609.
VA
Enacted eff 2026-07-01
Developers must update all disclosures required by § 59.1-608 within 90 days of performing an intentional and substantial modification to any high-risk AI system to ensure accuracy.
VA
Enacted eff 2026-07-01
Deployers must update all disclosures required by § 59.1-609 within 30 days of being notified by the developer that an intentional and substantial modification has been performed, to ensure accuracy.
VA
Enacted eff 2026-07-01
Deployers who perform an intentional and substantial modification to a high-risk AI system must comply with the developer documentation and disclosure requirements under subsections B through G of § 59.1-608.
CA
Engrossed
Developers must provide deployers who receive a covered ADS with the most recent performance evaluation results, usage instructions for each developer-approved use, fine-tuning guidance, an explanation of the deployer's chapter responsibilities (including when the deployer assumes developer status), and all technical information necessary for deployer compliance. Documentation must be transmitted directly, provided in English and any other language regularly used, and clearly presented. Trade-secret redactions are permitted with notice.
CA
Engrossed
Developers who receive an impact assessment from an auditor of a deployed covered ADS must forward to all deployers of that system any material accuracy discrepancies, reliability discrepancies, unanticipated disparate impacts (with deployment conditions under which they are likely), and recommended mitigation steps.
VA
Engrossed eff 2026-07-01
Developers must provide deployers with documentation covering the high-risk AI system's intended uses, known limitations, algorithmic discrimination risks, performance evaluation summaries, data governance measures, bias mitigation steps, intended outputs, and human oversight instructions before making the system available.
VA
Engrossed eff 2026-07-01
Developers must make available to deployers all information and documentation in the developer's possession, custody, or control that is reasonably required for the deployer to complete an impact assessment under § 2.2-5519.
VA
Engrossed eff 2026-07-01
Integrators must provide deployers with clear, conspicuous notice identifying the integrated high-risk AI system, the developer's name and contact information, any model weight adjustments and their discrimination risk evaluation, a summary of non-substantial modifications, and the integrator's acceptable use policy.
HI
Introduced
Developers must provide each deployer of their algorithmic decision system with (1) a risk analysis of intended and foreseeable uses and misuses, (2) a description of mitigation steps taken, (3) a statement of intended and foreseeable uses and misuses, and (4) all other information necessary for the deployer to comply with its obligations under this chapter.
IA
Introduced
Developers must provide deployers with documentation and information necessary for the deployer to complete an impact assessment, including model cards, dataset cards, and other impact assessments. This requirement does not apply where the deployer is affiliated with the developer.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers must publish any material modification to their public safety and child protection plan, along with a justification for the modification, within 30 days after the modification is made.
IL
Introduced
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, covering the developer's website, contact mechanism, release date, supported languages, output modalities, intended uses, and use restrictions.
IL
Introduced
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, including the developer's website, contact mechanism, release date, supported languages, output modalities, intended uses, and use restrictions.
IL
Introduced eff 2027-01-01
Covered online platforms must prominently and conspicuously publish on their website, service, or application: (1) a list of each algorithmic recommender system in use, (2) a description of each input and its data source, and (3) the weights used in each system, categorized into quartile groups by relative importance.
IL
Introduced eff 2027-01-01
Covered online platforms must annually publish, in an easily accessible location, a long-term holdout assessment disclosure including: (1) the platform's long-term user value metrics, (2) aggregate anonymized measurements across the holdout group, and (3) aggregate anonymized measurements across the rest of the user base.
LA
Introduced
Chatbot providers must publish information about their chatbot on their website on a monthly basis, with the content and format to be specified by attorney general rulemaking.
LA
Introduced eff 2027-01-01
Frontier developers must publish on their website, before or concurrently with deploying a new or substantially modified frontier model, a transparency report containing the model's release date, languages, output modalities, intended uses, restrictions or conditions, and a mechanism to communicate with the developer.
MA
Introduced
Developers must provide deployers with comprehensive documentation for each high-risk AI system, including: (1) a statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) high-level training data summaries, known limitations, discrimination risks, system purpose, and intended benefits; (3) pre-deployment performance and bias evaluation methodology, data governance measures, intended outputs, discrimination mitigation measures, and guidance on use, non-use, and human monitoring; and (4) any additional documentation reasonably necessary to assist deployers in understanding outputs and monitoring performance. Developers must also provide model cards, dataset cards, or impact assessments sufficient for deployers to complete their own impact assessments. A developer that also serves as a deployer is exempt unless the system is provided to an unaffiliated deployer. Trade secrets and legally protected information need not be disclosed.
