H-01
Human Oversight & Fairness
Human Oversight of Automated Decisions
Deployers that use AI to make or inform consequential decisions about individuals must give those individuals meaningful rights to understand, review, and/or challenge the decision, and/or to obtain human review or override in high-stakes contexts.
Sub-obligations6
Bills191
Jurisdictions35
Enacted10
Show
Sort bills within section

6 sub-obligations of H-01

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
H-01.1 Explanation right
The individual must receive an explanation of the principal factors that drove the automated decision, in plain language specific enough to be actionable — not a generic statement that AI was used.
8Enacted 94Live 56Failed 158Total Jump →
H-01.2 Data disclosure right
The specific data inputs used in making the decision about this individual must be disclosed, including the right to know what data was used and to correct inaccurate data.
4Enacted 43Live 19Failed 66Total Jump →
H-01.3 Pre-decision notice
The individual must be notified before a consequential automated decision is made — informing them that an automated system will be used and what categories of decisions it can make.
5Enacted 100Live 65Failed 170Total Jump →
H-01.4 Right to request human review
The individual must have a clear, accessible mechanism to request human review of an automated decision. The right must be disclosed at or near the time of the decision. Human review must be available but the individual must invoke it.
7Enacted 68Live 44Failed 119Total Jump →
H-01.5 Appeal and contestation right
A defined process must exist for the individual to formally contest an automated decision and receive a substantive response explaining the outcome. The process must be accessible without unreasonable burden.
6Enacted 49Live 31Failed 86Total Jump →
H-01.6 Mandatory pre-action human sign-off
Before action is taken on an AI recommendation in defined high-stakes contexts, a qualified human reviewer must affirmatively review and authorize the decision. The human must have authority and practical ability to override — not merely ratify — the AI output.
3Enacted 64Live 43Failed 110Total Jump →
Bills That Map This Requirement 713 mappings
H-01.1
Explanation right
The individual must receive an explanation of the principal factors that drove the automated decision, in plain language specific enough to be actionable — not a generic statement that AI was used.
Enacted
8
Live
94
Failed
56
Total
158
CO
Enacted eff 2026-05-14
Deployers must, within 30 days after a covered ADMT materially influences a consequential decision resulting in an adverse outcome, provide the affected consumer with: (1) a plain-language description of the consequential decision and the role the covered ADMT played; (2) instructions and a simple-to-follow process to request additional information about the covered ADMT and inputs, including the ADMT name, version number (if applicable), developer, and the types, categories, and sources of personal data used (to the extent the deployer received the necessary information from the developer); and (3) an explanation of consumer rights under § 6-1-1705 and how to exercise them. Trade secrets and information protected by federal law need not be disclosed, but the deployer must notify the consumer if information is withheld. Creditors complying with ECOA and FCRA notice requirements satisfy this obligation for the same decision if the federal notice also meets the requirements of this section. FERPA-subject deployers may use existing FERPA processes.
CO
Enacted eff 2026-05-14
HIPAA-covered entities that use a covered ADMT to determine a patient's eligibility for financial assistance (including discounted care) must provide patients with: (1) a plain-language description of the consequential decision and the role of the covered ADMT; (2) the types of information relied upon in the eligibility determination (except trade secrets and legally protected information); (3) information on how to request correction of materially inaccurate personal data consistent with HIPAA and § 25.5-3-502; and (4) information on how to request meaningful human review or reconsideration, where applicable. Compliance may be through advance general disclosure or a notice within 30 calendar days after an adverse outcome. Additionally, all HIPAA-covered entities must provide patients with a general notice of use of advanced technologies, including covered ADMT, which may be incorporated with existing patient-rights notices.
CO
Enacted eff 2026-02-01
Deployers must, before making a consequential decision, (1) notify the consumer that a high-risk AI system will be used, (2) disclose the system's purpose, the nature of the decision, deployer contact information, a plain-language system description, and instructions for accessing the deployer's public transparency statement, and (3) inform the consumer of applicable opt-out rights under Colorado's privacy law. Notices must be delivered directly, in plain language, in all languages the deployer uses in ordinary business, and in a format accessible to consumers with disabilities.
CO
Enacted eff 2026-02-01
Deployers must, following an adverse consequential decision, provide the consumer with (1) a statement disclosing the principal reasons for the decision, including the degree of AI contribution, data types used, and data sources, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review where technically feasible.
CO
Enacted eff 2026-02-01
Deployers must, before making a consequential decision about a consumer using a high-risk AI system, provide the consumer with: (1) notice that a high-risk AI system has been deployed to make or substantially factor in the decision; (2) a statement disclosing the system's purpose, the nature of the consequential decision, deployer contact information, a plain-language description of the system, and instructions for accessing the deployer's public transparency statement; and (3) information about the consumer's right to opt out of profiling for decisions with legal or similarly significant effects under C.R.S. § 6-1-1306(1)(a)(I)(C) if applicable. All notices and statements must be provided directly to the consumer, in plain language, in all languages the deployer uses in ordinary business communications, and in a format accessible to consumers with disabilities. If direct delivery is not possible, the deployer must make the information available in a manner reasonably calculated to reach the consumer.
CO
Enacted eff 2026-02-01
Deployers must, when a consequential decision made using a high-risk AI system is adverse to the consumer, provide the consumer with: (1) a statement of the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the source(s) of that data; (2) an opportunity to correct any incorrect personal data used in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless an appeal would not be in the consumer's best interest (e.g., where delay might endanger the consumer's life or safety).
CT
Enacted eff 2026-07-01
Deployers must, before making an employment-related decision using automated employment-related decision technology as a substantial factor, provide the affected employee or applicant a written notice disclosing: (1) deployment of the technology, (2) its purpose and nature of the decision, (3) the technology's trade name, (4) categories of personal data analyzed and how they are assessed, (5) data sources, and (6) deployer contact information.
VA
Enacted eff 2026-07-01
Deployers must transmit consequential decisions to consumers without undue delay. For adverse decisions based on personal data beyond what the consumer directly provided, deployers must (1) disclose the principal reasons for the decision, including the degree of AI contribution, data types processed, and data sources; (2) provide an opportunity to correct inaccuracies in personal data under the VCDPA; and (3) provide an opportunity to appeal, with human review where technically reasonable and practicable, unless delay would risk the consumer's life or safety.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must, before finalizing a consequential decision made or facilitated by a covered ADS, provide the subject with a plain-language written disclosure identifying that an ADS will be used, the system's name, version, and developer, whether the use is within a developer-approved scope, the personal characteristics assessed, data sources, key disproportionately-affecting parameters, output structure and how outputs inform the decision, whether a human will review the outputs or decision, the subject's opt-out and appeal rights, and contact information for the deployer and any managing or interpreting entity. A medical emergency exception applies.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must, within five days after finalizing a consequential decision, provide the subject with a plain-language written disclosure containing the personal characteristics used, data sources, key disproportionately-affecting parameters, output structure and how outputs were used, the role of the ADS and whether human judgment was involved, contact information, and the subject's correction and appeal rights. Disclosures must be transmitted directly, provided in English and any regularly used language, made accessible to people with disabilities, and clearly presented. A medical emergency exception applies.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed eff 2026-01-01
Deployers must notify any natural person when a high-risk automated decision system is used to make a decision about them and disclose: (1) the purpose of the system and the specific decision it was used to make; (2) how the system was used to make the decision; (3) the type of data used; (4) contact information for the deployer; and (5) a link to the deployer's public website statement about its high-risk automated decision systems.
CA
CA SB 947 (Workplace ADS) § Lab. Code § 1524
Engrossed
Employers must provide workers with a written postuse notice at the time the worker is informed of any ADS-assisted disciplinary, termination, or deactivation decision. The notice must be a separate, stand-alone, plain-language communication in the worker's routine language, delivered via email, hyperlink, or other simple method. The notice must state: (1) that the employer used an ADS to assist in the decision; (2) that a human reviewer conducted an independent investigation and compiled corroborating evidence; (3) contact information for a human the worker may reach for more information about the decision and the worker's data-access rights; and (4) that the employer is prohibited from retaliating against the worker for exercising rights under the bill.
CA
CA SB 947 (Workplace ADS) § Lab. Code § 1524
Engrossed
When a worker exercises a data-access request, employers must provide a written, plain-language document accessible away from the workplace containing: (1) the specific decision for which the ADS was used; (2) the specific worker input data the ADS used and the specific output it produced; (3) any additional corroborating or supporting information used beyond the ADS output; (4) the name of the vendor or entity that created the ADS and the product name of the ADS; and (5) a copy of any completed impact assessments regarding the ADS.
NJ
Engrossed
Business entities that use information obtained through a biometric surveillance system to deny a consumer access to the business's premises or to remove a consumer from the premises must provide the consumer with a detailed explanation of the business entity's actions and the criteria used in making the determination.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must, for adverse consequential decisions, provide the consumer with (1) a statement disclosing principal reasons for the decision including the AI system's contribution, data types processed, and data sources; (2) an opportunity to correct incorrect personal data used in the decision; and (3) an opportunity to appeal the decision with human review where technically feasible.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2103
Introduced eff 2026-01-01
Healthcare insurers must provide an explanation, understandable at all literacy levels, of the rationale used by any AI-based algorithm or system when recommending denial, delay, or modification of healthcare services under a health benefit plan.
CA
CA AB 1898 (Workplace AI Tools) § Lab. Code § 1601
Introduced
Employers must provide written notice to affected workers and their exclusive bargaining representatives before using any workplace AI tool for employment-related decisions or workplace surveillance, including (1) at least 90 days before first deploying a new tool, (2) by February 1, 2027 for tools already in use, and (3) upon hire for new workers. The notice must be a standalone, plain-language communication containing the tool's purpose and justification, affected employment decisions, worker data collected and its storage, a description of the tool's inputs, analysis, and outputs, data access and transfer practices, surveillance scope, tool vendor and model name, quotas and adverse-action consequences, job displacement impacts, manager/worker training, and results of any CCPA risk assessments.
CT
Introduced eff 2025-10-01
Employers must, before deploying a high-risk AI system to make or substantially factor into a consequential employee decision, (1) notify the employee that a high-risk AI system will be used, (2) disclose the system's purpose and the nature of the decision, (3) identify what employee data will be collected, (4) share the most recent impact assessment results, (5) inform the employee of the right to opt out and request an alternative decision-making process, (6) explain how to request reevaluation of any consequential decision, and (7) provide a plain-language description of the system. All disclosures must be delivered directly to the employee, in plain language, in the employer's business languages, and in accessible formats.
CT
Introduced eff 2025-10-01
Employers must, when a consequential decision made by or substantially based on a high-risk AI system is adverse to an employee, (1) disclose the principal reasons for the decision including the AI system's degree of contribution, the data types processed, and data sources, (2) allow the employee to examine and correct the personal data processed, and (3) provide an opportunity to appeal inaccurate-data-based decisions with human review.
CT
Introduced eff 2026-10-01
Deployers must, when an automated employment-related decision process makes or substantially factors into an adverse employment-related decision, provide the affected applicant or employee with: (1) a high-level statement disclosing the principal reasons for the adverse decision, including the degree and manner of the process's contribution, the type of data processed, and the source of that data; (2) an opportunity to examine and correct the data used and to appeal the decision with human review if it was based on incorrect data; and (3) upon request, a copy of the most recent bias audit. The high-level statement must be provided directly to the individual, in plain language, in all languages the deployer ordinarily uses in the state, and in a format accessible to individuals with disabilities.
GA
Introduced
Deployers must transmit to the consumer within one business day after an automated consequential decision a notice including: (1) a specific explanation of the principal factors and variables that led to the decision, including the degree and manner of AI contribution, the data sources processed, and a plain-language explanation of how the consumer's personal data informed those factors; (2) information about the consumer's right to correct data and how to submit corrections and supplementary information; (3) what actions the consumer might have taken to secure a different decision and may take in the future; (4) information on opportunities to correct incorrect personal data processed in the decision; and (5) information on opportunities to appeal an adverse decision, which appeal must allow for human review if technically feasible.
