G-02
Governance & Documentation
Public Transparency & Documentation
Developers must publish standardized documentation describing an AI system's capabilities, limitations, intended uses, safety measures, and/or risk assessments, and keep it current as of deployment.
Sub-obligations3
Bills122
Jurisdictions32
Enacted13
Show
Sort bills within section

3 sub-obligations of G-02

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
G-02.1 Model card or system card publication
A structured document covering model capabilities, training data characteristics, evaluation results, intended uses, known limitations, and out-of-scope uses must be published and kept current. Must be accessible to downstream deployers and researchers.
11Enacted 52Live 41Failed 104Total Jump →
G-02.2 Catastrophic risk assessment summary publication
Large frontier-model developers must publicly publish a summary of each catastrophic-risk assessment — the risk categories evaluated, the methodology, the safeguards adopted, and any residual-risk findings — with permitted redactions for trade secrets, security, or public safety described in the published version.
2Enacted 13Live 5Failed 20Total Jump →
G-02.3 Public AI Use Case Inventory
Developers and deployers of high-risk AI systems must publish and maintain on their public website or in a public use case inventory a clear summary describing the high-risk AI systems they offer or deploy, including intended uses, known discrimination risks, and risk management approaches.
13Enacted 44Live 55Failed 112Total Jump →
Bills That Map This Requirement 251 mappings
G-02.1
Model card or system card publication
A structured document covering model capabilities, training data characteristics, evaluation results, intended uses, known limitations, and out-of-scope uses must be published and kept current. Must be accessible to downstream deployers and researchers.
Enacted
11
Live
52
Failed
41
Total
104
CA
CA SB 53 (Frontier AI Transparency) § Bus. & Prof. Code § 22757.12
Enacted eff 2026-01-01
All frontier developers must, before or concurrently with deploying a new frontier model or a substantially modified version, publish a transparency report on their internet website containing: (1) the developer's website; (2) a mechanism for natural persons to communicate with the developer; (3) the model's release date; (4) supported languages; (5) supported output modalities; (6) intended uses; and (7) generally applicable restrictions or conditions on use. Large frontier developers must additionally include in the transparency report summaries of: (A) catastrophic risk assessments conducted under the frontier AI framework; (B) the results of those assessments; (C) the extent of third-party evaluator involvement; and (D) other steps taken to fulfill the framework requirements. Publishing the required information as part of a system card or model card satisfies compliance.
CO
Enacted eff 2026-02-01
Developers must make available to deployers comprehensive documentation covering foreseeable uses, training data summaries, known limitations, algorithmic discrimination risks, pre-deployment bias evaluation methods, data governance measures, intended outputs, mitigation steps, and monitoring guidance — including model cards, dataset cards, or impact assessments sufficient for the deployer to complete its own impact assessment.
CO
Enacted eff 2026-02-01
Developers must make available to deployers or other developers comprehensive documentation including: (1) a general statement of reasonably foreseeable uses and known harmful uses; (2) high-level training data summaries; (3) known limitations including algorithmic discrimination risks; (4) system purpose and intended benefits; (5) all information necessary for the deployer to comply with deployer obligations; (6) how the system was evaluated for performance and discrimination mitigation pre-release; (7) data governance measures covering training datasets, data source suitability, possible biases, and mitigation; (8) intended outputs; (9) discrimination risk mitigation measures; (10) how the system should and should not be used and monitored by individuals making consequential decisions; and (11) any additional documentation reasonably necessary for the deployer to understand outputs and monitor discrimination risk. Trade secrets and legally protected information need not be disclosed.
CO
Enacted eff 2026-02-01
Developers must make available to deployers or other developers, to the extent feasible, documentation and information through artifacts such as model cards, dataset cards, or other impact assessments necessary for the deployer or a third party contracted by the deployer to complete an impact assessment. A developer that also serves as deployer is not required to generate this documentation unless the system is provided to an unaffiliated entity acting as deployer.
CT
Enacted eff 2026-07-01
Developers of automated employment-related decision technologies deployed in Connecticut on or after October 1, 2027, must provide deployers with all information needed for the deployer to perform its disclosure duties, unless the technology was not advertised or configured for employment-decision use. Developers may contractually assume the deployer's disclosure duties.
NY
Enacted eff 2027-01-01
Frontier developers must publish on their website a transparency report before or concurrently with deploying a new or substantially modified frontier model, containing: developer website, a contact mechanism, model release date, supported languages, supported output modalities, intended uses, and generally applicable use restrictions or conditions. Publication via a system card or model card satisfies this requirement.
VA
Enacted eff 2026-07-01
Developers must not provide a high-risk AI system to a deployer or other developer without making available (1) a statement of intended uses, (2) documentation disclosing known limitations, algorithmic discrimination risks, system purpose, performance evaluation methods, mitigation measures, and monitoring guidance, (3) additional documentation describing intended outputs, usage and non-usage guidelines, and how a human should monitor the system for consequential decisions, and (4) any further documentation reasonably necessary for the deployer to understand and monitor the system.
VA
Enacted eff 2026-07-01
Developers must provide deployers with information and documentation through artifacts such as system cards or predeployment impact assessments — including risk management policies and completed impact assessments — sufficient to enable the deployer or a third party to complete the impact assessment required by § 59.1-609.
VA
Enacted eff 2026-07-01
Developers must update all disclosures required by § 59.1-608 within 90 days of performing an intentional and substantial modification to any high-risk AI system to ensure accuracy.
VA
Enacted eff 2026-07-01
Deployers must update all disclosures required by § 59.1-609 within 30 days of being notified by the developer that an intentional and substantial modification has been performed, to ensure accuracy.
VA
Enacted eff 2026-07-01
Deployers who perform an intentional and substantial modification to a high-risk AI system must comply with the developer documentation and disclosure requirements under subsections B through G of § 59.1-608.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must provide deployers who receive a covered ADS with the most recent performance evaluation results, usage instructions for each developer-approved use, fine-tuning guidance, an explanation of the deployer's chapter responsibilities (including when the deployer assumes developer status), and all technical information necessary for deployer compliance. Documentation must be transmitted directly, provided in English and any other language regularly used, and clearly presented. Trade-secret redactions are permitted with notice.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers who receive an impact assessment from an auditor of a deployed covered ADS must forward to all deployers of that system any material accuracy discrepancies, reliability discrepancies, unanticipated disparate impacts (with deployment conditions under which they are likely), and recommended mitigation steps.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5518
Engrossed eff 2026-07-01
Developers must provide deployers with documentation covering the high-risk AI system's intended uses, known limitations, algorithmic discrimination risks, performance evaluation summaries, data governance measures, bias mitigation steps, intended outputs, and human oversight instructions before making the system available.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5518
Engrossed eff 2026-07-01
Developers must make available to deployers all information and documentation in the developer's possession, custody, or control that is reasonably required for the deployer to complete an impact assessment under § 2.2-5519.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5520
Engrossed eff 2026-07-01
Integrators must provide deployers with clear, conspicuous notice identifying the integrated high-risk AI system, the developer's name and contact information, any model weight adjustments and their discrimination risk evaluation, a summary of non-substantial modifications, and the integrator's acceptable use policy.
HI
Introduced
Developers must provide each deployer of their algorithmic decision system with (1) a risk analysis of intended and foreseeable uses and misuses, (2) a description of mitigation steps taken, (3) a statement of intended and foreseeable uses and misuses, and (4) all other information necessary for the deployer to comply with its obligations under this chapter.
IA
Introduced
Developers must provide deployers with documentation and information necessary for the deployer to complete an impact assessment, including model cards, dataset cards, and other impact assessments. This requirement does not apply where the deployer is affiliated with the developer.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers must publish any material modification to their public safety and child protection plan, along with a justification for the modification, within 30 days after the modification is made.
IL
Introduced
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, covering the developer's website, contact mechanism, release date, supported languages, output modalities, intended uses, and use restrictions.
IL
Introduced
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, including the developer's website, contact mechanism, release date, supported languages, output modalities, intended uses, and use restrictions.
IL
Introduced eff 2027-01-01
Covered online platforms must prominently and conspicuously publish on their website, service, or application: (1) a list of each algorithmic recommender system in use, (2) a description of each input and its data source, and (3) the weights used in each system, categorized into quartile groups by relative importance.
IL
Introduced eff 2027-01-01
Covered online platforms must annually publish, in an easily accessible location, a long-term holdout assessment disclosure including: (1) the platform's long-term user value metrics, (2) aggregate anonymized measurements across the holdout group, and (3) aggregate anonymized measurements across the rest of the user base.