MA
Introduced
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, disclosing the developer's website, contact mechanism, release date, supported languages, output modalities, intended uses, and use restrictions.
MD
Introduced eff 2026-07-01
Manufacturers must publish a publicly accessible, plain-language AI safety summary report identifying the intended age range, risks from the safety assessment, testing results, and directions for parents to control data collection or adaptive behaviors.
MN
Introduced
Sellers or distributors of a program containing AI must, before the sale or distribution, disclose (1) the business names of the AI's manufacturers or creators, (2) contact information for technical experts who assist users, (3) the functions the AI performs, (4) the types of modeling the AI uses, and (5) all safety features of the AI, including human-in-the-loop integration.
MN
Introduced
Covered businesses must prominently and conspicuously publish on their platform (1) a list of each algorithmic recommender system used, (2) a description of each input and its data source for each system, and (3) the weights used in each system categorized into four quartile groups by relative importance.
MN
Introduced
Covered businesses must annually publish in an easily accessible location a long-term holdout assessment disclosure including (1) the platform's long-term user value metrics, (2) aggregate anonymized measurements for each metric across the holdout group(s), and (3) aggregate anonymized measurements for each metric across the rest of the user base.
MN
Introduced
Developers must conspicuously publish a copy of the safety and security protocol with appropriate redactions before deploying an AI model, and must transmit a copy of the redacted protocol to the attorney general. If the attorney general requests access, the developer must grant access to the protocol with redactions only to the extent required by federal law.
NY
Introduced
Designers, developers, and deployers of automated systems must provide accessible plain language documentation including: (1) clear descriptions of overall system functioning, (2) the role of automation, (3) notice of system use, (4) identification of the individual or organization responsible for the system, and (5) clear, timely, and accessible explanations of outcomes. This documentation must be kept up to date, and residents impacted by the system must be notified of any significant changes to use cases or key functionalities.
NY
Introduced
Developers must make available to each deployer or other developer: (1) a general statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) documentation disclosing training data type summaries, known limitations including algorithmic discrimination risks, system purpose, intended benefits and uses, and any information necessary for downstream compliance; (3) documentation describing pre-distribution performance and bias evaluation methods, data governance measures covering training datasets, intended outputs, discrimination mitigation measures, and instructions for use, non-use, and human monitoring when making consequential decisions; and (4) any additional documentation reasonably necessary for the deployer to understand outputs and monitor for discrimination risk. Trade secrets and security-sensitive information are exempt.
NY
Introduced
Developers must, to the extent feasible, make available to deployers and downstream developers the documentation and information necessary for the deployer (or the deployer's contracted third party) to complete an impact assessment under this article. Documentation must be delivered through artifacts such as model cards, dataset cards, or impact assessments. A developer that also serves as a deployer is exempt from generating this documentation unless the system is provided to an unaffiliated entity acting as a deployer.
NY
Introduced
Developers must provide deployers with an intended-use statement and documentation covering the AEDT's known limitations, foreseeable discrimination risks, training data types, and pre-sale validity and explainability evaluations.
RI
Introduced eff 2025-10-01
Developers must provide each deployer or downstream developer with documentation covering foreseeable uses, known harmful uses, training data summaries, system limitations, algorithmic discrimination risks, performance evaluation methods, data governance measures, bias mitigation steps, intended outputs, and human monitoring instructions.
RI
Introduced eff 2025-10-01
Developers must make available to deployers and downstream developers the documentation and information necessary for the deployer to complete an impact assessment, delivered through artifacts such as model cards, dataset cards, or other impact assessments.
RI
Introduced eff 2025-10-01
Developers of general-purpose AI models must create, maintain, and make available to downstream integrators documentation enabling them to understand model capabilities and limitations, comply with chapter obligations, and integrate the model, including technical integration requirements, model information, and training data descriptions, reviewed at least annually.
SC
Introduced
Developers must make available to deployers and other developers documentation covering: (1) a general statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) high-level summaries of training data types, known limitations and discrimination risks, system purpose, intended benefits and uses, and all information necessary for the deployer to comply with Section 37-31-30; (3) descriptions of pre-deployment performance evaluation and discrimination mitigation, data governance measures including data source suitability and bias examination, intended outputs, discrimination mitigation measures, and how the system should be used, not used, and monitored during consequential decision-making; and (4) any additional documentation reasonably necessary for the deployer to understand outputs and monitor performance for algorithmic discrimination risks. Trade secrets and legally protected information may be withheld.