HI
Introduced
Deployers must, within 30 days after using an algorithmic decision system to make or influence a covered decision, provide the affected individual with a plain-language disclosure listing (1) the types, categories, and sources of personal characteristics analyzed, predicted, input, inferred, or collected, (2) the top 20 personal characteristics that most substantially influenced the output, and (3) information on how to exercise access and correction rights.
HI
HI SB 2167 (Healthcare AI & Prior Authorization) § HRS § 432E-5 (Complaints and appeals procedure for enrollees — amended by Section 5)
Introduced
Health carriers must include in each denial notice the specific reasons for the denial, referencing the enrollee-provider contract, the specialty of the reviewing provider, the applicable medical or clinical policy sections, and the specific reasoning of the reviewing provider.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Consequential decisions; notice; statement; opt-out; corrections; appeal)
Introduced eff 2028-07-01
Health care providers must, before using an AI system to make or substantially factor into a consequential decision, provide the patient or authorized representative with a written notice that: (1) informs them that AI will be used to make or substantially factor into the consequential decision; (2) discloses the purpose of the AI system and the nature of the consequential decision; (3) describes the AI system in plain language; and (4) allows the patient to opt out of processing of individually identifiable health information or other personal data for purposes of profiling in furtherance of decisions that have legal or similarly significant effects. The notice must be provided directly to the patient or authorized representative, or if that is not possible, in a manner reasonably calculated to ensure receipt.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Consequential decisions; notice; statement; opt-out; corrections; appeal)
Introduced eff 2028-07-01
Health care providers that used an AI system to make or substantially factor into a consequential decision must provide the patient or authorized representative with: (1) a written statement describing the consequential decision and its principal reasons, including the degree and manner of the AI system's contribution, the types of data the AI processed, and the sources of that data; (2) an opportunity to correct any incorrect health information or personal data the AI system processed in making the decision; and (3) an opportunity to appeal the consequential decision, including human review of all information relating to the decision to the extent technically feasible. The appeal right does not apply when providing an opportunity for appeal is not in the patient's best interest, including when any delay might pose a risk to the patient's life or safety.
HI
Introduced
Deployers must provide consumers, in plain language and at or before the time of an adverse action, (1) notice that a high-risk AI system was used in the consequential decision, (2) a description of the type of information used and the primary factors contributing to the decision, and (3) information on how to request correction, submit additional information, seek reconsideration, and obtain human review. Trade secrets need not be disclosed, but a meaningful explanation must be provided.
IA
Introduced
Employers must provide written advance notice to each employee (or authorized representative) who will foreseeably be directly affected by an automated decision system used for employment-related decisions other than hiring. The notice must be provided: (1) at least 30 days before an automated decision system is first deployed; (2) no later than January 1, 2027, for systems already in use at the effective date; and (3) within 30 days of hiring a new employee. The notice must contain: (a) the type of employment-related decisions affected; (b) a general description of the categories of employee-input data, data sources, and collection methods; (c) any key parameters known to disproportionately affect the system's output; (d) the vendor or entity that created the system; (e) if applicable, a description of each quota including quantified tasks, potential adverse actions for failure to meet the quota, and whether the quota is subject to change; (f) the employee's right to access and correct data; and (g) a statement that retaliation is prohibited. The notice must be in plain language, stand-alone, in the employee's routine language, and delivered via a simple method such as email, electronic link, or other written format.
IA
Introduced
Employers that primarily relied on an automated decision system to make a discipline, termination, or deactivation decision must provide the affected employee with a written notice at the time the employer informs the employee of the decision. The notice must contain: (a) a contact person for more information; (b) a statement that the employer used an automated decision system to assist in the decision; (c) a statement that the employee has the right to request a copy of the data used by the system; and (d) a statement that retaliation for exercising chapter rights is prohibited. The notice must be in plain language, stand-alone, in the employee's routine language, and delivered via a simple method.
IL
Introduced
Health care entities must ensure registered professional nurses have access to the data inputs and key factors that produced any AI recommendation used in direct patient care.
IL
Introduced
Health care entities must ensure registered professional nurses have access to the data inputs and key factors that produced any AI recommendation used in direct patient care.
IN
Introduced eff 2026-07-01
Employers must, within seven days after making an employment-related decision using automated decision system output, provide the covered individual with full, accessible, and meaningful documentation in plain language and at no cost, including: (i) a description of the automated decision system used; (ii) a plain-language description and explanation of the input data and a machine-readable copy of that data; (iii) a description and explanation of how the output was used in making the decision; and (iv) the reasoning for using the output in the decision.
IN
Introduced eff 2026-07-01
Employers that use or intend to use automated decision system output in employment-related decisions must disclose to each covered individual: (1) the fact of use or intended use; (2) a description of the system, including input data types and collection circumstances, characteristics measured, job-relevance of those characteristics, measurement methodology, and plain-language interpretation guidance; (3) the identity of the entity operating the system; (4) how the output is or will be used in the decision; and (5) how the individual may dispute or appeal the decision. Existing employees hired on or before July 1, 2026 must receive disclosures by August 1, 2026. Candidates and future hires must receive disclosures before hiring. Employers must provide updated disclosures within 30 days of any significant change or new information.
LA
Introduced
Employers must provide written notice to each worker (or authorized representative) who will foreseeably be directly affected by an ADS used for employment-related decisions (excluding hiring). Notice must be provided at least 30 days before first ADS deployment, at the time the Part takes effect if the ADS is already in use, or within 30 days of a new worker's hiring date. The notice must be a separate, standalone, plain-language communication in the worker's routine language, delivered via an accessible method. The notice must include: (1) the types of employment-related decisions affected, (2) categories, sources, and collection methods for worker input data, (3) any key parameters known to disproportionately affect ADS output, (4) the individuals, vendors, or entities that created the ADS, (5) if applicable, each quota set or measured by the ADS with quantified metrics, potential adverse actions for failure to meet quotas, and whether quotas are subject to change, (6) the worker's right to access and correct data used by the ADS, (7) that retaliation is prohibited, and (8) the worker's right to appeal any ADS-assisted decision and the appeal process.
LA
Introduced
Employers that primarily rely on an ADS to make a discipline, termination, or deactivation decision must provide the affected worker with written notice at the time the decision is made. The notice must be a separate, standalone, plain-language communication in the worker's routine language, and must include: (1) the human individual to contact for more information and to request a copy of the worker's data relied on in the decision, (2) that the employer used an ADS in the decision, (3) that the worker has a right to request a copy of the data used by the ADS, (4) that retaliation is prohibited, and (5) the worker's right to appeal the decision under R.S. 23:975.
LA
Introduced
Covered insurers must, within 21 days of a consumer's request, provide a written, consumer-specific explanation of any adverse action involving an ADS, including the top contributing factors ranked by relative contribution, data sources used, the right to correct data, and the right to file a complaint. Trade-secret protection does not relieve this obligation.
LA
Introduced eff 2026-08-01
Health insurance issuers must allow covered persons, upon request, to review and obtain copies of all documents relevant to any AI or automated decision system used in the utilization review or determination process.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Introduced
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime who were identified using a facial recognition search that they were subject to such a search and (2) make readily available to defendants and their attorneys all records pertaining to facial recognition searches performed during the investigation, including match results, algorithm details, accuracy rates, audit testing, operator identities, training records, and the selection methodology.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Introduced
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime that a facial recognition search was used in their identification, and (2) make readily available to defendants and their attorneys all records pertaining to facial recognition searches conducted during the investigation — including search results, alternative matches, the algorithm used, system accuracy rates, audit testing records, officer identity and training, and the match-selection process.
MA
Introduced
Employers must disclose to affected employees no less than 30 days before a monitoring-based employment decision goes into effect: (1) that the decision was based on electronically-monitored data, (2) the specific monitoring tools used and how they work, (3) the specific data and judgments used, and (4) any non-monitoring information used in the decision.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that the tool will be used, (2) the qualifications and data attributes assessed and outputs produced, (3) data sources and retention policy, (4) the most recent impact assessment results, (5) how to request an alternative non-automated selection process, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all employee-facing languages, provided directly to candidates, and accessible to individuals with disabilities.
MA
Introduced
Deployers must (1) notify consumers when an AI system materially influences a consequential decision, (2) provide consumers with the purpose of the system and an explanation of how the system influenced the decision, and (3) provide a process to appeal or correct adverse decisions.
MA
Introduced
Deployers must, before a consequential decision is made, notify the consumer that a high-risk AI system has been deployed to make or be a substantial factor in making the decision. Deployers must also provide a statement disclosing: (1) the purpose of the system and the nature of the consequential decision; (2) the deployer's contact information; (3) a plain-language description of the system; and (4) instructions on how to access the deployer's public website summary. If applicable, deployers must inform the consumer of the right to opt out of personal data processing for profiling in furtherance of decisions with legal or similarly significant effects. Notices must be provided directly to the consumer, in plain language, in all languages in which the deployer ordinarily communicates with consumers, and in a format accessible to consumers with disabilities. If direct delivery is not possible, the deployer must make the information available in a manner reasonably calculated to reach the consumer.
MA
Introduced
Deployers must, when a consequential decision is adverse to the consumer, provide: (1) a statement disclosing the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the sources of that data; (2) an opportunity to correct any incorrect personal data the system processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless the appeal would not be in the consumer's best interest (e.g., where delay poses a risk to the consumer's life or safety).
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Introduced
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime that they were identified using a facial recognition search and (2) make readily available to defendants and their attorneys all records pertaining to facial recognition searches conducted during the investigation, including search results, alternative matches, the algorithm and accuracy rate, audit testing, searcher identity, training records, and the match-selection process.
MA
Introduced
When an employer makes a hiring, promotion, termination, disciplinary, or compensation decision based in whole or part on electronic monitoring data, the employer must disclose to affected employees no less than thirty days before the decision takes effect: (1) that the decision was based in whole or part on electronic monitoring data; (2) the specific monitoring tools used, how they gather and analyze data, and the time increments of data collection; (3) the specific data and judgments used in the decision-making process; and (4) any non-monitoring information used in the decision.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool to assess or evaluate them. The notice must include: (1) that an automated tool will be used; (2) the qualifications and characteristics the tool assesses, the data or attributes used, and the types of outputs produced; (3) what data is collected, its source, and the data retention policy; (4) results of the most recent impact assessment including any disparate impact findings and employer response; (5) how to request an alternative selection process or accommodation not involving the automated tool; and (6) how to request reevaluation of the tool's decision and the right to file a civil complaint. The notice must be written in plain language, included in job postings, posted on the employer's website in all employee-communication languages, provided directly to each candidate in their language, accessible to persons with disabilities, and otherwise presented to ensure clear and effective communication.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must be able to provide a plain-language explanation of each algorithmic evaluation, meeting at minimum an 8.0 on the Flesch–Kincaid readability scale.
MN
Introduced
Employers must provide a written pre-use notice to every worker (or their authorized representative) and any representing union before deploying an automated decision system for employment-related decisions. The notice must be provided: (1) at least 30 days before introducing a new ADS; (2) no later than September 1, 2026 for existing ADS; (3) prominently to job applicants or new workers before collecting personal information for ADS processing; (4) at least 30 days before any significant change; and (5) to unions on a timeline allowing meaningful bargaining. The notice must be a standalone plain-language communication in the worker's routine language and must include: the nature, purpose, and scope of the ADS; the specific data categories and sources; the system logic and key parameters; the identity of the ADS creator and operators; the job qualifications assessed and evaluation outputs; results of any impact assessments; a list of all ADS the employer currently uses; and a description of worker rights. A copy of every notice must be submitted to the commissioner of labor and industry within ten days.