LA
Introduced
Chatbot providers must publish information about their chatbot on their website on a monthly basis, with the content and format to be specified by attorney general rulemaking.
LA
Introduced eff 2027-01-01
Frontier developers must publish on their website, before or concurrently with deploying a new or substantially modified frontier model, a transparency report containing the model's release date, languages, output modalities, intended uses, restrictions or conditions, and a mechanism to communicate with the developer.
MA
Introduced
Developers must provide deployers with comprehensive documentation for each high-risk AI system, including: (1) a statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) high-level training data summaries, known limitations, discrimination risks, system purpose, and intended benefits; (3) pre-deployment performance and bias evaluation methodology, data governance measures, intended outputs, discrimination mitigation measures, and guidance on use, non-use, and human monitoring; and (4) any additional documentation reasonably necessary to assist deployers in understanding outputs and monitoring performance. Developers must also provide model cards, dataset cards, or impact assessments sufficient for deployers to complete their own impact assessments. A developer that also serves as a deployer is exempt unless the system is provided to an unaffiliated deployer. Trade secrets and legally protected information need not be disclosed.
MA
Introduced
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, disclosing the developer's website, contact mechanism, release date, supported languages, output modalities, intended uses, and use restrictions.
MD
MD HB 1261 (AI Toy Safety) § Md. Code, Com. Law § 14-5105
Introduced eff 2026-07-01
Manufacturers must publish a publicly accessible, plain-language AI safety summary report identifying the intended age range, risks from the safety assessment, testing results, and directions for parents to control data collection or adaptive behaviors.
MN
MN HF 5051 (AI Program Disclosures) § Minn. Stat. § 325G.64, subd. 2
Introduced
Sellers or distributors of a program containing AI must, before the sale or distribution, disclose (1) the business names of the AI's manufacturers or creators, (2) contact information for technical experts who assist users, (3) the functions the AI performs, (4) the types of modeling the AI uses, and (5) all safety features of the AI, including human-in-the-loop integration.
MN
MN SF 4380 (Online Platform Metrics) § Minn. Stat. § 325M.35, subd. 3
Introduced
Covered businesses must prominently and conspicuously publish on their platform (1) a list of each algorithmic recommender system used, (2) a description of each input and its data source for each system, and (3) the weights used in each system categorized into four quartile groups by relative importance.
MN
MN SF 4380 (Online Platform Metrics) § Minn. Stat. § 325M.35, subd. 6
Introduced
Covered businesses must annually publish in an easily accessible location a long-term holdout assessment disclosure including (1) the platform's long-term user value metrics, (2) aggregate anonymized measurements for each metric across the holdout group(s), and (3) aggregate anonymized measurements for each metric across the rest of the user base.
MN
Introduced
Developers must conspicuously publish a copy of the safety and security protocol with appropriate redactions before deploying an AI model, and must transmit a copy of the redacted protocol to the attorney general. If the attorney general requests access, the developer must grant access to the protocol with redactions only to the extent required by federal law.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 507
Introduced
Designers, developers, and deployers of automated systems must provide accessible plain language documentation including: (1) clear descriptions of overall system functioning, (2) the role of automation, (3) notice of system use, (4) identification of the individual or organization responsible for the system, and (5) clear, timely, and accessible explanations of outcomes. This documentation must be kept up to date, and residents impacted by the system must be notified of any significant changes to use cases or key functionalities.
NY
Introduced
Developers must make available to each deployer or other developer: (1) a general statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) documentation disclosing training data type summaries, known limitations including algorithmic discrimination risks, system purpose, intended benefits and uses, and any information necessary for downstream compliance; (3) documentation describing pre-distribution performance and bias evaluation methods, data governance measures covering training datasets, intended outputs, discrimination mitigation measures, and instructions for use, non-use, and human monitoring when making consequential decisions; and (4) any additional documentation reasonably necessary for the deployer to understand outputs and monitor for discrimination risk. Trade secrets and security-sensitive information are exempt.
NY
Introduced
Developers must, to the extent feasible, make available to deployers and downstream developers the documentation and information necessary for the deployer (or the deployer's contracted third party) to complete an impact assessment under this article. Documentation must be delivered through artifacts such as model cards, dataset cards, or impact assessments. A developer that also serves as a deployer is exempt from generating this documentation unless the system is provided to an unaffiliated entity acting as a deployer.
NY
Introduced
Developers must provide deployers with an intended-use statement and documentation covering the AEDT's known limitations, foreseeable discrimination risks, training data types, and pre-sale validity and explainability evaluations.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-3
Introduced eff 2025-10-01
Developers must provide each deployer or downstream developer with documentation covering foreseeable uses, known harmful uses, training data summaries, system limitations, algorithmic discrimination risks, performance evaluation methods, data governance measures, bias mitigation steps, intended outputs, and human monitoring instructions.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-3
Introduced eff 2025-10-01
Developers must make available to deployers and downstream developers the documentation and information necessary for the deployer to complete an impact assessment, delivered through artifacts such as model cards, dataset cards, or other impact assessments.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-6
Introduced eff 2025-10-01
Developers of general-purpose AI models must create, maintain, and make available to downstream integrators documentation enabling them to understand model capabilities and limitations, comply with chapter obligations, and integrate the model, including technical integration requirements, model information, and training data descriptions, reviewed at least annually.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-20
Introduced
Developers must make available to deployers and other developers documentation covering: (1) a general statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) high-level summaries of training data types, known limitations and discrimination risks, system purpose, intended benefits and uses, and all information necessary for the deployer to comply with Section 37-31-30; (3) descriptions of pre-deployment performance evaluation and discrimination mitigation, data governance measures including data source suitability and bias examination, intended outputs, discrimination mitigation measures, and how the system should be used, not used, and monitored during consequential decision-making; and (4) any additional documentation reasonably necessary for the deployer to understand outputs and monitor performance for algorithmic discrimination risks. Trade secrets and legally protected information may be withheld.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-20
Introduced
Developers must make available to deployers and other developers, to the extent feasible, the documentation and information — through artifacts such as model cards, dataset cards, or other impact assessments — necessary for a deployer or its contracted third party to complete an impact assessment under Section 37-31-30(C). A developer that also serves as the deployer is exempt from this documentation requirement unless the system is provided to an unaffiliated entity acting as a deployer.
US
Introduced
The NIST Director must initiate a pilot program to establish a structured template and technical guidelines for AI model documentation, subject to appropriations.
US
Introduced
The NIST Director must produce a modular structured template for AI model documentation covering model name, developer identity, incorporation location, release date, training data knowledge cutoff, supported languages, terms of service, and other information; and must provide accompanying technical guidelines with relevant metrics, benchmarks, and voluntary consensus-based standards.
US
Introduced
Covered entities must publish foundation model transparency information on their own website in human-readable, consumer-friendly format and on a central FTC-hosted website in machine-readable format. A covered entity may satisfy the obligation by publishing the required information as part of a system card or model card.
US
Introduced
Covered entities must publish documentation describing each foundation model's intended purposes, foreseen limitations and risks, version history and release date, training data knowledge cutoff date, adverse incident monitoring and response procedures, and supported languages.
US
Introduced
Covered entities must disclose the computational power used to train and operate each foundation model.
US
Introduced
Covered entities whose foundation model is derived from or built upon another covered entity's foundation model must publicly provide a URL to the base model's transparency disclosure website, provided the base model is in compliance with the regulations.
US
Introduced
Covered entities that redact information from published or submitted transparency documents must briefly identify and justify each redaction in the publication or submission. Permissible redactions are limited to those necessary to protect cybersecurity, entity or model security, public safety, or U.S. national security, or to comply with federal law.
US
Introduced eff 2025-12-01
Developers must, prior to deployment and on a continuous basis, publicly release and maintain (1) a model card describing training data sources, evaluation methodology, performance metrics, intended uses, limitations, and risk mitigations, and (2) the model specification (system prompt, constitutional AI documents, and RLHF rubrics), with only narrow trade-secret redactions accompanied by written justification. Developers must also provide clear and conspicuous documentation to learned professionals describing known limitations, failure modes, and appropriate domains of use. Immunity from civil liability for errors used by learned professionals is conditioned on meeting these transparency requirements and does not cover recklessness or willful misconduct.
US
Introduced eff 2025-12-01
Developers must update the model card, model specification, and learned-professional documentation within 30 days of deploying a new version of the AI product or discovering a new and material failure mode. Failure to update within this window forfeits civil liability immunity for harms proximately caused by the outdated documentation.