SC
Introduced
Developers must make available to deployers and other developers, to the extent feasible, the documentation and information — through artifacts such as model cards, dataset cards, or other impact assessments — necessary for a deployer or its contracted third party to complete an impact assessment under Section 37-31-30(C). A developer that also serves as the deployer is exempt from this documentation requirement unless the system is provided to an unaffiliated entity acting as a deployer.
US
Introduced
The NIST Director must initiate a pilot program to establish a structured template and technical guidelines for AI model documentation, subject to appropriations.
US
Introduced
The NIST Director must produce a modular structured template for AI model documentation covering model name, developer identity, incorporation location, release date, training data knowledge cutoff, supported languages, terms of service, and other information; and must provide accompanying technical guidelines with relevant metrics, benchmarks, and voluntary consensus-based standards.
US
Introduced
Covered entities must publish foundation model transparency information on their own website in human-readable, consumer-friendly format and on a central FTC-hosted website in machine-readable format. A covered entity may satisfy the obligation by publishing the required information as part of a system card or model card.
US
Introduced
Covered entities must publish documentation describing each foundation model's intended purposes, foreseen limitations and risks, version history and release date, training data knowledge cutoff date, adverse incident monitoring and response procedures, and supported languages.
US
Introduced
Covered entities must disclose the computational power used to train and operate each foundation model.
US
Introduced
Covered entities whose foundation model is derived from or built upon another covered entity's foundation model must publicly provide a URL to the base model's transparency disclosure website, provided the base model is in compliance with the regulations.
US
Introduced
Covered entities that redact information from published or submitted transparency documents must briefly identify and justify each redaction in the publication or submission. Permissible redactions are limited to those necessary to protect cybersecurity, entity or model security, public safety, or U.S. national security, or to comply with federal law.
US
Introduced eff 2025-12-01
Developers must, prior to deployment and on a continuous basis, publicly release and maintain (1) a model card describing training data sources, evaluation methodology, performance metrics, intended uses, limitations, and risk mitigations, and (2) the model specification (system prompt, constitutional AI documents, and RLHF rubrics), with only narrow trade-secret redactions accompanied by written justification. Developers must also provide clear and conspicuous documentation to learned professionals describing known limitations, failure modes, and appropriate domains of use. Immunity from civil liability for errors used by learned professionals is conditioned on meeting these transparency requirements and does not cover recklessness or willful misconduct.
US
Introduced eff 2025-12-01
Developers must update the model card, model specification, and learned-professional documentation within 30 days of deploying a new version of the AI product or discovering a new and material failure mode. Failure to update within this window forfeits civil liability immunity for harms proximately caused by the outdated documentation.
US
Introduced
Developers and deployers must publish a detailed public disclosure covering entity identity and contact information, links to evaluation/assessment summaries, personal data categories collected, third-party data transfers, individual rights descriptions, compliance practices, a mandatory audit disclaimer, and the disclosure effective date. Disclosures must be in each covered language and accessible to individuals with disabilities.
US
Introduced
Developers and deployers must notify affected individuals of material disclosure changes before implementation via direct electronic notification, retain all previous disclosure versions for at least 10 years on their website, and maintain a public log of material changes. Deployers must provide a short-form notice (max 500 words) at an individual's first interaction with the covered algorithm or on their website if no relationship exists.
VA
Introduced eff 2027-07-01
Developers of base AI models must clearly and conspicuously disclose in the model's terms of service: (1) the model name, (2) the developer, (3) the developer's incorporation location, (4) the release date of the most recent version, (5) the date training data was most recently updated, (6) supported languages, and (7) a link to the terms of service.
VT
Introduced eff 2025-07-01
Developers of inherently dangerous AI systems must document and disclose to any actual or potential deployer: (1) all reasonably foreseeable risks, including from unintended or unauthorized uses, that could cause any of the harms enumerated in the standard-of-care provision; and (2) all reasonably foreseeable risk mitigation processes to address those harms.
VT
Introduced eff 2026-07-01
Chatbot providers must make information about their chatbot publicly available on their website on a monthly basis, covering categories of information as prescribed by Attorney General rules.
WA
Introduced eff 2027-01-01
Developers must not make a high-risk AI system available to a deployer or other developer unless the developer provides: (1) a statement disclosing the intended uses; (2) documentation disclosing the known limitations and algorithmic discrimination risks, the system's purpose and intended outputs, a summary of how the system was evaluated for performance and discrimination mitigation before distribution, a description of measures taken to mitigate discrimination risks, and a description of how the system should be used, not be used, and be monitored by an individual when used for consequential decisions; and (3) any additional documentation reasonably necessary to assist the deployer in understanding outputs and monitoring performance for discrimination risks.