MN
Introduced
Employers must provide a post-decision written notice to every worker affected by an ADS-informed employment decision. The notice must be provided: (1) at the time the worker is informed of the decision, or no later than 15 business days after the decision, whichever is earlier; or (2) for discipline or termination, at least 30 days before it takes effect. The notice must acknowledge that an ADS was used, describe worker rights, include a form or link to appeal or request detailed information, and state that retaliation is prohibited. For repeated same-use ADS within a quarter, a full notice is required for the first use each quarter and a summary notice at quarter-end covering the number and dates of uses and worker rights.
MN
Introduced
Employers must respond to a worker's access request within 14 calendar days and provide: (1) a plain-language explanation of the specific decision; (2) the specific worker data used by the ADS and all worker-specific outputs; (3) how the ADS output was used, including the rationale, the roles of ADS output and human involvement, corroborating information, the ADS logic and assumptions as applied to the worker, the key parameters and how they applied, and the range of possible outputs with aggregate statistics for comparison; (4) the name of the ADS creator and the product name; and (5) a copy of any completed impact assessments. Service providers, contractors, and vendors must provide full assistance to the employer in fulfilling access requests, including providing worker input/output data and relevant ADS information in their possession.
MN
Introduced
Employers must provide affected workers with written post-decision notice when monitoring data was used in an employment-related decision — at the time of the decision or within 15 business days, or at least 30 days before discipline or termination takes effect. The notice must acknowledge monitoring-data use, describe worker rights, provide an appeal form link, and state the anti-retaliation prohibition.
MN
Introduced
Employers must respond to worker access requests within 14 calendar days with a plain-language explanation of the decision, identification of the specific monitoring tool and its data-collection methodology, a machine-readable copy of the worker's monitored data, any additional decision inputs (including automated decision system inferences and aggregate benchmark data), and the names of monitoring vendors. Vendors must provide full assistance to employers in fulfilling access requests.
MN
Introduced eff 2027-01-01
Employers must provide workers with written post-decision notice when monitoring data was used in an employment-related decision — within 15 business days of the decision, or at least 30 days before discipline or termination takes effect. The notice must acknowledge use of monitoring data, describe worker rights, include an appeal form, and state the anti-retaliation prohibition.
MN
Introduced eff 2027-01-01
Employers must, within 14 calendar days of a worker's access request, provide a plain-language explanation of the decision, identification of the monitoring tool and how it operates, a machine-readable copy of the worker's data, any additional information used in the decision (including automated inferences and benchmark data), and the names of monitoring vendors. Vendors must fully assist in responding.
MN
Introduced eff 2027-01-01
Employers must provide affected workers, their authorized representatives, and any representing union with a written, plain-language pre-use notice at least 30 days before introducing or significantly modifying an automated decision system, disclosing the system's purpose, data categories, logic, key parameters, creator and operator identity, job qualifications assessed, impact assessment results, a current list of all automated decision systems in use, and a description of worker rights.
MN
Introduced eff 2027-01-01
Employers must provide each affected worker with a written post-decision notice — at the time of the decision or within 15 business days (30 days before discipline takes effect) — acknowledging use of an automated decision system, describing worker rights, providing an appeal form, and stating the anti-retaliation protection. For repeat use of the same system, a full notice for the first quarterly use plus a quarterly summary is required.
MN
Introduced eff 2027-01-01
Employers must, within 14 calendar days of a worker's access request, provide the specific data used, all outputs produced, the rationale for the decision (including the roles of the system output and human involvement), the system logic as applied to the worker, key parameters, the range of possible outputs with aggregate statistics, the system creator's name, and any completed impact assessments. Vendors must provide full assistance to the employer in responding.
MO
Introduced
Employers must not discipline or terminate an employee for failure to meet a performance standard without first providing written notice that includes a plain-language explanation of reasons, the effective date, and all records relied upon to substantiate the action.
NJ
Introduced
Employers must notify each covered individual within 30 days of use that an automated employment decision tool was used, disclose the job qualifications or characteristics assessed, the data sources, the employer's data retention policy, the tool name and vendor, and — if the outcome was adverse — provide a written statement of specific reasons and sufficient disclosures to enable the individual to contest the employment decision.
NJ
Introduced
Employers must, before requesting a video interview analyzed by AI, (1) notify the applicant that AI may be used to analyze the video and assess fitness, (2) explain how the AI works and what characteristics it evaluates, and (3) obtain written consent (which may be electronic) before proceeding with AI evaluation.
NJ
Introduced
Employers and public entities must provide at least 10 days' advance written notice before any adverse AI-assisted employment or public-benefit decision takes effect, explaining the reasons, providing access to all data, and informing the individual of appeal rights. Upon request within 30 days, the employer must (1) allow the individual to review and copy all data and receive a complete explanation of how the AEDS or ABSDS produced its outputs including factor weighting, (2) allow the individual to appeal on grounds of data inaccuracy, bias, or legal violations, and (3) designate a qualified human reviewer with authority and discretion to modify or overturn the decision. For applicants, notice must be provided no later than the time of the decision.
NJ
Introduced
Employers must, before requesting an AI-analyzed video interview, (1) notify the applicant that AI may be used to analyze the video and assess fitness, (2) explain how the AI works and what characteristics it evaluates, and (3) obtain written consent to be evaluated by AI. Employers may not use AI to evaluate an applicant who has not consented.
NJ
Introduced
Business entities that use biometric surveillance information to deny a consumer access to premises or to remove a consumer from premises must provide the consumer with a detailed explanation of the entity's actions and the criteria used in making the determination.
NJ
Introduced
Employers and public entities must give at least 10 days' advance written notice of an adverse decision made using an EMT, AEDS, or ABSDS (or notice at decision time for application rejections), explaining the reasons, providing access to all relevant data and a full explanation of how the system was used, and stating access, contest, and relief rights.
NM
Introduced eff 2026-07-01
Deployers must, after an adverse consequential decision, provide the consumer with (1) a statement explaining the principal reasons for the decision and the specific data about the consumer that most influenced it, (2) the degree of AI contribution and level of human oversight, (3) the source and type of data processed, and (4) an opportunity to correct any incorrect personal data used.
NY
Introduced
Food delivery platforms must provide delivery workers, upon request, with a written explanation of any suspension, deactivation, or significant limitation of access to work imposed through an algorithmic management system.
NY
Introduced
Employers must provide each worker (or authorized representative) foreseeably affected by an ADS with a written, plain-language, standalone pre-use notice at least 30 days before first deploying the ADS (or by January 1, 2027 for systems already in use), and within 30 days of hiring a new worker. The notice must describe: (1) the types of employment-related decisions affected, (2) categories and sources of worker input data, (3) parameters disproportionately affecting output, (4) ADS vendor contact information, (5) applicable quotas and adverse consequences, (6) data access and correction rights, and (7) the employer's anti-retaliation obligation.
NY
Introduced
Employers that primarily relied on ADS output for a discipline, termination, or deactivation decision must provide the affected worker with a written, plain-language, standalone notice at the time the decision is communicated. The notice must identify a human contact, state that an ADS was used, disclose the worker's right to request a copy of their data, and state the employer's anti-retaliation obligation.
NY
Introduced
Employers and employment agencies that use an automated employment decision tool to screen job applicants must notify each candidate of: (1) that an automated employment decision tool will be used in connection with the assessment or evaluation of the candidate; (2) the job qualifications and characteristics the tool will use in assessing the candidate; and (3) the type of data collected for the tool, the source of that data, and the employer's or employment agency's data retention policy.
NY
NY AB 3125 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must notify an applicant of the reason for denial if the applicant's housing application is denied through use of the automated housing decision making tool.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 507
Introduced
New York residents must have the right to understand how and why an outcome impacting them was determined by an automated system, even when the system is not the sole determinant of the outcome. Automated systems must provide explanations that are technically valid, meaningful to the individual, and proportionate to the level of risk based on context.
NY
Introduced
Employers must notify employees and candidates, before or at the time of an employment decision, that an AEDT is being used, what qualifications and data it assesses, what outputs it produces, the data sources and retention policy, and (for 100+ employee employers) the most recent impact assessment results. Notice must be in clear and plain language, included in every relevant job posting, and posted on the employer's website in English and the ten most commonly spoken non-English languages in the state.
NY
Introduced
Landlords must notify each housing applicant at least 24 hours before using an automated decision tool that (1) the tool will be used, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's retention policy, and (4) the reason for any denial. The notice must allow the applicant to request an alternative selection process or accommodation.
NY
Introduced
Banks must notify each loan applicant at least 24 hours before using an automated decision tool that (1) the tool will be used, (2) the characteristics it will evaluate, (3) the type and source of data collected and the bank's retention policy, and (4) the reason for any denial. The notice must allow the applicant to opt out of or consent to the use and retention of their personal information.
NY
Introduced
Before deploying a high-risk AI decision system to make or substantially factor into a consequential decision concerning a consumer, the deployer must: (1) notify the consumer that the system is being used; (2) provide a statement disclosing the system's purpose and the nature of the consequential decision; (3) provide deployer contact information; (4) provide a plain-language description of the system; and (5) provide instructions for accessing the deployer's public website statement on deployed systems. All notices must be provided directly to the consumer, in plain language, in all languages the deployer ordinarily uses for consumer communications, and in a format accessible to consumers with disabilities.
NY
Introduced
When a high-risk AI decision system has been used to make or substantially factor into an adverse consequential decision concerning a consumer, the deployer must provide the consumer: (1) a statement disclosing the principal reasons for the adverse decision, including the degree and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data the system processed; and (3) an opportunity to appeal the adverse decision, which must include human review if technically feasible, unless human review would not be in the consumer's best interest (e.g., where delay poses a risk to life or safety).
NY
Introduced
When a deployer withholds information from a consumer under the trade secret or legal protection exemption, the deployer must send notice to the consumer disclosing: (1) that information is being withheld; and (2) the basis for the decision to withhold.
NY
Introduced
Covered entities must notify each loan applicant at least 24 hours before using an automated lending decision-making tool that (1) an automated tool will be used in their assessment, (2) the criteria the tool will apply, (3) the types and sources of data collected and the entity's data retention policy, and (4) within 24 hours after any denial, to the extent practicable, the reason for the denial.
NY
Introduced
Employers must notify applicants that an automated system will be used in the hiring process, describe in plain language the type of data the system analyzes, and describe the role of the human reviewer in the final employment decision.
NY
Introduced
Employers must notify employees and candidates before or at the time of an employment decision that an AEDT will be used, including what qualifications and data the tool assesses, what data is collected and its source, the employer's data retention policy, and (for employers with 100+ employees) the most recent impact assessment results. Notices must be in plain language, included in job postings, and posted on the employer's website in English and the ten most commonly spoken non-English languages in the state.
NY
Introduced
Employers must disclose to affected employees at least 14 days before a monitoring-based employment decision takes effect: that the decision was based on electronically monitored data, the specific monitoring tools used, the specific data and judgments derived from that data, and any non-monitoring information used in the decision.
NY
Introduced
Employers must notify employees and candidates at least 10 business days before using an AEDT to assess or evaluate them, disclosing: that an AEDT will be used; the qualifications assessed, data inputs, and output types; what data is collected and its source and retention policy; the most recent impact assessment results including any disparate impact findings; how to request an alternative non-AEDT selection process or accommodation; and how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all languages regularly used with employees, provided directly to each candidate in their language, and available in accessible formats.
NY
Introduced
Employers must provide written notice at least 14 calendar days before any employment decision based on monitoring data or AEDT output takes effect, disclosing performance standards, the employee's monitored data, aggregated peer data for the prior 90 days, AEDT outputs, the most recent impact assessment, and all non-monitoring information used. Employees may request reevaluation in writing (including text or email) by identifying the disputed data or output and providing supporting evidence. Employers must investigate and respond within seven calendar days, providing evidence of accuracy or correcting the data and reevaluating the decision without the flawed input.