US
Introduced
Developers and deployers must publish a detailed public disclosure covering entity identity and contact information, links to evaluation/assessment summaries, personal data categories collected, third-party data transfers, individual rights descriptions, compliance practices, a mandatory audit disclaimer, and the disclosure effective date. Disclosures must be in each covered language and accessible to individuals with disabilities.
US
Introduced
Developers and deployers must notify affected individuals of material disclosure changes before implementation via direct electronic notification, retain all previous disclosure versions for at least 10 years on their website, and maintain a public log of material changes. Deployers must provide a short-form notice (max 500 words) at an individual's first interaction with the covered algorithm or on their website if no relationship exists.
VA
VA SB 365 (FAIR AI Act) § Va. Code § 59.1-615
Introduced eff 2027-07-01
Developers of base AI models must clearly and conspicuously disclose in the model's terms of service: (1) the model name, (2) the developer, (3) the developer's incorporation location, (4) the release date of the most recent version, (5) the date training data was most recently updated, (6) supported languages, and (7) a link to the terms of service.
VT
VT HB 341 (AI Safety Standards) § 9 V.S.A. § 4193f
Introduced eff 2025-07-01
Developers of inherently dangerous AI systems must document and disclose to any actual or potential deployer: (1) all reasonably foreseeable risks, including from unintended or unauthorized uses, that could cause any of the harms enumerated in the standard-of-care provision; and (2) all reasonably foreseeable risk mitigation processes to address those harms.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193c
Introduced eff 2026-07-01
Chatbot providers must make information about their chatbot publicly available on their website on a monthly basis, covering categories of information as prescribed by Attorney General rules.
WA
Introduced eff 2027-01-01
Developers must not make a high-risk AI system available to a deployer or other developer unless the developer provides: (1) a statement disclosing the intended uses; (2) documentation disclosing the known limitations and algorithmic discrimination risks, the system's purpose and intended outputs, a summary of how the system was evaluated for performance and discrimination mitigation before distribution, a description of measures taken to mitigate discrimination risks, and a description of how the system should be used, not be used, and be monitored by an individual when used for consequential decisions; and (3) any additional documentation reasonably necessary to assist the deployer in understanding outputs and monitoring performance for discrimination risks.
WA
Introduced eff 2027-01-01
Developers must make available to deployers or other developers, to the extent feasible and necessary, information and documentation enabling the deployer, other developer, or a third party contracted by the deployer to complete a deployer impact assessment. This documentation must include artifacts such as system cards or predeployment impact assessments, including relevant risk management policies and impact assessments.
WA
Introduced eff 2027-01-01
Developers must update all disclosures required under Section 2 no later than 90 days after performing an intentional and substantial modification to a high-risk AI system, to ensure each disclosure remains accurate.
WA
Introduced eff 2027-01-01
Deployers must update all disclosures required under Section 3 no later than 30 days after being notified by the developer of an intentional and substantial modification to a high-risk AI system, to ensure each disclosure remains accurate.
WA
Introduced eff 2027-01-01
Deployers who perform an intentional and substantial modification to a high-risk AI system must comply with all developer-level documentation and disclosure requirements under Section 2, including providing intended-use statements, limitation disclosures, discrimination-risk documentation, evaluation summaries, mitigation descriptions, and usage guidance.
WA
Introduced eff 2027-01-01
Developers must not offer, sell, lease, give, or otherwise provide a high-risk AI system to a deployer or other developer unless the developer makes available: (1) a statement disclosing the intended uses; (2) documentation disclosing known limitations, discrimination risks, the system's purpose and intended outputs, a summary of performance and discrimination evaluation conducted before availability, a description of discrimination-mitigation measures, and guidance on how the system should be used, not be used, and be monitored by a human when making or substantially factoring into consequential decisions; and (3) any additional documentation reasonably necessary for the deployer to understand outputs and monitor performance for algorithmic discrimination risks. Conformity with the NIST AI RMF, ISO/IEC 42001, or an equivalent framework creates a rebuttable presumption of compliance.
WA
Introduced eff 2027-01-01
Developers must make available to deployers (or third parties contracted by deployers), to the extent feasible and necessary, information and documentation to enable them to complete an impact assessment as required by Section 3(3). This documentation must include artifacts such as system cards or predeployment impact assessments, including relevant risk management policies and impact assessments.
WA
Introduced eff 2027-01-01
Deployers who perform an intentional and substantial modification to a high-risk AI system must comply with the documentation and disclosure requirements applicable to developers under Section 2, including providing intended-use statements, limitation disclosures, evaluation summaries, mitigation descriptions, and usage guidance.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.3
Failed
Developers must provide each deployer with documentation covering the automated decision tool's intended uses, known limitations (including foreseeable algorithmic discrimination risks), the type of training data used, the tool's pre-sale validity and explainability evaluation, and the deployer's responsibilities under the chapter. Trade secrets need not be disclosed.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.3
Failed
Developers must provide each deployer with a statement of the automated decision tool's intended uses and documentation of its known limitations (including foreseeable algorithmic discrimination risks), the types of training data used, and the tool's pre-sale validity and explainability evaluations. Trade secrets need not be disclosed.
CO
Failed
Developers must make documentation available to deployers or other developers describing the high-risk AI system's capabilities, limitations, and intended uses.
CO
Failed
Developers must provide deployers with impact-assessment-enabling documentation — including model cards, dataset cards, or other impact assessments — to the extent feasible.
CO
Failed eff 2025-05-05
Developers must make available to each deployer or other developer a general statement describing intended uses and known harmful uses of the high-risk AI system, along with documentation describing data governance measures, intended inputs, and outputs.
CO
Failed eff 2025-05-05
Developers must make available to deployers, to the extent feasible, the documentation and information (such as model cards, dataset cards, or impact assessments) necessary for deployers to complete an impact assessment under § 6-1-1703(3).
CO
Failed
Developers must make available to deployers, to the extent feasible, model cards, dataset cards, or other impact assessment documentation necessary for the deployer to complete its own impact assessment, effective June 30, 2026.
CT
Failed
Developers must make available to each deployer documentation covering foreseeable uses, training data summaries, discrimination risks, performance evaluation methods, data governance measures, intended outputs, mitigation measures, and monitoring guidance for each high-risk AI system, including materials necessary for the deployer to complete an impact assessment.
IL
Failed
Businesses with 10 or more employees that use AI systems in Illinois must publish on their official website a public report explaining compliance with the five AI governance principles. The report must: (1) be updated annually and whenever significant changes are made to the AI system, including modifications to algorithms, substantial alterations to data inputs, or shifts in operational contexts; (2) include information on the system's design, major design-process decisions (such as testing metrics), training data, risk mitigation strategies, and any impact assessments conducted; and (3) be written in plain language accessible to the general public while also providing a more detailed explanation for specialized audiences.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5002
Failed
Developers offering a high-risk AI system for sale must (1) provide purchasers with standardized disclosure documentation covering system purpose, intended uses, known risks of algorithmic discrimination, limitations, training data summary, data governance measures, bias mitigation steps, best practices, and monitoring information, and (2) provide deployers with information necessary to complete an impact assessment.
NE
Failed
Developers must make available to deployers or other developers of each high-risk AI system: (1) a general statement describing uses and known harmful or inappropriate uses; (2) documentation disclosing a high-level summary of training data types, each known limitation including reasonably foreseeable algorithmic discrimination risks, the system's purpose, intended benefits and uses, and information necessary for deployer compliance; (3) documentation describing pre-deployment performance and discrimination evaluation methodology, data governance measures covering training datasets including suitability of data sources and bias mitigation, intended outputs, measures taken to mitigate known discrimination risks, and guidance on how the system should be used, not be used, and be monitored by a human in consequential-decision contexts; and (4) documentation reasonably necessary to assist the deployer in understanding each output and monitoring performance for algorithmic discrimination risk. Trade secrets and legally protected or security-sensitive information may be withheld.
NE
Failed
Developers that make a high-risk AI system available to deployers or other developers must, to the extent feasible, provide the documentation and information necessary for the deployer or a third party contracted by the deployer to complete an impact assessment, including any model card or other impact assessment. A developer that also serves as deployer for the same system need not generate this documentation unless the system is provided to an unaffiliated deployer.