WA
Introduced eff 2027-01-01
Developers must make available to deployers or other developers, to the extent feasible and necessary, information and documentation enabling the deployer, other developer, or a third party contracted by the deployer to complete a deployer impact assessment. This documentation must include artifacts such as system cards or predeployment impact assessments, including relevant risk management policies and impact assessments.
WA
Introduced eff 2027-01-01
Developers must update all disclosures required under Section 2 no later than 90 days after performing an intentional and substantial modification to a high-risk AI system, to ensure each disclosure remains accurate.
WA
Introduced eff 2027-01-01
Deployers must update all disclosures required under Section 3 no later than 30 days after being notified by the developer of an intentional and substantial modification to a high-risk AI system, to ensure each disclosure remains accurate.
WA
Introduced eff 2027-01-01
Deployers who perform an intentional and substantial modification to a high-risk AI system must comply with all developer-level documentation and disclosure requirements under Section 2, including providing intended-use statements, limitation disclosures, discrimination-risk documentation, evaluation summaries, mitigation descriptions, and usage guidance.
WA
Introduced eff 2027-01-01
Developers must not offer, sell, lease, give, or otherwise provide a high-risk AI system to a deployer or other developer unless the developer makes available: (1) a statement disclosing the intended uses; (2) documentation disclosing known limitations, discrimination risks, the system's purpose and intended outputs, a summary of performance and discrimination evaluation conducted before availability, a description of discrimination-mitigation measures, and guidance on how the system should be used, not be used, and be monitored by a human when making or substantially factoring into consequential decisions; and (3) any additional documentation reasonably necessary for the deployer to understand outputs and monitor performance for algorithmic discrimination risks. Conformity with the NIST AI RMF, ISO/IEC 42001, or an equivalent framework creates a rebuttable presumption of compliance.
WA
Introduced eff 2027-01-01
Developers must make available to deployers (or third parties contracted by deployers), to the extent feasible and necessary, information and documentation to enable them to complete an impact assessment as required by Section 3(3). This documentation must include artifacts such as system cards or predeployment impact assessments, including relevant risk management policies and impact assessments.
WA
Introduced eff 2027-01-01
Deployers who perform an intentional and substantial modification to a high-risk AI system must comply with the documentation and disclosure requirements applicable to developers under Section 2, including providing intended-use statements, limitation disclosures, evaluation summaries, mitigation descriptions, and usage guidance.
CA
Failed
Developers must provide each deployer with documentation covering the automated decision tool's intended uses, known limitations (including foreseeable algorithmic discrimination risks), the type of training data used, the tool's pre-sale validity and explainability evaluation, and the deployer's responsibilities under the chapter. Trade secrets need not be disclosed.
CA
Failed
Developers must provide each deployer with a statement of the automated decision tool's intended uses and documentation of its known limitations (including foreseeable algorithmic discrimination risks), the types of training data used, and the tool's pre-sale validity and explainability evaluations. Trade secrets need not be disclosed.
CO
Failed
Developers must make documentation available to deployers or other developers describing the high-risk AI system's capabilities, limitations, and intended uses.
CO
Failed
Developers must provide deployers with impact-assessment-enabling documentation — including model cards, dataset cards, or other impact assessments — to the extent feasible.
CO
Failed eff 2025-05-05
Developers must make available to each deployer or other developer a general statement describing intended uses and known harmful uses of the high-risk AI system, along with documentation describing data governance measures, intended inputs, and outputs.
CO
Failed eff 2025-05-05
Developers must make available to deployers, to the extent feasible, the documentation and information (such as model cards, dataset cards, or impact assessments) necessary for deployers to complete an impact assessment under § 6-1-1703(3).
CO
Failed
Developers must make available to deployers, to the extent feasible, model cards, dataset cards, or other impact assessment documentation necessary for the deployer to complete its own impact assessment, effective June 30, 2026.
CT
Failed
Developers must make available to each deployer documentation covering foreseeable uses, training data summaries, discrimination risks, performance evaluation methods, data governance measures, intended outputs, mitigation measures, and monitoring guidance for each high-risk AI system, including materials necessary for the deployer to complete an impact assessment.