NY
Introduced
Deployers must, when a high-risk AI decision system makes or substantially factors into an adverse consequential decision concerning a consumer, provide the consumer with: (1) a statement disclosing the principal reasons for the adverse decision, including the degree to which and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless providing such opportunity would not be in the consumer's best interest (e.g., delay posing life or safety risk).
NY
Introduced
Deployers must notify each individual subject to a consequential employment decision, at or before the time of the decision, that an AEDT is in use, and must provide the tool's purpose, a plain-language description of how it is the controlling factor, and deployer contact information.
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must notify each applicant (1) that an automated housing decision making tool will be used, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's data retention policy, and (4) if the application is denied, the reason for denial.
NY
Introduced
Covered entities must, to the extent practicable, notify a loan applicant of the reason for denial within 24 hours after a loan application is denied through use of an automated lending decision-making tool.
NY
Introduced
Food delivery platforms must provide delivery workers with a written explanation upon request of any suspension, deactivation, or significant limitation of access to work imposed through an algorithmic management system.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must, within 30 days of making or effectuating a hiring, promotion, termination, disciplinary, or compensation decision based in whole or in part on data gathered through electronic monitoring, disclose to affected employees and their authorized representative: (1) that the decision was based in whole or in part on electronically monitored data, (2) the specific monitoring tools used, how they work to gather and analyze data, and the time increments in which data is gathered, (3) the specific data and judgments based on that data used in the decision-making process, and (4) any information used in the decision-making process gathered from sources other than electronic monitoring.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must, when a consequential decision is adverse to a consumer, (1) explain the principal reasons including the degree and manner of AI contribution, data types, and data sources, (2) allow the consumer to examine and correct personal data used, and (3) provide an opportunity to appeal based on inaccurate personal data with human review where technically feasible. All notices must be provided directly to the consumer, in plain language, in all languages the deployer ordinarily uses, and in formats accessible to consumers with disabilities.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must, when a high-risk AI system has made or been a substantial factor in making an adverse consequential decision concerning a consumer, provide the consumer with: (1) a statement disclosing the principal reasons for the decision, including the degree to which and manner in which the AI system contributed, the type of data processed, and the source(s) of that data; (2) an opportunity to correct any incorrect personal data that the AI system processed in making the decision; and (3) an opportunity to appeal the adverse decision, which appeal must, if technically feasible, allow for human review — unless providing the appeal opportunity is not in the consumer's best interest (e.g., where delay might pose a risk to the consumer's life or safety).
TX
TX HB 5496 (AI Transparency) § Bus. & Com. Code § 611.002
Introduced eff 2025-09-01
Persons using AI in conducting business or providing goods or services to Texas residents must make available to any individual affected by an AI-made decision an explanation of how and why the AI reached that decision.
US
Introduced
Covered entities must evaluate and document consumer rights with respect to covered algorithms, including (1) whether consumers receive clear notice that an algorithm will be used, (2) whether consumers have an opt-out mechanism, (3) the transparency and explainability of the algorithm, (4) any mechanisms for consumers to contest, correct, or appeal a decision, and (5) the extent to which third-party decision recipients access algorithm results.
US
Introduced
Employers must, within 7 days of making an employment-related decision using ADS output, provide the covered individual with free, plain-language documentation describing the ADS used, the input data (including a machine-readable copy), how the output was used, and the reasoning for relying on it.
US
Introduced
Employers must disclose to covered individuals, before making an employment-related decision (or within 30 days for existing employees pre-enactment, or before accepting an application for post-enactment candidates): that ADS output is or will be used; the system's description, data types collected, characteristics measured, how they relate to job functions, and how to interpret outputs; the ADS operator's identity; how the output will be used; and the dispute/appeal process. Updated disclosures must be provided within 30 days of material changes.
VA
Introduced
Landlords must, upon request, provide tenants or prospective tenants with a plain-language summary of the general factors considered by the algorithmic pricing device in determining rent. Landlords need not disclose proprietary formulas, source code, weighting of inputs, or other trade secrets.
VA
Introduced
Landlords must provide tenants and prospective tenants with a plain-language summary of the general factors considered by the algorithmic pricing device in determining rent. Proprietary formulas, source code, weighting of inputs, and trade secrets need not be disclosed.
VT
Introduced eff 2025-07-01
Employers must provide employees with written notice in plain, clear, and concise language before using an automated decision system to make an employment-related decision. The notice must include at minimum: (1) a plain language explanation of the ADS's nature, purpose, and scope, including specific employment decisions potentially affected; (2) the logic and key parameters affecting output; (3) the specific categories and sources of employee input data, including any data from electronic monitoring; (4) performance metrics the employer will use with the ADS; (5) the types of outputs the ADS will produce; (6) the developer(s) of the ADS; (7) the operator(s), monitor(s), and interpreter(s) of ADS results; (8) how to access the most recent impact assessment; (9) a description of the employee's rights to access and correct data under subsection (j); and (10) a statement that employees are protected from retaliation.
VT
Introduced eff 2025-07-01
Deployers must provide the consumer with a single post-decision notice containing a plain-language explanation of the consequential decision that identifies the principal reasons for the decision, including: (1) the identity of the developer if different from the deployer; (2) a description of the system's output (score, recommendation, etc.); (3) the degree and manner to which the automated decision system contributed to the decision; (4) the types and sources of data processed; (5) a plain-language explanation of how the consumer's personal data informed the decision; and (6) what actions the consumer might have taken or might take in the future to secure a different decision.
WA
Introduced eff 2028-07-01
Employers must include in the written notice (1) a statement that the employer uses electronic monitoring, (2) a general list of the types of monitoring technology used for the primary purpose of monitoring job performance, and (3) a statement whether the employer has a verification process that includes meaningful human review to confirm monitoring data.
WA
Introduced eff 2027-01-01
Deployers must transmit consequential decisions to consumers without undue delay. When a consequential decision is adverse to the consumer and based on personal information beyond what the consumer directly provided, the deployer must provide a statement disclosing the principal reasons for the decision, including: (1) the degree to which and manner in which the high-risk AI system contributed to the decision; (2) the type of data processed by the system in making the decision; and (3) the sources of such data.
WA
Introduced eff 2027-01-01
Deployers must transmit to the consumer any consequential decision made by a high-risk AI system without undue delay. If the decision is adverse to the consumer and based on personal data beyond what the consumer provided directly, the deployer must provide a statement disclosing the principal reason or reasons for the decision, including: (1) the degree to which and manner in which the AI system contributed to the decision; (2) the type of data processed in making the decision; and (3) the sources of such data.
CA
Failed
Employers must provide a written pre-use notice to each worker (or their authorized representative) who will foreseeably be directly affected by an ADS used for employment-related decisions other than hiring. The notice must be provided: (1) at least 30 days before an ADS is first deployed; (2) no later than April 1, 2026 for ADS already in use when the law takes effect; and (3) within 30 days of hiring a new worker. The notice must be written in plain language as a separate, stand-alone communication, in the worker's routine language, and delivered via a simple method such as email, hyperlink, or other written format. The notice must contain: the types of employment-related decisions affected; a general description of the categories, sources, and collection methods for worker input data; key parameters known to disproportionately affect ADS output; the ADS vendor or creator; any quota set or measured by the ADS (including task quantities, potential adverse actions for failure, and whether quotas are subject to change); a description of the worker's right to access and correct data used by the ADS; and a statement that retaliation for exercising those rights is prohibited.
CA
Failed
Employers that primarily relied on an ADS to make a discipline, termination, or deactivation decision must provide the affected worker with a written notice at the time the worker is informed of the decision. The notice must be in plain language as a separate, stand-alone communication, in the worker's routine language, delivered via a simple method, and must contain: (1) the human to contact for more information and to request a copy of the worker's data; (2) a statement that the employer used an ADS in the decision; (3) a statement that the worker has the right to request a copy of data used by the ADS; and (4) a statement that retaliation for exercising rights under this part is prohibited.
CO
Failed
Deployers must, when a high-risk AI system makes or substantially factors in an adverse consequential decision concerning a consumer, provide the consumer with the required adverse-decision disclosures.
CO
Failed
Deployers must provide consumers with an explanation and appeal opportunity when a high-risk AI system makes or substantially factors in an adverse consequential decision about them.
CO
Failed eff 2025-05-05
Deployers must, before each use of a high-risk AI system to make or substantially factor in a consequential decision about a consumer, disclose the system's purpose, trade name, developer name, deployer contact information, a plain-language description including the roles of AI and human components, the personal aspects evaluated, the evaluation method, relevance to the decision, accommodation information, and instructions for accessing the deployer's public statement.
CO
Failed eff 2025-05-05
Deployers must, within 30 days after an adverse consequential decision, provide a single notice disclosing the main reasons for the decision (including the AI system's contribution and the categories and sources of data that adversely affected the output, including sensitive data), information on how to exercise correction and appeal rights, and a copy of the notice. Deployers must offer an opportunity to correct incorrect personal data. For non-competitive, non-time-limited adverse decisions based on incorrect data or unlawful information, deployers must provide an opportunity to appeal with human review if technically feasible. The correction and appeal rights apply only to systems that are the principal basis of the decision.
CO
Failed
Deployers must provide consumers with specified information when a high-risk AI system makes or substantially factors into an adverse consequential decision, effective June 30, 2026.
CT
Failed
Deployers must, before making a consequential decision using a high-risk AI system, notify the consumer that AI is being used, disclose the system's purpose and the nature of the decision, offer opt-out rights, and provide contact information and a plain-language system description. If the decision is adverse, the deployer must disclose the principal reasons (including AI's contribution and the data types and sources used), provide an opportunity to examine and correct personal data, and offer an appeal with human review where technically feasible. All notices must be in plain language, multilingual, accessible, and delivered directly to the consumer.
HI
Failed
Covered entities must, upon taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure that includes (1) the entity's contact information, (2) the factors the determination depended on, and (3) an explanation that the individual may access any personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
HI
Failed
Covered entities must, upon taking any adverse action based on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's right to access their personal information used in the determination, submit corrections, and request a human-conducted reevaluation based on corrected data.
HI
Failed
Covered entities must, when taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's rights to access personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
IL
Failed
Deployers must notify any natural person subject to a consequential decision, at or before the time the automated decision tool is used, that an automated tool is being used and must provide (1) the tool's purpose, (2) the deployer's contact information, and (3) a plain-language description of the tool including its human and automated components.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(f)
Failed
Law enforcement agencies and district attorneys must (1) notify individuals charged with a crime that they were identified using a facial recognition search, and (2) make readily available to defendants and their attorneys all records about facial recognition searches in the investigation, including search results, alternative matches, algorithm details, accuracy rates, audit testing, operator identities, training records, and the match-selection process.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Failed
Law enforcement agencies and district attorneys must notify all individuals charged with a crime who were identified via facial recognition search, and must disclose to defendants and their attorneys all facial recognition search records — including results, all possible matches, the algorithm used, accuracy rates, audit testing results, operator identity and training, and the match-selection process.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(f)
Failed
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime that they were identified using a facial recognition search, and (2) provide defendants and their attorneys with all records of facial recognition searches conducted during the investigation, including search results, other possible matches, the algorithm used, accuracy rates, audit testing results, operator identity and training, and the process for selecting the defendant as the most likely match.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5005
Failed
Deployers must provide consumers with a standardized disclosure that (1) notifies the consumer a high-risk AI system is in use, (2) discloses the purpose of the system and the nature, reason, and degree of the AI's involvement in the decision, (3) identifies the data used and its source, (4) includes deployer contact information, and (5) is delivered directly to the consumer in plain language, in all languages the deployer regularly uses, and in an accessible format.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must be able to provide a plain-language explanation of each evaluation made by an algorithmic system, meeting at minimum an 8.0 on the Flesch–Kincaid readability scale.