NM
Failed
Developers must provide recipients (deployers) with a general summary of foreseeable and harmful uses and detailed documentation covering purpose, training data summary, known limitations and discrimination risks, bias evaluation methodology, data governance measures, intended outputs, mitigation steps, monitoring guidance, and all information necessary for deployer compliance.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 404
Failed
Persons developing automated systems must, whenever possible, perform independent evaluations confirming system safety and effectiveness — including steps taken to mitigate potential harms — and make the results publicly available.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 407
Failed
Designers, developers, and deployers must provide accessible, plain-language documentation describing overall system functioning, the role of automation, the responsible individual or organization, and clear explanations of outcomes. Documentation must be kept current and residents must be notified of significant changes to use cases or key functionalities.
NY
Failed
Frontier developers must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier model, covering the developer's website, a user-communication mechanism, the model's release date, supported languages, output modalities, intended uses, and any generally applicable use restrictions. Publication within a system card or model card satisfies this requirement.
NY
Failed
Developers must provide deployers with a statement of intended use and documentation covering (1) known limitations including foreseeable discrimination risks, (2) the type of data used to program or train the tool, and (3) how the tool was evaluated for validity and explainability before sale or licensing. Trade secrets and confidential business information need not be disclosed.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 404
Failed
Persons developing automated systems must perform independent evaluation and reporting confirming system safety and effectiveness — including steps taken to mitigate potential harms — and must make results public whenever possible.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Whenever possible, persons developing automated systems must provide residents with access to reporting that confirms respect for their data decisions and assesses the potential impact of surveillance technologies on their rights, opportunities, or access.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 407
Failed
Designers, developers, and deployers must provide accessible plain-language documentation covering overall system functioning, the role of automation, notice of system use, identification of the responsible individual or organization, and clear explanations of outcomes. Notice must be kept current and residents must be notified of significant changes to use cases or key functionalities.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 407
Failed
Persons developing automated systems must make public, whenever possible, summary reporting that includes plain-language information about the automated systems and assessments of the clarity and quality of notice and explanations provided.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing automated systems must make publicly available, whenever possible, summary reporting on human governance processes including descriptions of fallback mechanisms and assessments of their timeliness, accessibility, outcomes, and effectiveness.
OK
OK HB 3835 (Ethical AI Act) § 75A O.S. § 1003
Failed
Developers must provide deployers with a statement of intended uses and documentation covering the tool's known limitations and algorithmic discrimination risks, the types of data used to program or train the tool, and how the tool was evaluated for validity and explainability before sale or licensing.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-4
Failed
Developers must provide deployers with a statement of the automated decision tool's intended uses and documentation covering known limitations (including foreseeable algorithmic discrimination risks), training data types, and pre-sale validity and explainability evaluations. Trade secrets need not be disclosed.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.003
Failed
Developers must provide deployers with a written High-Risk Report before delivering a high-risk AI system, covering intended uses, known discrimination risks, NIST AI RMF-aligned performance metrics, training data summary, data governance measures, and recommended risk management principles.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.003
Failed
Developers must update and provide the High-Risk Report information to deployers within 30 days of any intentional and substantial modification to the system.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.006
Failed
Developers must provide deployers with all documentation and information necessary for the deployer to complete an impact assessment.
TX
TX HB 4695 (AI Mental Health Services) § Health & Safety Code § 616.003
Failed
The Health and Human Services Commission must publish on its website the testing results for each AI technology application submitted for approval.
TX
TX SB 668 (AI Disclosure) § Bus. & Com. Code § 2003.003
Failed
Covered persons must publicly disclose on their website or another electronically accessible location: (1) the name of each AI model used, (2) a brief description of each model's functions and purposes, (3) the name of each third party that has provided input on an implemented AI model, (4) a description of each third party's specific input, and (5) any model changes resulting from such third-party input. Individual end users providing personal-capacity feedback based on their own user experience are not considered third parties for these purposes.
US
Failed
Online platforms must disclose to users, in conspicuous, accessible, and plain language (in each language in which the platform provides services), for each type of algorithmic process: (1) the categories of personal information collected or created, (2) how that information is collected, (3) how it is used in the algorithmic process, and (4) the method by which the process prioritizes, ranks, or weighs different categories of personal information.
US
Failed
Online platforms must disclose to users, in conspicuous, accessible, and plain language (in every language the platform serves), the categories of personal information each algorithmic process collects, how it is collected, how it is used, and how the algorithm prioritizes or ranks categories of personal information to withhold, amplify, recommend, or promote content.
US
Failed
Covered entities must publish specified foundation model transparency information on their website and on the FTC's central registry, in machine-readable format, as defined by FTC regulations.
US
Failed
Covered entities must disclose the intended purposes, foreseen limitations or risks, version history, release date, and computational power used to train and operate each foundation model, as specified in FTC regulations.
US
Failed
Covered entities must disclose benchmark performance results — whether from self-evaluation or audit — including what precautions the model takes when responding to high-risk domains such as healthcare, biological or chemical synthesis, cybersecurity, elections, policing, financial lending, education, employment, public services, and vulnerable populations including children.
US
Failed
Online platforms must disclose to users, in conspicuous, accessible, and plain language available in all supported languages, the categories of personal information collected for each algorithmic process, the collection method, how the information is used, and the method by which the algorithm prioritizes or ranks data to recommend or withhold content.
US
Failed
Online platforms must disclose to users in conspicuous, accessible, and plain language a complete description of content moderation practices, including automated and human-labor-based practices, available in all supported languages.
US
Failed
Developers and deployers must publish a comprehensive public disclosure covering their identity and contact information, links to evaluation and assessment summaries, categories of personal data collected or processed and processing purposes, third-party data transfers, a description of individual rights, general compliance practices, a mandated statutory disclaimer, and the effective date. Disclosures must be in plain language, available in all covered languages, and accessible to individuals with disabilities. Material changes require prior notification to affected individuals and a 10-year public version log.
VA
VA HB 713 (FAIR AI Act) § Va. Code § 59.1-615
Failed eff 2027-07-01
Developers of base artificial intelligence models must clearly and conspicuously disclose the following information in the model's terms of service, in a manner appropriate for the medium and easily accessible to users: (1) the name of the model, (2) the developer of the model, (3) the location where the developer is incorporated, (4) the release date of the most recent version, (5) the date the model's training data was most recently updated, (6) supported languages, and (7) a link to the model's terms of service. Compliance with this disclosure obligation does not serve as a defense to liability for harm caused to a plaintiff.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-604
Failed
Developers must not provide a high-risk AI system to a deployer unless the developer makes available (1) a statement of intended uses and (2) documentation disclosing known limitations, algorithmic discrimination risks, performance evaluation summaries, mitigation measures, and instructions for human oversight of the system's consequential decisions. Trade secrets and proprietary information are exempt from disclosure.
VT
Failed
Developers must provide deployers, before offering a high-risk AI system, with documentation covering intended uses, known limitations, foreseeable discrimination risks, data types collected and used for training, data governance measures, bias mitigation steps, system outputs, and how individuals can use or monitor the system for consequential decisions.
WA
Failed
Developers must provide deployers with a statement of intended uses and documentation covering (1) the tool's known limitations and foreseeable algorithmic discrimination risks, (2) the types of data used to program or train the tool, and (3) how the tool was evaluated for validity and explainability before sale or licensing.
G-02.2
Catastrophic risk assessment summary publication
Large frontier-model developers must publicly publish a summary of each catastrophic-risk assessment — the risk categories evaluated, the methodology, the safeguards adopted, and any residual-risk findings — with permitted redactions for trade secrets, security, or public safety described in the published version.
Enacted
2
Live
13
Failed
5
Total
20
CA
CA SB 53 (Frontier AI Transparency) § Bus. & Prof. Code § 22757.12
Enacted eff 2026-01-01
All frontier developers must, before or concurrently with deploying a new frontier model or a substantially modified version, publish a transparency report on their internet website containing: (1) the developer's website; (2) a mechanism for natural persons to communicate with the developer; (3) the model's release date; (4) supported languages; (5) supported output modalities; (6) intended uses; and (7) generally applicable restrictions or conditions on use. Large frontier developers must additionally include in the transparency report summaries of: (A) catastrophic risk assessments conducted under the frontier AI framework; (B) the results of those assessments; (C) the extent of third-party evaluator involvement; and (D) other steps taken to fulfill the framework requirements. Publishing the required information as part of a system card or model card satisfies compliance.
NY
Enacted eff 2027-01-01
Large frontier developers must include in their transparency report summaries of: catastrophic risk assessments conducted under the frontier AI framework, the assessment results, the extent of third-party evaluator involvement, and other steps taken to fulfill the frontier AI framework requirements for the frontier model.