IL
Failed
Businesses with 10 or more employees that use AI systems in Illinois must publish on their official website a public report explaining compliance with the five AI governance principles. The report must: (1) be updated annually and whenever significant changes are made to the AI system, including modifications to algorithms, substantial alterations to data inputs, or shifts in operational contexts; (2) include information on the system's design, major design-process decisions (such as testing metrics), training data, risk mitigation strategies, and any impact assessments conducted; and (3) be written in plain language accessible to the general public while also providing a more detailed explanation for specialized audiences.
MD
Failed
Developers offering a high-risk AI system for sale must (1) provide purchasers with standardized disclosure documentation covering system purpose, intended uses, known risks of algorithmic discrimination, limitations, training data summary, data governance measures, bias mitigation steps, best practices, and monitoring information, and (2) provide deployers with information necessary to complete an impact assessment.
NE
Failed
Developers must make available to deployers or other developers of each high-risk AI system: (1) a general statement describing uses and known harmful or inappropriate uses; (2) documentation disclosing a high-level summary of training data types, each known limitation including reasonably foreseeable algorithmic discrimination risks, the system's purpose, intended benefits and uses, and information necessary for deployer compliance; (3) documentation describing pre-deployment performance and discrimination evaluation methodology, data governance measures covering training datasets including suitability of data sources and bias mitigation, intended outputs, measures taken to mitigate known discrimination risks, and guidance on how the system should be used, not be used, and be monitored by a human in consequential-decision contexts; and (4) documentation reasonably necessary to assist the deployer in understanding each output and monitoring performance for algorithmic discrimination risk. Trade secrets and legally protected or security-sensitive information may be withheld.
NE
Failed
Developers that make a high-risk AI system available to deployers or other developers must, to the extent feasible, provide the documentation and information necessary for the deployer or a third party contracted by the deployer to complete an impact assessment, including any model card or other impact assessment. A developer that also serves as deployer for the same system need not generate this documentation unless the system is provided to an unaffiliated deployer.
NM
Failed
Developers must provide recipients (deployers) with a general summary of foreseeable and harmful uses and detailed documentation covering purpose, training data summary, known limitations and discrimination risks, bias evaluation methodology, data governance measures, intended outputs, mitigation steps, monitoring guidance, and all information necessary for deployer compliance.
NY
Failed
Persons developing automated systems must, whenever possible, perform independent evaluations confirming system safety and effectiveness — including steps taken to mitigate potential harms — and make the results publicly available.
NY
Failed
Designers, developers, and deployers must provide accessible, plain-language documentation describing overall system functioning, the role of automation, the responsible individual or organization, and clear explanations of outcomes. Documentation must be kept current and residents must be notified of significant changes to use cases or key functionalities.
NY
Failed
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, covering the developer's website, a user-communication mechanism, the model's release date, supported languages, output modalities, intended uses, and any generally applicable use restrictions. Publication within a system card or model card satisfies this requirement.
NY
Failed
Developers must provide deployers with a statement of intended use and documentation covering (1) known limitations including foreseeable discrimination risks, (2) the type of data used to program or train the tool, and (3) how the tool was evaluated for validity and explainability before sale or licensing. Trade secrets and confidential business information need not be disclosed.
NY
Failed
Persons developing automated systems must perform independent evaluation and reporting confirming system safety and effectiveness — including steps taken to mitigate potential harms — and must make results public whenever possible.
NY
Failed
Whenever possible, persons developing automated systems must provide residents with access to reporting that confirms respect for their data decisions and assesses the potential impact of surveillance technologies on their rights, opportunities, or access.
NY
Failed
Designers, developers, and deployers must provide accessible plain-language documentation covering overall system functioning, the role of automation, notice of system use, identification of the responsible individual or organization, and clear explanations of outcomes. Notice must be kept current and residents must be notified of significant changes to use cases or key functionalities.
NY
Failed
Persons developing automated systems must make public, whenever possible, summary reporting that includes plain-language information about the automated systems and assessments of the clarity and quality of notice and explanations provided.
NY
Failed
Persons developing automated systems must make publicly available, whenever possible, summary reporting on human governance processes including descriptions of fallback mechanisms and assessments of their timeliness, accessibility, outcomes, and effectiveness.
OK
Failed
Developers must provide deployers with a statement of intended uses and documentation covering the tool's known limitations and algorithmic discrimination risks, the types of data used to program or train the tool, and how the tool was evaluated for validity and explainability before sale or licensing.
RI
Failed
Developers must provide deployers with a statement of the automated decision tool's intended uses and documentation covering known limitations (including foreseeable algorithmic discrimination risks), training data types, and pre-sale validity and explainability evaluations. Trade secrets need not be disclosed.