NE
Failed
Deployers must, for each high-risk AI system that makes or is a substantial factor in making an adverse consequential decision concerning a consumer, provide to that consumer: (1) a statement disclosing each principal reason for the decision, including the degree and manner in which the AI system contributed to the decision, the type of data processed, and each source of that data; (2) an opportunity to correct any incorrect personal data that the system processed in making or contributing to the decision; and (3) an opportunity to appeal the adverse decision, unless an appeal is not in the consumer's best interest (e.g., where delay would risk life or safety), with human review if technically feasible. All notices, statements, and descriptions must be provided directly to the consumer, in plain language, in each language the deployer ordinarily uses in business communications, and in a format accessible to consumers with disabilities. If direct provision is not possible, the deployer must make the information available in a manner reasonably calculated to ensure the consumer receives it.
NJ
Failed
Business entities that use biometric surveillance system data to deny a consumer access to or remove a consumer from their premises must provide the consumer with a detailed explanation of the actions taken and the criteria used in making the determination.
NJ
Failed
Business entities that use biometric surveillance data to deny a consumer access to premises or remove a consumer from premises must provide the consumer with a detailed explanation of the actions taken and the criteria used in making the determination.
NM
Failed
Deployers must, after an adverse consequential decision, provide the consumer with (1) an explanation of the principal reasons, the degree and manner of AI contribution, and the source and type of data processed, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review if technically feasible.
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must notify any housing applicant whose application is denied through use of the automated decision tool of the reason for the denial.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 407
Failed
Persons developing or deploying automated systems must provide New York residents with explanations of how and why an outcome impacting them was determined — even when the system is not the sole determinant. Explanations must be technically valid, meaningful to the individual, and proportionate to the level of risk.
NY
Failed
Employers must document the information and judgments involved in their use of electronic monitoring data and communicate that documentation to affected employees before any hiring, promotion, termination, or disciplinary decision takes effect.
NY
Failed
Employers must notify employees and candidates at least 10 business days before using an automated employment decision tool, disclosing: (1) that an AEDT will be used, (2) the qualifications and characteristics assessed, data attributes used, and outputs produced, (3) data collected, its source, and the data retention policy, (4) the most recent bias audit results, (5) how to request an alternative selection process or accommodation, and (6) how to request internal review and the right to file a civil action.
NY
Failed
Employers must respond in writing within 60 days to reevaluation requests, providing the AEDT outputs used, a description of non-AEDT information that contributed to the decision, the employer's assessment of the complaint (with supporting evidence if disputed), reprocessing results if requested, and an explanation for any refusal to take remedial action.
NY
Failed
Employers must disclose to affected employees at least 14 days before an employment decision takes effect that the decision was based in whole or part on electronic monitoring data, identify the specific monitoring tools used, disclose the specific data and judgments used in the decision, and identify any non-monitoring information used.
NY
Failed
Employers must notify employees and candidates at least ten business days before using an AEDT to assess or evaluate them, disclosing: (1) that an AEDT will be used, (2) the qualifications and characteristics assessed, data attributes used, and outputs produced, (3) what data is collected and from what source, along with the data retention policy, (4) results of the most recent impact assessment including any disparate impact findings, (5) how to request an alternative non-AEDT selection process or accommodation, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website, provided to each candidate in their language, and accessible to employees with disabilities.
NY
Failed
Employers must provide affected employees written notice at least 14 calendar days before any employment decision based on monitoring data or AEDT outputs takes effect, disclosing: (1) performance standards used, (2) the employee's monitoring data used, (3) aggregated data for similarly situated employees for the prior 90 days, (4) any AEDT outputs used, (5) the most recent impact assessment of any AEDT used, and (6) any other information used in the decision.
NY
Failed
Deployers must notify individuals at or before the time of a consequential employment decision that an automated employment decision tool is in use, and must provide the individual with (1) a statement of the tool's purpose, (2) a plain-language description of how the tool is the controlling factor in the decision, and (3) deployer contact information.
NY
Failed
Employers using an automated employment decision tool to screen candidates must notify each candidate that an automated tool subject to disparate impact reporting was used and must disclose the specific job qualifications or characteristics the tool assessed.
NY
Failed
Employers must document and communicate to affected employees the information and judgments involved in the employer's use of electronic monitoring data before any hiring, promotion, termination, or disciplinary decision goes into effect.
NY
Failed
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that an AEDT will be used; (2) the qualifications assessed, data inputs and attributes used, and output types; (3) data collected, its source, and the retention policy; (4) the most recent bias audit results and employer response; (5) how to request an alternative selection process or accommodation; and (6) how to request internal reevaluation and the right to file a civil action.
NY
Failed
Employers must respond in writing within sixty days to a reevaluation request, disclosing: the AEDT outputs used in the decision, non-AEDT information that contributed, whether the employer agrees with the complaint and why, evidence supporting the tool's accuracy if the employer disagrees, reprocessing results if requested, and the reason for refusing any requested remedial action.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must notify each housing applicant (1) that an automated decision tool will be used to assess the applicant, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's data retention policy, and (4) if the application is denied, the reason for the denial.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 407
Failed
Residents must have the right to understand how and why an outcome impacting them was determined by an automated system, even when the system is not the sole determinant. Explanations must be technically valid, meaningful to the individual, and proportionate to the level of risk.
PA
Failed
Employers and employment agencies must notify each candidate at least ten days before their interview that an automated employment decision tool may be used, and must provide an explanation of how the tool works and what general types of characteristics it evaluates.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-3
Failed
Deployers must notify individuals at or before the time an automated decision tool is used for a consequential decision, providing the tool's purpose, deployer contact information, and a plain-language description of the tool's human and automated components.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.108
Failed
Deployers must provide consumers the right to appeal adverse consequential decisions made by high-risk AI systems and to obtain clear and meaningful explanations of the AI system's role in the decision and the main elements of the decision taken.
TX
Failed
Employers must, before using an automated employment decision tool on an applicant, (1) notify the applicant that an AEDT may be used, (2) describe how the tool will be used and what characteristics it evaluates, and (3) obtain the applicant's written consent.
US
Failed
The prosecution must provide criminal defendants with all results and reports from computational forensic software analysis, along with the software's executable copy, source code (current and prior versions), instructions, and all relevant files and data. Reports must include the developer name, lab name, software version, change history (including bugs), documentation of procedures followed per internal validation, documentation of conditions of use versus conditions of testing, and any additional NIST-specified information.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of automated decision system use, have a mechanism to opt out, can access information about the factors contributing to a decision, and can contest, correct, or appeal a decision, and must document all complaints, disputes, and remediation outcomes.
US
Failed
Law enforcement agencies that use facial recognition to attempt to identify an arrested individual must provide the individual with notice of the agency and database used, a copy of the authorizing court order, accuracy and bias reports, all probe images and modifications, the ranked candidate list, and all related police documentation, in an appropriate language if the individual is not fluent in English.
US
Failed
Covered entities must evaluate consumer rights in the impact assessment, including assessing whether consumers receive clear notice that an automated system will be used, whether a mechanism for opting out exists, the transparency and explainability of the system, and the degree to which consumers may contest, correct, or appeal decisions.
US
Failed
Employers must provide covered individuals, within 7 days of making an employment-related decision, with free, accessible, plain-language documentation describing the automated decision system, the input data (including a machine-readable copy), how the output was used in the decision, and the reasoning for using it.
US
Failed
Employers must disclose to covered individuals, before making an employment-related decision (or before accepting an application for candidates), that they use or intend to use an automated decision system, along with a description of the system's data inputs, measured characteristics, job relevance, measurement methodology, how to interpret outputs, the operator's identity, how outputs will be used, and how to dispute or appeal. Updated disclosures must be provided within 30 days of significant changes.
US
Failed
Employers must, within 7 days of making an employment-related decision using an automated decision system output, provide the covered individual with free, accessible, plain-language documentation covering (1) a description of the ADS, (2) the input data used and a machine-readable copy, (3) how the output was used in the decision, and (4) the reasoning for the use of the output.
US
Failed
Employers must disclose to covered individuals, prior to making an employment-related decision (or within 30 days for pre-enactment employees): (1) the fact of ADS use, (2) a description of the system including data types, measured characteristics, job-relatedness, measurement methodology, and how to interpret the output, (3) the identity of the ADS operator, (4) how the output will be used, and (5) how to dispute or appeal. For candidates applying post-enactment, disclosure must occur before accepting the application. Updated disclosures must be provided within 30 days of material changes.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of system use, have an opt-out mechanism, can access information about factors driving their decision, and can contest, correct, or appeal decisions — and must document all consumer complaints, disputes, corrections, appeals, opt-out requests, and remediation outcomes.
US
Failed
Covered entities must evaluate consumer rights with respect to the automated decision system, including: (1) whether consumers receive clear notice that the system will be used, (2) whether consumers can opt out, (3) the transparency and explainability of the system including which contributing factors drive decisions, (4) consumer contestation, correction, and appeal mechanisms, and (5) the extent to which third-party decision recipients access decision results.
VA
Failed
State agencies must disclose to affected individuals: (i) the fact that an automated decision system is being used; (ii) the intended use of the system (e.g., evaluating candidates, making compensation decisions, considering employees for promotion); (iii) the type of data inputs received by the system and the source of such data; (iv) how the system will be used in the agency's decision-making processes; and (v) the extent to which an individual's personal data will be shared with third parties or used as future inputs for the system.
VA
Failed
Local government entities must disclose to affected individuals: (i) the fact that an automated decision system is being used; (ii) the intended use of the system; (iii) the type of data inputs received and their source; (iv) how the system will be used in the entity's decision-making processes; and (v) the extent to which personal data will be shared with third parties or used as future inputs.
VT
Failed
Deployers must, no later than the time of a consequential decision, (1) notify the affected individual that a high-risk AI system is being used, (2) disclose the system's purpose, (3) provide deployer contact information, and (4) provide a plain-language description of the system including its human and automated components.
WA
Failed
Public agencies must give clear, plain-language notice to each individual impacted by an automated decision system disclosing: the fact that the system is in use, the system's name, vendor, and version, what decisions it will make or support, whether it is an automated final or support system and what human verification process applies, applicable deployment policies, and how the individual may contest any decision.
WA
Failed
Public agencies must be able to explain the basis for any automated decision to the impacted individual in terms understandable to a layperson, including by requiring the vendor to create such an explanation.
WA
Failed
Agencies must be able to explain the basis for any automated decision to impacted persons in terms understandable to a layperson, including by requiring the vendor to create such an explanation.
H-01.2
Data disclosure right
The specific data inputs used in making the decision about this individual must be disclosed, including the right to know what data was used and to correct inaccurate data.
Enacted
4
Live
43
Failed
19
Total
66
CO
Enacted eff 2026-02-01
Deployers must, following an adverse consequential decision, provide the consumer with (1) a statement disclosing the principal reasons for the decision, including the degree of AI contribution, data types used, and data sources, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review where technically feasible.
CO
Enacted eff 2026-02-01
Deployers must, when a consequential decision made using a high-risk AI system is adverse to the consumer, provide the consumer with: (1) a statement of the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the source(s) of that data; (2) an opportunity to correct any incorrect personal data used in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless an appeal would not be in the consumer's best interest (e.g., where delay might endanger the consumer's life or safety).
CT
CT SB 4 (Consumer Privacy) § Section 14 (amending Conn. Gen. Stat. § 42-518(a))
Enacted eff 2026-10-01
Controllers using automated profiling that produces a decision denying a consumer an employment opportunity must, on consumer request: (1) inform the consumer whether any of the personal data processed for the profiling was submitted by a third party; (2) allow the consumer to correct any incorrect third-party-submitted personal data used in the profiling; and (3) re-evaluate the profiling decision based on the corrected personal data.