IL
Introduced
Developers must produce and conspicuously publish a risk assessment report at least every 90 days, covering risk assessment conclusions, per-type critical risk capability assessments for the developer's most capable foundation models, and deployment rationale and safeguards for any newly deployed models posing elevated critical risk.
IL
Introduced eff 2027-01-01
Large chatbot providers must, before or concurrently with integrating a new or substantially modified foundation model into a covered chatbot, publish on their website summaries of all child safety risk assessments, their results, the extent of third-party evaluator involvement, and other steps taken to address child safety risks.
IL
Introduced eff 2027-01-01
Large frontier developers must, before or concurrently with deploying a new or substantially modified frontier model, (1) implement appropriate safeguards to prevent unreasonable catastrophic risk and (2) publish on their website summaries of all catastrophic risk assessments, their results, the extent of third-party evaluator involvement, and other steps taken to address catastrophic risks. Publication within a system card or model card satisfies this requirement.
IL
Introduced
Large frontier developers must include in their pre-deployment transparency report summaries of catastrophic risk assessments, assessment results, the extent of third-party evaluator involvement, and other steps taken to fulfill the frontier AI framework requirements.
IL
Introduced eff 2027-01-01
Large chatbot providers must, before or concurrently with integrating a new or substantially modified foundation model into a covered chatbot, conspicuously publish on their website summaries of all child safety risk assessments, their results, the extent of third-party evaluator involvement, and other steps taken to address child safety risks under their plan.
IL
Introduced eff 2027-01-01
Large frontier developers must, before or concurrently with deploying a new or substantially modified frontier model, implement appropriate safeguards to prevent unreasonable catastrophic risk and conspicuously publish on their website summaries of all catastrophic risk assessments, their results, the extent of third-party evaluator involvement, and other steps taken to address catastrophic risks. Publishing within a system card or model card satisfies this requirement.
IL
Introduced
Large frontier developers must include in the transparency report summaries of catastrophic risk assessments, assessment results, third-party evaluator involvement, and other steps taken to fulfill their frontier AI framework requirements.
IL
Introduced
Developers must create and publish a transparency report that identifies the frontier model and summarizes the results of safety assessments conducted under the developer's safety and security protocol, including steps taken to address identified risks. Appropriate redactions for model security, trade secrets, and proprietary information are permitted.
LA
Introduced eff 2027-01-01
Large frontier developers must include in the transparency report summaries of catastrophic risk assessments (including cybersecurity and biochemical risk), the results of those assessments, the extent of third-party evaluator involvement, and other steps taken to fulfill the frontier AI framework requirements for that model.
MA
Introduced
Large frontier developers must include in the transparency report summaries of catastrophic risk assessments conducted under their frontier AI framework, the results of those assessments, the extent of third-party evaluator involvement, and other steps taken to fulfill framework requirements.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must retain the unredacted investigation report for at least five years, conspicuously publish a redacted copy, and transmit a redacted copy to the attorney general. Redactions are limited to public safety, trade secrets, or confidential information. Unredacted reports must be provided to the AG upon request.
MI
Introduced eff 2026-01-01
Large developers must produce and conspicuously publish a transparency report at least once every 90 days. Each report must cover the period from 120 days before publication to 30 days before publication and must include: (1) conclusions of any risk assessments made during the reporting period in accordance with the safety and security protocol; (2) if different from the preceding report, for each type of critical risk, a capability assessment of the foundation model posing the highest level of that critical risk if deployed without safeguards; and (3) if a foundation model posing a higher level of critical risk than any existing deployed model was deployed or modified during the period, the grounds and process for the deployment decision and any safeguards and protections implemented.
NY
Introduced
The third-party verifier must conspicuously publish a summary of its compliance assessment report within 60 days of report completion, excluding information that would jeopardize trade secrets, cybersecurity, public safety, or national security.
NE
Failed eff 2027-01-01
Large chatbot providers must, before or concurrently with integrating a new foundation model or a substantially modified version of an existing foundation model into a covered chatbot, conspicuously publish on their website summaries of: (1) child safety risk assessments conducted pursuant to their plan; (2) the results of those assessments; (3) the extent of third-party evaluator involvement; and (4) other steps taken to fulfill child safety risk requirements under the plan.
NE
Failed eff 2027-01-01
Large frontier developers must, before or concurrently with deploying a new frontier model or a substantially modified version of an existing frontier model, conspicuously publish on their website summaries of: (1) catastrophic risk assessments conducted pursuant to their plan; (2) the results of those assessments; (3) the extent of third-party evaluator involvement; and (4) other steps taken to fulfill catastrophic risk requirements under the plan. Publication as part of a system card or model card satisfies this obligation.
NY
Failed
Large developers must, before deploying a frontier model, conspicuously publish a copy of the safety and security protocol with appropriate redactions and transmit a copy of the redacted protocol to the Division of Homeland Security and Emergency Services. The large developer must also grant the Division of Homeland Security and Emergency Services or the Attorney General access to the protocol with redactions only to the extent required by federal law, upon request.
NY
Failed
Large frontier developers must include in the transparency report summaries of catastrophic risk assessments, assessment results, the extent of third-party evaluator involvement, and other steps taken to fulfill the frontier AI framework with respect to the frontier model.
UT
UT HB 286 (AI Transparency Act) § Utah Code § 13-72b-104
Failed eff 2026-05-06
Large frontier developers must publish on their website, before deploying a new or substantially modified frontier model, summaries of catastrophic risk assessments, assessment results, the extent of third-party evaluator involvement, and other steps taken to fulfill the public safety plan.
G-02.3
Public AI Use Case Inventory
Developers and deployers of high-risk AI systems must publish and maintain on their public website or in a public use case inventory a clear summary describing the high-risk AI systems they offer or deploy, including intended uses, known discrimination risks, and risk management approaches.
Enacted
13
Live
44
Failed
55
Total
112
CO
Enacted eff 2026-02-01
Developers must publish and maintain on their website or in a public use case inventory a clear statement summarizing the types of high-risk AI systems they offer and how they manage known or reasonably foreseeable risks of algorithmic discrimination, updating the statement within 90 days of any intentional and substantial modification.
CO
Enacted eff 2026-02-01
Deployers must publish and periodically update on their website a clear statement summarizing the types of high-risk AI systems currently deployed, how the deployer manages algorithmic discrimination risks for each, and the nature, source, and extent of information collected and used.
CO
Enacted eff 2026-02-01
Developers must publish and maintain on their website or in a public use case inventory a clear and readily available statement summarizing: (1) the types of high-risk AI systems the developer has developed or intentionally and substantially modified and currently makes available; and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination from those systems. The statement must be updated as necessary for accuracy and within 90 days of any intentional and substantial modification.
CO
Enacted eff 2026-02-01
Deployers must publish and maintain on their website a clear and readily available statement summarizing: (1) the types of high-risk AI systems currently deployed; (2) how the deployer manages known or reasonably foreseeable risks of algorithmic discrimination from each system; and (3) in detail, the nature, source, and extent of information collected and used by the deployer. The statement must be periodically updated. Small deployers meeting the exemption conditions in subsection (6) are exempt.
CT
Enacted eff 2023-07-01
The Office of Policy and Management must post its AI policies and procedures — and any revisions — on its website.
IN
Enacted eff 2025-07-01
The Indiana Department of Education must publish AI educational materials for students and parents on its website.
IN
Enacted eff 2025-07-01
Each school corporation and charter school must post its AI policy on the school's website and clearly communicate the policy to students.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-508
Enacted eff 2024-10-01
Law enforcement agencies using FRT must adopt and maintain a use and data management policy and post it on the agency's public website.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–804
Enacted eff 2024-07-01
The Department must publish the adopted AI governance policies and procedures on its website within 45 days of adoption.
TN
TN HB 1630 (AI in Education Policy) § Tenn. Code Ann. § 49-7-1xx (new section, Section 1 of the Act)
Enacted eff 2024-03-11
Each higher education governing board must post its adopted AI policy on the institution's website and submit it to the chairs of the Senate education committee and House education administration committee no later than July 1, 2025. Governing boards that fail to comply must appear before the joint government operations committee within 60 days to report on their noncompliance.
TN
TN SB 1711 (AI in Education Policy) § Tenn. Code Ann. § 49-7-1xx (new section, Title 49, Chapter 7, Part 1)
Enacted eff 2024-03-11
Each higher education governing board must post its adopted AI policy on the institution's website and submit the policy to the chairs of the Senate education committee and the House education administration committee no later than July 1, 2025. Boards that fail to adopt and submit a policy must appear before the joint government operations committee within sixty days.