TX
Failed
Developers must provide deployers with a written High-Risk Report before delivering a high-risk AI system, covering intended uses, known discrimination risks, NIST AI RMF-aligned performance metrics, training data summary, data governance measures, and recommended risk management principles.
TX
Failed
Developers must update and provide the High-Risk Report information to deployers within 30 days of any intentional and substantial modification to the system.
TX
Failed
Developers must provide deployers with all documentation and information necessary for the deployer to complete an impact assessment.
TX
Failed
The Health and Human Services Commission must publish on its website the testing results for each AI technology application submitted for approval.
TX
Failed
Covered persons must publicly disclose on their website or another electronically accessible location: (1) the name of each AI model used, (2) a brief description of each model's functions and purposes, (3) the name of each third party that has provided input on an implemented AI model, (4) a description of each third party's specific input, and (5) any model changes resulting from such third-party input. Individual end users providing personal-capacity feedback based on their own user experience are not considered third parties for these purposes.
US
Failed
Online platforms must disclose to users, in conspicuous, accessible, and plain language (in each language in which the platform provides services), for each type of algorithmic process: (1) the categories of personal information collected or created, (2) how that information is collected, (3) how it is used in the algorithmic process, and (4) the method by which the process prioritizes, ranks, or weighs different categories of personal information.
US
Failed
Online platforms must disclose to users, in conspicuous, accessible, and plain language (in every language the platform serves), the categories of personal information each algorithmic process collects, how it is collected, how it is used, and how the algorithm prioritizes or ranks categories of personal information to withhold, amplify, recommend, or promote content.
US
Failed
Covered entities must publish specified foundation model transparency information on their website and on the FTC's central registry, in machine-readable format, as defined by FTC regulations.
US
Failed
Covered entities must disclose the intended purposes, foreseen limitations or risks, version history, release date, and computational power used to train and operate each foundation model, as specified in FTC regulations.
US
Failed
Covered entities must disclose benchmark performance results — whether from self-evaluation or audit — including what precautions the model takes when responding to high-risk domains such as healthcare, biological or chemical synthesis, cybersecurity, elections, policing, financial lending, education, employment, public services, and vulnerable populations including children.
US
Failed
Online platforms must disclose to users, in conspicuous, accessible, and plain language available in all supported languages, the categories of personal information collected for each algorithmic process, the collection method, how the information is used, and the method by which the algorithm prioritizes or ranks data to recommend or withhold content.
US
Failed
Online platforms must disclose to users in conspicuous, accessible, and plain language a complete description of content moderation practices, including automated and human-labor-based practices, available in all supported languages.
US
Failed
Developers and deployers must publish a comprehensive public disclosure covering their identity and contact information, links to evaluation and assessment summaries, categories of personal data collected or processed and processing purposes, third-party data transfers, a description of individual rights, general compliance practices, a mandated statutory disclaimer, and the effective date. Disclosures must be in plain language, available in all covered languages, and accessible to individuals with disabilities. Material changes require prior notification to affected individuals and a 10-year public version log.
VA
Failed eff 2027-07-01
Developers of base artificial intelligence models must clearly and conspicuously disclose the following information in the model's terms of service, in a manner appropriate for the medium and easily accessible to users: (1) the name of the model, (2) the developer of the model, (3) the location where the developer is incorporated, (4) the release date of the most recent version, (5) the date the model's training data was most recently updated, (6) supported languages, and (7) a link to the model's terms of service. Compliance with this disclosure obligation does not serve as a defense to liability for harm caused to a plaintiff.
VA
Failed
Developers must not provide a high-risk AI system to a deployer unless the developer makes available (1) a statement of intended uses and (2) documentation disclosing known limitations, algorithmic discrimination risks, performance evaluation summaries, mitigation measures, and instructions for human oversight of the system's consequential decisions. Trade secrets and proprietary information are exempt from disclosure.
VT
Failed
Developers must provide deployers, before offering a high-risk AI system, with documentation covering intended uses, known limitations, foreseeable discrimination risks, data types collected and used for training, data governance measures, bias mitigation steps, system outputs, and how individuals can use or monitor the system for consequential decisions.
WA
Failed
Developers must provide deployers with a statement of intended uses and documentation covering (1) the tool's known limitations and foreseeable algorithmic discrimination risks, (2) the types of data used to program or train the tool, and (3) how the tool was evaluated for validity and explainability before sale or licensing.