VA
Enacted eff 2026-07-01
Deployers must transmit consequential decisions to consumers without undue delay. For adverse decisions based on personal data beyond what the consumer directly provided, deployers must (1) disclose the principal reasons for the decision, including the degree of AI contribution, data types processed, and data sources; (2) provide an opportunity to correct inaccuracies in personal data under the VCDPA; and (3) provide an opportunity to appeal, with human review where technically reasonable and practicable, unless delay would risk the consumer's life or safety.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must, within five days after finalizing a consequential decision, provide the subject with a plain-language written disclosure containing the personal characteristics used, data sources, key disproportionately-affecting parameters, output structure and how outputs were used, the role of the ADS and whether human judgment was involved, contact information, and the subject's correction and appeal rights. Disclosures must be transmitted directly, provided in English and any regularly used language, made accessible to people with disabilities, and clearly presented. A medical emergency exception applies.
CA
CA SB 947 (Workplace ADS) § Lab. Code § 1524
Engrossed
When a worker exercises a data-access request, employers must provide a written, plain-language document accessible away from the workplace containing: (1) the specific decision for which the ADS was used; (2) the specific worker input data the ADS used and the specific output it produced; (3) any additional corroborating or supporting information used beyond the ADS output; (4) the name of the vendor or entity that created the ADS and the product name of the ADS; and (5) a copy of any completed impact assessments regarding the ADS.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must, for adverse consequential decisions, provide the consumer with (1) a statement disclosing principal reasons for the decision including the AI system's contribution, data types processed, and data sources; (2) an opportunity to correct incorrect personal data used in the decision; and (3) an opportunity to appeal the decision with human review where technically feasible.
CT
Introduced eff 2025-10-01
Employers must, when a consequential decision made by or substantially based on a high-risk AI system is adverse to an employee, (1) disclose the principal reasons for the decision including the AI system's degree of contribution, the data types processed, and data sources, (2) allow the employee to examine and correct the personal data processed, and (3) provide an opportunity to appeal inaccurate-data-based decisions with human review.
CT
Introduced eff 2026-10-01
Deployers must, when an automated employment-related decision process makes or substantially factors into an adverse employment-related decision, provide the affected applicant or employee with: (1) a high-level statement disclosing the principal reasons for the adverse decision, including the degree and manner of the process's contribution, the type of data processed, and the source of that data; (2) an opportunity to examine and correct the data used and to appeal the decision with human review if it was based on incorrect data; and (3) upon request, a copy of the most recent bias audit. The high-level statement must be provided directly to the individual, in plain language, in all languages the deployer ordinarily uses in the state, and in a format accessible to individuals with disabilities.
GA
Introduced
Deployers must transmit to the consumer within one business day after an automated consequential decision a notice including: (1) a specific explanation of the principal factors and variables that led to the decision, including the degree and manner of AI contribution, the data sources processed, and a plain-language explanation of how the consumer's personal data informed those factors; (2) information about the consumer's right to correct data and how to submit corrections and supplementary information; (3) what actions the consumer might have taken to secure a different decision and may take in the future; (4) information on opportunities to correct incorrect personal data processed in the decision; and (5) information on opportunities to appeal an adverse decision, which appeal must allow for human review if technically feasible.
HI
Introduced
Deployers must, within 30 days after using an algorithmic decision system to make or influence a covered decision, provide the affected individual with a plain-language disclosure listing (1) the types, categories, and sources of personal characteristics analyzed, predicted, input, inferred, or collected, (2) the top 20 personal characteristics that most substantially influenced the output, and (3) information on how to exercise access and correction rights.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Consequential decisions; notice; statement; opt-out; corrections; appeal)
Introduced eff 2028-07-01
Health care providers that used an AI system to make or substantially factor into a consequential decision must provide the patient or authorized representative with: (1) a written statement describing the consequential decision and its principal reasons, including the degree and manner of the AI system's contribution, the types of data the AI processed, and the sources of that data; (2) an opportunity to correct any incorrect health information or personal data the AI system processed in making the decision; and (3) an opportunity to appeal the consequential decision, including human review of all information relating to the decision to the extent technically feasible. The appeal right does not apply when providing an opportunity for appeal is not in the patient's best interest, including when any delay might pose a risk to the patient's life or safety.
HI
Introduced
Deployers must implement a reasonable process by which consumers may (1) request correction of inaccurate personal information used in a consequential decision, (2) submit additional information for reconsideration, and (3) obtain human review of an adverse action by a reviewer with authority to overturn the decision and subject-matter-relevant training. Narrow exceptions apply when human review would conflict with law or compromise security, but the deployer must document the basis and offer an alternative dispute channel.
HI
Introduced
Deployers must, upon consumer request and to the extent reasonably necessary for dispute resolution, provide the consumer with access to relevant records including a copy or summary of the information used by the high-risk AI system and the output relied upon as a substantial factor. Trade secrets and proprietary source code need not be disclosed.
IL
Introduced
Health care entities must ensure registered professional nurses have access to the data inputs and key factors that produced any AI recommendation used in direct patient care.
IL
Introduced
Health care entities must ensure registered professional nurses have access to the data inputs and key factors that produced any AI recommendation used in direct patient care.
IN
Introduced eff 2026-07-01
Employers must, within seven days after making an employment-related decision using automated decision system output, provide the covered individual with full, accessible, and meaningful documentation in plain language and at no cost, including: (i) a description of the automated decision system used; (ii) a plain-language description and explanation of the input data and a machine-readable copy of that data; (iii) a description and explanation of how the output was used in making the decision; and (iv) the reasoning for using the output in the decision.
LA
Introduced
Covered insurers must, within 21 days of a consumer's request, provide a written, consumer-specific explanation of any adverse action involving an ADS, including the top contributing factors ranked by relative contribution, data sources used, the right to correct data, and the right to file a complaint. Trade-secret protection does not relieve this obligation.
LA
Introduced eff 2026-08-01
Health insurance issuers must allow covered persons, upon request, to review and obtain copies of all documents relevant to any AI or automated decision system used in the utilization review or determination process.
MA
Introduced
Employers must disclose to affected employees no less than 30 days before a monitoring-based employment decision goes into effect: (1) that the decision was based on electronically-monitored data, (2) the specific monitoring tools used and how they work, (3) the specific data and judgments used, and (4) any non-monitoring information used in the decision.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that the tool will be used, (2) the qualifications and data attributes assessed and outputs produced, (3) data sources and retention policy, (4) the most recent impact assessment results, (5) how to request an alternative non-automated selection process, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all employee-facing languages, provided directly to candidates, and accessible to individuals with disabilities.
MA
Introduced
Deployers must, when a consequential decision is adverse to the consumer, provide: (1) a statement disclosing the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the sources of that data; (2) an opportunity to correct any incorrect personal data the system processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless the appeal would not be in the consumer's best interest (e.g., where delay poses a risk to the consumer's life or safety).
MA
Introduced
When an employer makes a hiring, promotion, termination, disciplinary, or compensation decision based in whole or part on electronic monitoring data, the employer must disclose to affected employees no less than thirty days before the decision takes effect: (1) that the decision was based in whole or part on electronic monitoring data; (2) the specific monitoring tools used, how they gather and analyze data, and the time increments of data collection; (3) the specific data and judgments used in the decision-making process; and (4) any non-monitoring information used in the decision.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool to assess or evaluate them. The notice must include: (1) that an automated tool will be used; (2) the qualifications and characteristics the tool assesses, the data or attributes used, and the types of outputs produced; (3) what data is collected, its source, and the data retention policy; (4) results of the most recent impact assessment including any disparate impact findings and employer response; (5) how to request an alternative selection process or accommodation not involving the automated tool; and (6) how to request reevaluation of the tool's decision and the right to file a civil complaint. The notice must be written in plain language, included in job postings, posted on the employer's website in all employee-communication languages, provided directly to each candidate in their language, accessible to persons with disabilities, and otherwise presented to ensure clear and effective communication.
MN
Introduced
Employers must respond to a worker's access request within 14 calendar days and provide: (1) a plain-language explanation of the specific decision; (2) the specific worker data used by the ADS and all worker-specific outputs; (3) how the ADS output was used, including the rationale, the roles of ADS output and human involvement, corroborating information, the ADS logic and assumptions as applied to the worker, the key parameters and how they applied, and the range of possible outputs with aggregate statistics for comparison; (4) the name of the ADS creator and the product name; and (5) a copy of any completed impact assessments. Service providers, contractors, and vendors must provide full assistance to the employer in fulfilling access requests, including providing worker input/output data and relevant ADS information in their possession.
MN
Introduced
Employers must respond to worker access requests within 14 calendar days with a plain-language explanation of the decision, identification of the specific monitoring tool and its data-collection methodology, a machine-readable copy of the worker's monitored data, any additional decision inputs (including automated decision system inferences and aggregate benchmark data), and the names of monitoring vendors. Vendors must provide full assistance to employers in fulfilling access requests.
MN
Introduced eff 2027-01-01
Employers must, within 14 calendar days of a worker's access request, provide a plain-language explanation of the decision, identification of the monitoring tool and how it operates, a machine-readable copy of the worker's data, any additional information used in the decision (including automated inferences and benchmark data), and the names of monitoring vendors. Vendors must fully assist in responding.
MN
Introduced eff 2027-01-01
Employers must, within 14 calendar days of a worker's access request, provide the specific data used, all outputs produced, the rationale for the decision (including the roles of the system output and human involvement), the system logic as applied to the worker, key parameters, the range of possible outputs with aggregate statistics, the system creator's name, and any completed impact assessments. Vendors must provide full assistance to the employer in responding.
NJ
Introduced
Employers must notify each covered individual within 30 days of use that an automated employment decision tool was used, disclose the job qualifications or characteristics assessed, the data sources, the employer's data retention policy, the tool name and vendor, and — if the outcome was adverse — provide a written statement of specific reasons and sufficient disclosures to enable the individual to contest the employment decision.
NJ
Introduced
Employers and public entities must provide at least 10 days' advance written notice before any adverse AI-assisted employment or public-benefit decision takes effect, explaining the reasons, providing access to all data, and informing the individual of appeal rights. Upon request within 30 days, the employer must (1) allow the individual to review and copy all data and receive a complete explanation of how the AEDS or ABSDS produced its outputs including factor weighting, (2) allow the individual to appeal on grounds of data inaccuracy, bias, or legal violations, and (3) designate a qualified human reviewer with authority and discretion to modify or overturn the decision. For applicants, notice must be provided no later than the time of the decision.
NJ
Introduced
Employers and public entities must give at least 10 days' advance written notice of an adverse decision made using an EMT, AEDS, or ABSDS (or notice at decision time for application rejections), explaining the reasons, providing access to all relevant data and a full explanation of how the system was used, and stating access, contest, and relief rights.
NJ
Introduced
On request within 30 days, employers and public entities must let the individual review and copy the decision data, personnel files, impact-assessment and oversight records, and factor-weighting explanation; permit an appeal to correct inaccurate or biased data and contest the decision; and designate a qualified, empowered human reviewer with authority to modify or overturn it who issues the final internal determination.
NM
Introduced eff 2026-07-01
Deployers must, after an adverse consequential decision, provide the consumer with (1) a statement explaining the principal reasons for the decision and the specific data about the consumer that most influenced it, (2) the degree of AI contribution and level of human oversight, (3) the source and type of data processed, and (4) an opportunity to correct any incorrect personal data used.
NY
NY AB 3125 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must notify each housing applicant, at least 24 hours before the automated housing decision making tool is used, that (1) an automated tool will be used in connection with the assessment or evaluation of the applicant, (2) the characteristics the tool will use in the assessment, and (3) the type of data collected, the source of that data, and the landlord's data retention policy.
NY
Introduced
Banks must provide loan applicants denied based on incorrect personal information a 30-day period to correct the information and appeal the denial.
NY
Introduced
When a high-risk AI decision system has been used to make or substantially factor into an adverse consequential decision concerning a consumer, the deployer must provide the consumer: (1) a statement disclosing the principal reasons for the adverse decision, including the degree and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data the system processed; and (3) an opportunity to appeal the adverse decision, which must include human review if technically feasible, unless human review would not be in the consumer's best interest (e.g., where delay poses a risk to life or safety).