UT
UT HB 276 (AI Content Provenance & NCII) § Utah Code § 13-72b-205
Enacted eff 2027-01-01
Generation services must publish on their website or primary user interface their written anti-NCII policy and a general description of the safeguards implemented to prevent generation of non-consensual counterfeit intimate images.
VA
Enacted eff 2026-07-01
Deployers must make publicly available, in a clear and readily accessible manner, a statement summarizing how they manage reasonably foreseeable risks of algorithmic discrimination arising from deployment or use of each high-risk AI system.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed eff 2026-01-01
Deployers must publish on their internet website a statement summarizing: (1) the types of high-risk automated decision systems currently deployed; (2) how the deployer manages known or reasonably foreseeable risks of algorithmic discrimination; and (3) the nature and source of information collected and used by those systems.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must make publicly available, in a clear and readily accessible manner, a statement summarizing how the deployer manages reasonably foreseeable algorithmic discrimination risks arising from use or deployment of the high-risk AI system.
AZ
Introduced
AI businesses must publicly post their transparency reports on the business's website.
GA
GA HB 1603 (AI Performer Protection) § O.C.G.A. § 10-1-972
Introduced eff 2027-01-01
Production companies deploying AI systems for use in production in Georgia must, by December 31, 2027 and annually thereafter, conduct an inventory of all AI systems in use and publish the inventory on a publicly accessible website. The inventory must include for each AI system: (A) the name and vendor; (B) a description of general capabilities and uses; (C) a description of the manner in which the system can independently make, inform, or materially support conclusions, decisions, or judgments; and (D) a description of how the system underwent an impact assessment prior to implementation.
GA
Introduced
Developers must publish and maintain on their public website or in a public use case inventory a statement summarizing (1) the types of automated decision systems the developer has developed or intentionally and substantially modified and currently makes available and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination. The statement must be updated as necessary for accuracy and no later than 90 days after any intentional and substantial modification to any system described in the statement.
GA
Introduced
Deployers must publish and maintain on their public website a statement summarizing (1) the types of automated decision systems currently deployed, (2) how the deployer manages known or reasonably foreseeable risks of algorithmic discrimination from each system, and (3) in detail, the nature, source, and extent of the information collected and used by the deployer. The statement must be periodically updated. Subject to small-deployer exemption in § 10-16-6.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-975
Introduced eff 2027-01-01
Covered entities must publish on their website or mobile application: (1) privacy policy, terms of service, and community standards; (2) for each algorithmic feed and recommendation system, the system's purpose, the minor personal data used as inputs, data sources, use purposes, and (for derived-data inputs) a quartile-bucket disclosure of relative input weight; and (3) for every other feature using minor personal data, purpose, data collected and used, third-party transfers and recipients, and retention periods.
IA
Introduced
Developers must publish and maintain on their website or in a public use-case inventory a summary of: (1) the types of high-risk AI systems they currently make available to deployers, and (2) how they manage known or reasonably foreseeable risks of algorithmic discrimination. The statement must be updated within 90 days after developing or intentionally and substantially modifying a high-risk AI system.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(h)
Introduced
The Executive Office of Public Safety and Security must publish annually by March 31 on its website disaggregated data on all law enforcement facial recognition searches for the prior calendar year, including total searches by the state police and FBI broken down by requesting agency, warrant-based versus emergency searches by alleged offense, and the race and gender of search subjects.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(j)
Introduced
The Executive Office of Public Safety and Security must publish annually by March 31 on its website disaggregated data on all non-law-enforcement public agency facial recognition searches for the prior calendar year, including search volume by agency and the race and gender of search subjects.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(h)
Introduced
The Executive Office of Public Safety and Security must publish on its website by March 31 each year aggregated data on law enforcement facial recognition searches for the prior calendar year, disaggregated by agency, including warrant-based vs. emergency search counts by offense, and the race and gender of search subjects.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(j)
Introduced
The Executive Office of Public Safety and Security must publish on its website by March 31 each year aggregated data on facial recognition searches by non-law-enforcement public agencies for the prior calendar year, disaggregated by agency, including the race and gender of search subjects.
MA
Introduced
Developers must publish a plain-language summary on their website detailing: (1) the types of AI systems they develop, (2) measures taken to mitigate algorithmic discrimination, and (3) contact information for inquiries.
MA
Introduced
Deployers must publicly disclose the types of high-risk AI systems in use and their risk mitigation strategies.
MA
Introduced
Developers must publish and maintain on their website or in a public use case inventory a statement summarizing: (1) the types of high-risk AI systems the developer currently makes available; and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination. The statement must be updated as necessary for accuracy and no later than 90 days after any intentional and substantial modification to any listed system.
MA
Introduced
Deployers must publish and maintain on their website a clear and readily available statement summarizing: (1) the types of high-risk AI systems currently deployed; (2) how the deployer manages known or reasonably foreseeable risks of algorithmic discrimination for each system; and (3) in detail, the nature, source, and extent of the information collected and used by the deployer. The statement must be periodically updated.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must maintain a public registry of all algorithms used, including each algorithm's purpose, data sources, and general methodology.
MN
MN HF 3980 (Online Platform Algorithmic Transparency) § Minn. Stat. § 325M.35, subd. 3
Introduced
Covered online platforms must prominently and conspicuously publish on their website, service, or application (1) a list of each algorithmic recommender system used, (2) a description of each input and its data source, and (3) the weights used in each system, categorized into four quartile groups by relative importance.
MO
Introduced
Local educational agencies must annually publish on their public website a searchable list of all instructional software products with executed digital privacy agreements and academic-effectiveness verification, including product name, vendor, instructional purpose, and links to the agreement and verification summary. The list must be updated within ten business days of any software addition or removal.
MO
Introduced
Local educational agencies must provide written notice to parents within five school days when a new instructional software product is added mid-year, including links to the product's digital privacy agreement and academic-effectiveness verification summary, before making the software available for student use.
MO
Introduced
Local educational agencies must provide parents with timely written notice of any significant software update or change in data-collection or data-sharing practices that may affect digital privacy agreement compliance or trigger new consent requirements, and must maintain a publicly accessible two-year archive of previously used instructional software including product name, vendor, and dates of active use.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Persons developing automated systems must, whenever possible, provide New York residents with access to reporting that confirms respect for their data decisions and provides an assessment of the potential impact of surveillance technologies on their rights, opportunities, or access.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 507
Introduced
Persons developing and deploying automated systems must make summary reporting publicly available whenever possible, including plain language information about the automated systems and assessments of the clarity and quality of notice and explanations provided.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 508
Introduced
Persons developing and deploying automated systems must make summary reporting publicly available whenever possible, including a description of human governance processes and an assessment of their timeliness, accessibility, outcomes, and effectiveness.
NY
Introduced
Developers must publish on their website or a public use case inventory a clear, readily available statement summarizing: (1) the types of high-risk AI decision systems the developer has developed or intentionally and substantially modified and currently makes available; and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination from those systems. The statement must be updated as necessary for accuracy and no later than 90 days after any intentional and substantial modification.
NY
Introduced
Deployers must publish on their website a clear, readily available statement summarizing: (1) the types of high-risk AI decision systems currently deployed; (2) how the deployer manages known or reasonably foreseeable risks of algorithmic discrimination for each system; and (3) in detail, the nature, source, and extent of information collected and used by the deployer. The statement must be periodically updated.
NY
Introduced
Real estate brokers and online housing platforms using AI tools must document, retain, and provide public-facing reporting on their website describing their compliance with the anti-discrimination requirements for advertising and captioning AI tools, including any internal auditing methods used for such compliance.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 110
Introduced
Developers and deployers must publish a detailed public disclosure, in plain language, that provides a detailed and accurate representation of practices under this article, including: (1) identity and contact information (including for affiliated data-transfer entities); (2) links to evaluation/assessment/review summaries; (3) categories and processing purposes of personal data collected or processed; (4) third-party data transfer recipients and purposes; (5) a prominent description of how individuals can exercise their rights; (6) a general description of compliance practices for pre-deployment evaluations and algorithm standards; (7) a mandated disclaimer stating that the audit was conducted to comply with the Act and does not guarantee safety or legal compliance; and (8) the disclosure's effective date. The disclosure must be available in each covered language and accessible to individuals with disabilities.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 110
Introduced
Developers and deployers must make publicly available, in a clear, conspicuous, and readily accessible manner, a mechanism for any individual impacted by a covered algorithm to report potential violations of this article to the developer or deployer.
NY
Introduced
Large frontier developers must clearly and conspicuously publish a link on their website to the third-party verifier's published summary within 15 days of the verifier's publication.
NY
Introduced
Developers must publish on their website or a public use-case inventory a clear and readily available statement summarizing (1) the types of high-risk AI decision systems the developer has developed or intentionally and substantially modified and currently makes available to deployers or other developers, and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination arising from those systems. The statement must be updated as necessary to remain accurate and no later than 90 days after any intentional and substantial modification.
NY
Introduced
Deployers must publish on their website a clear and readily available statement summarizing (1) the types of high-risk AI decision systems currently deployed, (2) how the deployer manages known or reasonably foreseeable algorithmic discrimination risks for each system, and (3) in detail, the nature, source, and extent of the information collected and used. The statement must be periodically updated.
NY
Introduced
Deployers and developers must make publicly available, in a readily accessible manner, a plain-language policy summarizing the types of AEDTs in use or made available, and how they manage foreseeable discrimination risk arising from those tools.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(G)
Introduced eff 2026-11-01
State education agencies must publicly disclose all multi-agency data-sharing arrangements through the Data Transparency Portal.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-3
Introduced eff 2025-10-01
Developers must publish on their website or in a public use case inventory a statement summarizing the types of high-risk AI systems they currently offer, and how they manage known or reasonably foreseeable risks of algorithmic discrimination, updated within 90 days of any intentional and substantial modification.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-4
Introduced eff 2025-10-01
Integrators must publish on their website or in a public use case inventory a statement summarizing the types of high-risk AI systems they have integrated and how they manage algorithmic discrimination risks, updated within 90 days of any intentional and substantial modification.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must publish on their website a periodically updated statement summarizing the types of high-risk AI systems they deploy, how they manage algorithmic discrimination risks, and the nature, source, and extent of information collected and used.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-20
Introduced
Developers must publish and maintain on their website or in a public-use case inventory a clear statement summarizing (1) the types of high-risk AI systems the developer has developed or intentionally and substantially modified and currently makes available to deployers or other developers, and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination arising from those systems. The statement must be updated as necessary to remain accurate and no later than 90 days after any intentional and substantial modification.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must publish and periodically update on their website a clear statement summarizing: (1) the types of high-risk AI systems currently deployed; (2) how the deployer manages known or reasonably foreseeable risks of algorithmic discrimination from each deployed system; and (3) in detail, the nature, source, and extent of information collected and used by the deployer. Small deployers with fewer than 50 employees are exempt if other conditions in subsection (F) are met.
US
Introduced
Developers and deployers must publicly disclose a detailed, plain-language summary of their practices under the Act, including contact information, links to evaluation summaries, categories of personal data collected and their purposes, third-party data transfers, how individuals can exercise their rights, general compliance practices, a mandated audit disclaimer, and the effective date. The disclosure must be available in each covered language and accessible to individuals with disabilities.
US
Introduced
Developers and deployers must notify affected individuals before implementing material changes to disclosures, provide direct electronic notification in all covered languages, retain previous disclosure versions for at least 10 years and publish them on their website, and maintain a public log of material changes. Deployers must additionally provide a short-form notice (max 500 words) at first interaction with the covered algorithm, summarizing individual rights and drawing attention to unexpected practices or consequential actions.
US
Introduced
Developers and deployers must publish a detailed public disclosure covering entity identity and contact information, links to evaluation/assessment summaries, personal data categories collected, third-party data transfers, individual rights descriptions, compliance practices, a mandatory audit disclaimer, and the disclosure effective date. Disclosures must be in each covered language and accessible to individuals with disabilities.
WA
Introduced eff 2027-01-01
Deployers must make readily available a clear statement summarizing how the deployer manages any reasonably foreseeable risk of algorithmic discrimination arising from the use or deployment of the high-risk AI system.
WA
Introduced eff 2027-01-01
Deployers must make readily available a clear statement summarizing how the deployer manages any reasonably foreseeable risk of algorithmic discrimination arising from the use or deployment of the high-risk AI system.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.5
Failed
Deployers and developers must publish a clear, readily accessible public policy summarizing the types of automated decision tools they use or make available and how they manage the foreseeable risks of algorithmic discrimination arising from those tools.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.5
Failed
Deployers and developers must publish a clear, publicly accessible AI policy summarizing the types of automated decision tools they use or offer and how they manage reasonably foreseeable risks of algorithmic discrimination.
CO
Failed
Developers must publish on their website or in a public use case inventory a clear and readily available statement summarizing their high-risk AI systems, including intended uses and known risks.
CO
Failed
Deployers must publish on their website a clear and readily available statement summarizing their deployment of high-risk AI systems, including the types of systems deployed and their purposes.
CO
Failed
Developers must publish on their website or in a public use-case inventory a statement summarizing the types of high-risk AI systems they make available and their intended uses.
CO
Failed
Deployers must publish on their website a clear summary of the high-risk AI systems they deploy, including intended uses and risk information.
CO
Failed eff 2026-12-01
Social media platforms must prominently and clearly provide on their website or mobile application: (1) terms of service, policies, and community standards; (2) user privacy policies; (3) the purpose of each algorithmic recommendation system in use; (4) inputs used by each algorithmic recommendation system, including how each input is measured, uses minor personal data, influences recommendations, and is weighed relative to other inputs; and (5) for every feature using minor user personal data, descriptions of the feature's purpose, the personal data collected and used, how the data is used, any transfers to processors or third parties (with identity and purpose), and how long the data is retained.
CO
Failed eff 2025-05-05
Developers must publish and maintain on their website or in a public use case inventory a statement summarizing the types of high-risk AI systems they offer and how they manage known or reasonably foreseeable risks of algorithmic discrimination.
CO
Failed eff 2025-05-05
Deployers must publish and maintain on their website a clear and readily available statement summarizing the types of high-risk AI systems they deploy and how they manage associated risks.
CO
Failed
Developers must publish a clear and readily available statement on their website or in a public use case inventory summarizing specified information about their high-risk AI systems, effective June 30, 2026.
CO
Failed
Deployers must publish a clear and readily available statement on their website summarizing specified information about their high-risk AI systems, effective June 30, 2026.
CT
Failed
Developers must publish and maintain on their website or in a public use-case inventory a statement summarizing the types of high-risk AI systems they offer and how they manage algorithmic discrimination risks, updated within 90 days of any intentional and substantial modification.
CT
Failed
Integrators must publish and maintain on their website or in a public use-case inventory a statement summarizing the types of high-risk AI systems they have integrated and how they manage algorithmic discrimination risks, updated within 90 days of any intentional and substantial modification.
CT
Failed
Deployers must publish and periodically update on their website a statement summarizing the types of high-risk AI systems they deploy, how they manage algorithmic discrimination risks, and the nature, source, and extent of data collected and used.
IL
Failed
Deployers must publicly publish and maintain a clear, readily accessible policy summarizing (1) the types of automated decision tools currently in use or made available to others and (2) how the deployer manages the reasonably foreseeable risks of algorithmic discrimination from those tools.
IL
Failed
Developers must publicly post a clear, readily accessible policy summarizing (1) the types of automated decision tools they currently make available to others and (2) how they manage foreseeable algorithmic discrimination risks arising from use of those tools.
IL
Failed
Deployers must make publicly available, in a readily accessible manner, a clear policy summarizing: (1) the types of automated decision tools currently in use or made available to others by the deployer; and (2) how the deployer manages the reasonably foreseeable risks of algorithmic discrimination arising from those tools.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(h)
Failed
The executive office of public safety and security must publish annually on its website, by March 31, aggregated data on law enforcement facial recognition searches for the prior calendar year — disaggregated by requesting agency, search basis (warrant vs. emergency), alleged offense, and race and gender of search subjects.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(j)
Failed
The executive office of public safety and security must publish annually on its website, by March 31, the total number of facial recognition searches performed by or at the request of non-law-enforcement public agencies, disaggregated by agency, including the race and gender of search subjects.
MD
MD HB 1240 (AI in Health Care Decisions) § Health – General § 24–2503
Failed
Health care providers that use AI to determine or influence health care decisions must annually post on their website, by July 1, documentation detailing key data about AI-driven decisions from the preceding year — including human review thresholds, overturn rates, misdiagnosis rates, miscalculated dosage rates, instances of care plans disregarding preexisting conditions or contraindicated medications or patient care preferences, and any additional data the Department requires. This data must be archived and remain publicly available.