NY
Introduced
Employers must notify employees and candidates at least 10 business days before using an AEDT to assess or evaluate them, disclosing: that an AEDT will be used; the qualifications assessed, data inputs, and output types; what data is collected and its source and retention policy; the most recent impact assessment results including any disparate impact findings; how to request an alternative non-AEDT selection process or accommodation; and how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all languages regularly used with employees, provided directly to each candidate in their language, and available in accessible formats.
NY
Introduced
Employers must provide written notice at least 14 calendar days before any employment decision based on monitoring data or AEDT output takes effect, disclosing performance standards, the employee's monitored data, aggregated peer data for the prior 90 days, AEDT outputs, the most recent impact assessment, and all non-monitoring information used. Employees may request reevaluation in writing (including text or email) by identifying the disputed data or output and providing supporting evidence. Employers must investigate and respond within seven calendar days, providing evidence of accuracy or correcting the data and reevaluating the decision without the flawed input.
NY
Introduced
Deployers must, when a high-risk AI decision system makes or substantially factors into an adverse consequential decision concerning a consumer, provide the consumer with: (1) a statement disclosing the principal reasons for the adverse decision, including the degree to which and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless providing such opportunity would not be in the consumer's best interest (e.g., delay posing life or safety risk).
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must notify each applicant (1) that an automated housing decision making tool will be used, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's data retention policy, and (4) if the application is denied, the reason for denial.
NY
Introduced
Covered entities must provide loan applicants denied based on incorrect personal information a 30-day window to correct the information and appeal the denial.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must, within 30 days of making or effectuating a hiring, promotion, termination, disciplinary, or compensation decision based in whole or in part on data gathered through electronic monitoring, disclose to affected employees and their authorized representative: (1) that the decision was based in whole or in part on electronically monitored data, (2) the specific monitoring tools used, how they work to gather and analyze data, and the time increments in which data is gathered, (3) the specific data and judgments based on that data used in the decision-making process, and (4) any information used in the decision-making process gathered from sources other than electronic monitoring.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must, when a consequential decision is adverse to a consumer, (1) explain the principal reasons including the degree and manner of AI contribution, data types, and data sources, (2) allow the consumer to examine and correct personal data used, and (3) provide an opportunity to appeal based on inaccurate personal data with human review where technically feasible. All notices must be provided directly to the consumer, in plain language, in all languages the deployer ordinarily uses, and in formats accessible to consumers with disabilities.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must, when a high-risk AI system has made or been a substantial factor in making an adverse consequential decision concerning a consumer, provide the consumer with: (1) a statement disclosing the principal reasons for the decision, including the degree to which and manner in which the AI system contributed, the type of data processed, and the source(s) of that data; (2) an opportunity to correct any incorrect personal data that the AI system processed in making the decision; and (3) an opportunity to appeal the adverse decision, which appeal must, if technically feasible, allow for human review — unless providing the appeal opportunity is not in the consumer's best interest (e.g., where delay might pose a risk to the consumer's life or safety).
US
Introduced
Employers must, within 7 days of making an employment-related decision using ADS output, provide the covered individual with free, plain-language documentation describing the ADS used, the input data (including a machine-readable copy), how the output was used, and the reasoning for relying on it.
VT
Introduced eff 2025-07-01
Deployers must provide the consumer with a single post-decision notice containing a plain-language explanation of the consequential decision that identifies the principal reasons for the decision, including: (1) the identity of the developer if different from the deployer; (2) a description of the system's output (score, recommendation, etc.); (3) the degree and manner to which the automated decision system contributed to the decision; (4) the types and sources of data processed; (5) a plain-language explanation of how the consumer's personal data informed the decision; and (6) what actions the consumer might have taken or might take in the future to secure a different decision.
WA
Introduced eff 2027-01-01
Deployers must transmit consequential decisions to consumers without undue delay. When a consequential decision is adverse to the consumer and based on personal information beyond what the consumer directly provided, the deployer must provide a statement disclosing the principal reasons for the decision, including: (1) the degree to which and manner in which the high-risk AI system contributed to the decision; (2) the type of data processed by the system in making the decision; and (3) the sources of such data.
CO
Failed eff 2025-05-05
Deployers must, within 30 days after an adverse consequential decision, provide a single notice disclosing the main reasons for the decision (including the AI system's contribution and the categories and sources of data that adversely affected the output, including sensitive data), information on how to exercise correction and appeal rights, and a copy of the notice. Deployers must offer an opportunity to correct incorrect personal data. For non-competitive, non-time-limited adverse decisions based on incorrect data or unlawful information, deployers must provide an opportunity to appeal with human review if technically feasible. The correction and appeal rights apply only to systems that are the principal basis of the decision.
CT
Failed
Deployers must, before making a consequential decision using a high-risk AI system, notify the consumer that AI is being used, disclose the system's purpose and the nature of the decision, offer opt-out rights, and provide contact information and a plain-language system description. If the decision is adverse, the deployer must disclose the principal reasons (including AI's contribution and the data types and sources used), provide an opportunity to examine and correct personal data, and offer an appeal with human review where technically feasible. All notices must be in plain language, multilingual, accessible, and delivered directly to the consumer.
HI
Failed
Covered entities must, upon taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure that includes (1) the entity's contact information, (2) the factors the determination depended on, and (3) an explanation that the individual may access any personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
HI
Failed
Covered entities must, upon taking any adverse action based on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's right to access their personal information used in the determination, submit corrections, and request a human-conducted reevaluation based on corrected data.
HI
Failed
Covered entities must, when taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's rights to access personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must provide consumers subject to a high-risk AI system the opportunity to (1) correct any data used by the system in making a decision about the consumer, and (2) appeal an adverse decision, including human review. A deployer may decline to provide appeal where the delay would pose a risk to the consumer's safety.
NE
Failed
Deployers must, for each high-risk AI system that makes or is a substantial factor in making an adverse consequential decision concerning a consumer, provide to that consumer: (1) a statement disclosing each principal reason for the decision, including the degree and manner in which the AI system contributed to the decision, the type of data processed, and each source of that data; (2) an opportunity to correct any incorrect personal data that the system processed in making or contributing to the decision; and (3) an opportunity to appeal the adverse decision, unless an appeal is not in the consumer's best interest (e.g., where delay would risk life or safety), with human review if technically feasible. All notices, statements, and descriptions must be provided directly to the consumer, in plain language, in each language the deployer ordinarily uses in business communications, and in a format accessible to consumers with disabilities. If direct provision is not possible, the deployer must make the information available in a manner reasonably calculated to ensure the consumer receives it.
NM
Failed
Deployers must, after an adverse consequential decision, provide the consumer with (1) an explanation of the principal reasons, the degree and manner of AI contribution, and the source and type of data processed, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review if technically feasible.
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must notify each housing applicant, at least 24 hours before using the automated decision tool, that (1) an automated tool will be used to assess the applicant, (2) the characteristics the tool will use in the assessment, and (3) the type of data collected, its source, and the landlord's data retention policy.
NY
Failed
Employers must notify employees and candidates at least 10 business days before using an automated employment decision tool, disclosing: (1) that an AEDT will be used, (2) the qualifications and characteristics assessed, data attributes used, and outputs produced, (3) data collected, its source, and the data retention policy, (4) the most recent bias audit results, (5) how to request an alternative selection process or accommodation, and (6) how to request internal review and the right to file a civil action.
NY
Failed
Employers must disclose to affected employees at least 14 days before an employment decision takes effect that the decision was based in whole or part on electronic monitoring data, identify the specific monitoring tools used, disclose the specific data and judgments used in the decision, and identify any non-monitoring information used.
NY
Failed
Employers must notify employees and candidates at least ten business days before using an AEDT to assess or evaluate them, disclosing: (1) that an AEDT will be used, (2) the qualifications and characteristics assessed, data attributes used, and outputs produced, (3) what data is collected and from what source, along with the data retention policy, (4) results of the most recent impact assessment including any disparate impact findings, (5) how to request an alternative non-AEDT selection process or accommodation, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website, provided to each candidate in their language, and accessible to employees with disabilities.
NY
Failed
Employers must provide affected employees written notice at least 14 calendar days before any employment decision based on monitoring data or AEDT outputs takes effect, disclosing: (1) performance standards used, (2) the employee's monitoring data used, (3) aggregated data for similarly situated employees for the prior 90 days, (4) any AEDT outputs used, (5) the most recent impact assessment of any AEDT used, and (6) any other information used in the decision.
NY
Failed
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that an AEDT will be used; (2) the qualifications assessed, data inputs and attributes used, and output types; (3) data collected, its source, and the retention policy; (4) the most recent bias audit results and employer response; (5) how to request an alternative selection process or accommodation; and (6) how to request internal reevaluation and the right to file a civil action.
NY
Failed
Employers must respond in writing within sixty days to a reevaluation request, disclosing: the AEDT outputs used in the decision, non-AEDT information that contributed, whether the employer agrees with the complaint and why, evidence supporting the tool's accuracy if the employer disagrees, reprocessing results if requested, and the reason for refusing any requested remedial action.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must notify each housing applicant (1) that an automated decision tool will be used to assess the applicant, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's data retention policy, and (4) if the application is denied, the reason for the denial.
US
Failed
The prosecution must provide criminal defendants with all results and reports from computational forensic software analysis, along with the software's executable copy, source code (current and prior versions), instructions, and all relevant files and data. Reports must include the developer name, lab name, software version, change history (including bugs), documentation of procedures followed per internal validation, documentation of conditions of use versus conditions of testing, and any additional NIST-specified information.
US
Failed
Employers must provide covered individuals, within 7 days of making an employment-related decision, with free, accessible, plain-language documentation describing the automated decision system, the input data (including a machine-readable copy), how the output was used in the decision, and the reasoning for using it.
US
Failed
Employers must, within 7 days of making an employment-related decision using an automated decision system output, provide the covered individual with free, accessible, plain-language documentation covering (1) a description of the ADS, (2) the input data used and a machine-readable copy, (3) how the output was used in the decision, and (4) the reasoning for the use of the output.
H-01.3
Pre-decision notice
The individual must be notified before a consequential automated decision is made — informing them that an automated system will be used and what categories of decisions it can make.
Enacted
5
Live
100
Failed
65
Total
170
CA
CA SB 892 (ADS Procurement Standards) § Pub. Contract Code § 12100.1(d)
Enacted eff 2025-01-01
State agencies or ADS vendors must provide notice to individuals likely to be affected by ADS decisions or outcomes, including information about how to appeal or opt out of those decisions.
CO
Enacted eff 2026-05-14
Deployers must provide consumers with clear and conspicuous notice, prior to using a covered ADMT to materially influence a consequential decision, that the deployer uses or will use a covered ADMT in a consequential decision affecting the consumer, along with instructions on how to obtain additional information. A deployer satisfies this requirement by maintaining a prominent public notice reasonably accessible at points of consumer interaction, including through a link or posting reasonably proximate to the interaction or transaction.
CO
Enacted eff 2026-02-01
Deployers must, before making a consequential decision, (1) notify the consumer that a high-risk AI system will be used, (2) disclose the system's purpose, the nature of the decision, deployer contact information, a plain-language system description, and instructions for accessing the deployer's public transparency statement, and (3) inform the consumer of applicable opt-out rights under Colorado's privacy law. Notices must be delivered directly, in plain language, in all languages the deployer uses in ordinary business, and in a format accessible to consumers with disabilities.
CO
Enacted eff 2026-02-01
Deployers must, before making a consequential decision about a consumer using a high-risk AI system, provide the consumer with: (1) notice that a high-risk AI system has been deployed to make or substantially factor in the decision; (2) a statement disclosing the system's purpose, the nature of the consequential decision, deployer contact information, a plain-language description of the system, and instructions for accessing the deployer's public transparency statement; and (3) information about the consumer's right to opt out of profiling for decisions with legal or similarly significant effects under C.R.S. § 6-1-1306(1)(a)(I)(C) if applicable. All notices and statements must be provided directly to the consumer, in plain language, in all languages the deployer uses in ordinary business communications, and in a format accessible to consumers with disabilities. If direct delivery is not possible, the deployer must make the information available in a manner reasonably calculated to reach the consumer.