MD
MD HB 1240 (AI in Health Care Decisions) § Insurance § 15–147
Failed
Carriers that use AI to determine or influence health care decisions must annually post on their website, by July 1 beginning in 2026, documentation detailing key data about AI-driven decisions from the preceding year — including human review thresholds, overturn rates, denial rates, criteria used for approvals or denials, and any additional data required by the Commissioner. This data must be archived and remain publicly available.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–804
Failed
The Department must publish the AI policies and procedures on its website within 45 days of adoption.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5002
Failed
Developers must publish on their website or in a public use-case inventory a summary of each high-risk AI system offered for sale and the measures taken to manage algorithmic discrimination risks, and must update the publication within 90 days of any material system change.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must publish and periodically update a clear, prominently displayed statement on their website summarizing deployed high-risk AI systems, discrimination risk management practices, and the nature, source, and extent of personal information collected or used.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must maintain a public registry of all algorithms used, including each algorithm's purpose, data sources, and general methodology.
NC
Failed
Operators must publish a privacy policy accessible on the platform's website that discloses how user data will be used, stated in a succinct and easy-to-understand statement of less than 250 words.
NE
Failed
Developers must publish and maintain a public use case inventory that is clear and readily available, summarizing: (1) the types of high-risk AI systems developed and currently made available; (2) the types of high-risk AI systems intentionally and substantially modified and currently made available; and (3) how the developer manages known risks of algorithmic discrimination from those systems. The inventory must be updated as necessary for accuracy and no later than 90 days after any intentional and substantial modification.
NE
Failed
Deployers must publish and maintain a clear and readily available public statement disclosing: (1) the types of high-risk AI systems currently deployed; (2) how the deployer manages known risks of algorithmic discrimination from those systems; and (3) a description of the nature, source, and extent of information collected and used by the deployer. The statement must be updated at least annually.
NH
Failed
Covered businesses must prominently and clearly disclose on their website or mobile application their privacy policies, terms of service, and community standards; the purpose of each algorithmic recommendation system; the inputs used by each such system and how each input is measured, uses minors' data, influences recommendations, and is weighted; and for every feature using minors' personal data, the purpose, data collected and used, how data is used, any third-party transfers, and data retention periods.
NM
Failed
Developers must post on their website a public-use case inventory summarizing the types of high-risk AI systems they offer, how they manage algorithmic discrimination risks, and must update it within 90 days of any intentional and substantial modification.
NM
Failed
Deployers must publish on their website and make readily available to consumers (1) a summary of deployed high-risk AI systems and how algorithmic discrimination risks are managed, and (2) a detailed explanation of the information collected and used. The disclosure must be updated at least annually and upon deployment of a new high-risk AI system.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must, whenever possible, provide New York residents with access to reporting that confirms respect for their data decisions and assesses the potential impact of surveillance technologies on their rights, opportunities, or access.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 407
Failed
Designers, developers, and deployers must, whenever possible, make public summary reporting that includes plain-language information about automated systems and assessments of the clarity and quality of notice and explanations provided.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing or deploying automated systems must, whenever possible, make publicly available summary reporting describing human governance processes and assessing their timeliness, accessibility, outcomes, and effectiveness.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 414
Failed
Licensees must conspicuously post their license in their office and, if they have a public internet presence, on their website or mobile application.
NY
Failed
Deployers and developers must make publicly available, in a readily accessible manner, a plain-language policy summarizing (1) the type of automated employment decision tools currently in use or offered to others, and (2) how the entity manages foreseeable discrimination risks arising from those tools.
OK
OK HB 3835 (Ethical AI Act) § 75A O.S. § 1004
Failed
Developers must publicly publish a readily accessible policy summarizing the types of automated decision tools they make available and how they manage algorithmic discrimination risks for those tools.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-6
Failed
Deployers and developers must publicly publish a clear, readily accessible policy summarizing the types of automated decision tools they use or make available and how they manage the foreseeable risks of algorithmic discrimination from those tools.
US
Failed
Online platforms must disclose to users in conspicuous, accessible, and plain language — in each language the platform serves — a complete description of the platform's content moderation practices, including both automated and human-labor moderation.
US
Failed
Online platforms must disclose to users a complete, conspicuous, accessible, and plain-language description of their content moderation practices, including automated and human-labor-based methods, in every language the platform serves.
US
Failed
The Director of the Administrative Office of the United States Courts must release to the public, post online, and transmit to Congress each June a full report on the use of facial recognition in conjunction with reference photo databases.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3593
Failed
The OMB Director must provide guidance and a template for agency AI governance plans, requiring publication on a centralized public agency webpage using a uniform URL format (agencyname.gov/AI).
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3595
Failed
Each agency must publish its AI governance charters on the agency's public webpage and on the Federal AI System Inventory before the associated federal AI system is used, subject to narrow waivers for classified national security information or Director-approved exemptions.
US
Failed
Covered platforms with 10M+ monthly U.S. active users that predominantly host user-generated content must publish at least annually a public transparency report, based on an independent third-party audit, covering (1) minor-user metrics, (2) foreseeable risks of harm to minors, (3) descriptions of engagement-driving design features and personal data collection, (4) safeguard efficacy evaluations, (5) harm-content prevalence data, and (6) prevention and mitigation measures taken and planned.
US
Failed
Online platforms must disclose to users a complete description of their content moderation practices — including automated and human moderation methods — in conspicuous, accessible, plain, non-misleading language in every language the platform supports.
US
Failed
Developers and deployers must publish a comprehensive public disclosure covering their identity and contact information, links to evaluation and assessment summaries, categories of personal data collected or processed and processing purposes, third-party data transfers, a description of individual rights, general compliance practices, a mandated statutory disclaimer, and the effective date. Disclosures must be in plain language, available in all covered languages, and accessible to individuals with disabilities. Material changes require prior notification to affected individuals and a 10-year public version log.
US
Failed
The Secretary of Defense must make the unclassified portion of each annual AI submission publicly available.
UT
UT HB 286 (AI Transparency Act) § Utah Code § 13-72b-104
Failed eff 2026-05-06
Large frontier developers must publish on their website, before deploying a new or substantially modified foundation model as part of a covered chatbot, summaries of child safety risk assessments, assessment results, the extent of third-party evaluator involvement, and other steps taken to fulfill the child protection plan.
UT
UT HB 438 (AI Companion Chatbot Safety) § Utah Code § 13-72b-203
Failed eff 2026-05-06
Suppliers must publish on their website, not less than quarterly, clear and conspicuous disclosures covering: (1) safety protocols and their efficacy, (2) detection protocols and their efficacy, (3) findings of independent assessments, (4) user engagement estimates with methodology, and (5) the number and type of user-reported safety-critical situations. Disclosures may not include personal data of any Utah user.
VA
VA HB 249 (Law Enforcement AI Use) § Va. Code § 9.1-102(66)
Failed
The Department of Criminal Justice Services must establish and publish a model policy for the use of generative AI and machine learning systems to serve as a guideline for criminal justice agencies statewide.
VT
Failed
Developers must post a clear and conspicuous statement on their public-facing website summarizing the types of high-risk AI systems they have developed or substantially modified that are currently deployed, and how the developer manages foreseeable algorithmic discrimination risks for each.
VT
Failed
Deployers must post a clear and conspicuous statement on their public-facing website summarizing the types of high-risk AI systems currently deployed and how the deployer manages foreseeable algorithmic discrimination risks for each.
WA
Failed
Developers must publicly publish a clear, readily accessible policy summarizing the types of automated decision tools they make available and how they manage foreseeable algorithmic discrimination risks from those tools.
WI
WI AB 1161 (Minors Online Privacy) § Wis. Stat. § 100.80(4)
Failed eff 2027-01-01
Covered businesses must prominently and clearly publish on their website or mobile application (1) terms of service, privacy policies, and community standards; (2) the purpose, inputs, measurement methodology, minor-data usage, recommendation influence, and relative weighting for each algorithmic recommendation system; and (3) for each service feature using covered minors' personal data, the feature's purpose, data collected and used, how data is used, third-party data sharing details, and retention periods.
WI
Failed eff 2027-01-01
Covered businesses must prominently publish on their website or mobile application: (1) terms of service, privacy policies, and community standards; (2) the purpose and detailed input-level information for each algorithmic recommendation system, including how each input uses minors' personal data and influences recommendations; and (3) for each feature using minors' personal data, the feature's purpose, data collected, data used, how data is used, third-party sharing details, and retention periods.