CT
Enacted eff 2026-07-01
Deployers must, before making an employment-related decision using automated employment-related decision technology as a substantial factor, provide the affected employee or applicant a written notice disclosing: (1) deployment of the technology, (2) its purpose and nature of the decision, (3) the technology's trade name, (4) categories of personal data analyzed and how they are assessed, (5) data sources, and (6) deployer contact information.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must, before finalizing a consequential decision made or facilitated by a covered ADS, provide the subject with a plain-language written disclosure identifying that an ADS will be used, the system's name, version, and developer, whether the use is within a developer-approved scope, the personal characteristics assessed, data sources, key disproportionately-affecting parameters, output structure and how outputs inform the decision, whether a human will review the outputs or decision, the subject's opt-out and appeal rights, and contact information for the deployer and any managing or interpreting entity. A medical emergency exception applies.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed eff 2026-01-01
Deployers must notify any natural person when a high-risk automated decision system is used to make a decision about them and disclose: (1) the purpose of the system and the specific decision it was used to make; (2) how the system was used to make the decision; (3) the type of data used; (4) contact information for the deployer; and (5) a link to the deployer's public website statement about its high-risk automated decision systems.
CA
CA SB 947 (Workplace ADS) § Lab. Code § 1524
Engrossed
Employers must provide workers with a written postuse notice at the time the worker is informed of any ADS-assisted disciplinary, termination, or deactivation decision. The notice must be a separate, stand-alone, plain-language communication in the worker's routine language, delivered via email, hyperlink, or other simple method. The notice must state: (1) that the employer used an ADS to assist in the decision; (2) that a human reviewer conducted an independent investigation and compiled corroborating evidence; (3) contact information for a human the worker may reach for more information about the decision and the worker's data-access rights; and (4) that the employer is prohibited from retaliating against the worker for exercising rights under the bill.
NY
NY SB 1169 (AI Algorithmic Discrimination) § Civ. Rights Law § 86-a
Engrossed
Deployers must inform end users at least five business days before using a high-risk AI system to make a consequential decision, in clear, conspicuous, and consumer-friendly terms available in each language in which the company offers its services. Deployers must allow sufficient time and opportunity for the end user to opt out of the automated decision process and have the decision made by a human representative instead. End users may not be punished for opting out, and the deployer must render a decision within 45 days. When the decision confers a benefit on the end user, the deployer must offer the option to waive the five-day advance notice. An urgent-necessity exception applies when compliance would cause imminent detriment to the end user's welfare, but the right to request human review may never be waived. End users are entitled to no more than one opt-out per consequential decision in a six-month period.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must notify consumers no later than the time a high-risk AI system is used to make a consequential decision, disclosing the system's purpose, nature, the nature of the consequential decision, deployer contact information, and a plain-language description of the system.
CA
CA AB 1898 (Workplace AI Tools) § Lab. Code § 1601
Introduced
Employers must provide written notice to affected workers and their exclusive bargaining representatives before using any workplace AI tool for employment-related decisions or workplace surveillance, including (1) at least 90 days before first deploying a new tool, (2) by February 1, 2027 for tools already in use, and (3) upon hire for new workers. The notice must be a standalone, plain-language communication containing the tool's purpose and justification, affected employment decisions, worker data collected and its storage, a description of the tool's inputs, analysis, and outputs, data access and transfer practices, surveillance scope, tool vendor and model name, quotas and adverse-action consequences, job displacement impacts, manager/worker training, and results of any CCPA risk assessments.
CA
CA AB 1898 (Workplace AI Tools) § Lab. Code § 1601
Introduced
Employers must require workers to sign confirming they received and understand the workplace AI tool notice, and must not use the tool until affected workers have returned their signed notices.
CT
CT SB 1484 (AI Employee Protections) § Conn. Gen. Stat. § 31-48d
Introduced eff 2025-10-01
Employers must give prior written notice in plain language and in the employee's primary language to all affected employees before engaging in electronic monitoring, disclosing the types of monitoring, the intended use of collected information, data storage practices and retention periods, and a statement of employees' rights. Employers must also post a conspicuous workplace notice of monitoring types. An exception applies when the employer has reasonable grounds to believe employees are engaged in misconduct.
CT
Introduced eff 2025-10-01
Employers must, before deploying a high-risk AI system to make or substantially factor into a consequential employee decision, (1) notify the employee that a high-risk AI system will be used, (2) disclose the system's purpose and the nature of the decision, (3) identify what employee data will be collected, (4) share the most recent impact assessment results, (5) inform the employee of the right to opt out and request an alternative decision-making process, (6) explain how to request reevaluation of any consequential decision, and (7) provide a plain-language description of the system. All disclosures must be delivered directly to the employee, in plain language, in the employer's business languages, and in accessible formats.
CT
Introduced eff 2026-10-01
Deployers must, before an automated employment-related decision process makes or substantially factors into an employment-related decision, provide written notice to the affected applicant or employee disclosing: (1) that the deployer has deployed the process, (2) the process's purpose and the nature of the decision, (3) opt-out rights under § 42-518, (4) deployer contact information, (5) availability of human review, (6) how to request reevaluation of the decision, (7) a link to the most recent bias audit summary, and (8) how to request additional documentation about the process.
CT
Introduced eff 2026-10-01
Employers must provide advance written notice to any individual disclosing that an automated employment-related decision process will be used to make, assist in, or be used in the course of making employment decisions affecting that individual. The notice must at minimum disclose the trade name of the process and the types and sources of personal information the process will process or analyze.
GA
Introduced
Persons using AI or automated decision tools in determinations about the sale, rental, or financing of dwellings, or in brokerage services, must disclose to affected individuals that such tools were used.
GA
Introduced
Deployers must notify the consumer, no later than the time the automated decision system is deployed to make or assist in making a consequential decision, that an automated decision system is being used. Deployers must also provide the consumer with: (1) a statement disclosing the system's purpose and the nature of the consequential decision; (2) contact information for the deployer; (3) a plain-language description of the system, including the personal characteristics or attributes measured, the method of measurement, relevance to the decision, any human components, how automated components inform the decision, and a direct link to a public website page containing a plain-language logic description, key parameters, outputs, data types and sources, and the most recent impact assessment results; and (4) instructions on how to access the deployer's public website statement required by § 10-16-5.
GA
Introduced
Deployers must provide all notices and explanations required by this section directly to the consumer, in plain language, in all languages in which the deployer ordinarily communicates with consumers, and in a format accessible to consumers with disabilities. If direct delivery is not possible, the deployer must make the information available in a manner reasonably calculated to ensure the consumer receives it. Deployers must not use an automated decision system to make or assist in making a consequential decision if they cannot satisfy these notice requirements.
HI
Introduced
Deployers must, before using an algorithmic decision system to make, inform, or influence a decision with a material legal or similarly significant effect in a covered domain, provide the affected individual with a plain-language notice identifying the developer, system trade name and version, the nature and stage of the decision, and deployer contact information.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Consequential decisions; notice; statement; opt-out; corrections; appeal)
Introduced eff 2028-07-01
Health care providers must, before using an AI system to make or substantially factor into a consequential decision, provide the patient or authorized representative with a written notice that: (1) informs them that AI will be used to make or substantially factor into the consequential decision; (2) discloses the purpose of the AI system and the nature of the consequential decision; (3) describes the AI system in plain language; and (4) allows the patient to opt out of processing of individually identifiable health information or other personal data for purposes of profiling in furtherance of decisions that have legal or similarly significant effects. The notice must be provided directly to the patient or authorized representative, or if that is not possible, in a manner reasonably calculated to ensure receipt.
HI
Introduced
Deployers must provide consumers, in plain language and at or before the time of an adverse action, (1) notice that a high-risk AI system was used in the consequential decision, (2) a description of the type of information used and the primary factors contributing to the decision, and (3) information on how to request correction, submit additional information, seek reconsideration, and obtain human review. Trade secrets need not be disclosed, but a meaningful explanation must be provided.
IA
Introduced
Employers must provide written advance notice to each employee (or authorized representative) who will foreseeably be directly affected by an automated decision system used for employment-related decisions other than hiring. The notice must be provided: (1) at least 30 days before an automated decision system is first deployed; (2) no later than January 1, 2027, for systems already in use at the effective date; and (3) within 30 days of hiring a new employee. The notice must contain: (a) the type of employment-related decisions affected; (b) a general description of the categories of employee-input data, data sources, and collection methods; (c) any key parameters known to disproportionately affect the system's output; (d) the vendor or entity that created the system; (e) if applicable, a description of each quota including quantified tasks, potential adverse actions for failure to meet the quota, and whether the quota is subject to change; (f) the employee's right to access and correct data; and (g) a statement that retaliation is prohibited. The notice must be in plain language, stand-alone, in the employee's routine language, and delivered via a simple method such as email, electronic link, or other written format.
IA
Introduced
Employers must notify applicants upon receiving their application that the employer utilizes an automated decision system when making hiring decisions. The notification may be provided using an automatic reply mechanism or on a job posting.
ID
ID HB 945 (AI Medical Services Act) § Idaho Code § 54-6005
Introduced eff 2026-07-01
Fully autonomous (L3) AAASPs must, before delivering services, obtain affirmative patient acknowledgment of the prescribed disclosure that the provider is an AI system without routine human clinical oversight and that the patient may seek alternative human care at any time.
IL
Introduced
Employers must, when using an automated decision-making system for any function covered by Section 10(a): (1) provide notice to each affected employee no later than the time a decision is issued that the decision was made using an automated decision-making system; (2) provide an appeals process for employees directly impacted by decisions made by the system; and (3) offer each affected employee the opportunity for an independent alternative review of the decision by an individual working for or on behalf of the employer, separate from the automated system.
IN
Introduced eff 2026-07-01
Employers must provide the disclosures required by Section 11 of this chapter before using automated decision system output in any employment-related decision. This is a prerequisite to lawful use of the output.
IN
Introduced eff 2026-07-01
Employers that use or intend to use automated decision system output in employment-related decisions must disclose to each covered individual: (1) the fact of use or intended use; (2) a description of the system, including input data types and collection circumstances, characteristics measured, job-relevance of those characteristics, measurement methodology, and plain-language interpretation guidance; (3) the identity of the entity operating the system; (4) how the output is or will be used in the decision; and (5) how the individual may dispute or appeal the decision. Existing employees hired on or before July 1, 2026 must receive disclosures by August 1, 2026. Candidates and future hires must receive disclosures before hiring. Employers must provide updated disclosures within 30 days of any significant change or new information.
LA
Introduced
Employers must provide written notice to each worker (or authorized representative) who will foreseeably be directly affected by an ADS used for employment-related decisions (excluding hiring). Notice must be provided at least 30 days before first ADS deployment, at the time the Part takes effect if the ADS is already in use, or within 30 days of a new worker's hiring date. The notice must be a separate, standalone, plain-language communication in the worker's routine language, delivered via an accessible method. The notice must include: (1) the types of employment-related decisions affected, (2) categories, sources, and collection methods for worker input data, (3) any key parameters known to disproportionately affect ADS output, (4) the individuals, vendors, or entities that created the ADS, (5) if applicable, each quota set or measured by the ADS with quantified metrics, potential adverse actions for failure to meet quotas, and whether quotas are subject to change, (6) the worker's right to access and correct data used by the ADS, (7) that retaliation is prohibited, and (8) the worker's right to appeal any ADS-assisted decision and the appeal process.
LA
Introduced
Employers who use an ADS to make hiring decisions must notify each job applicant upon receiving the applicant's application that the employer utilizes an ADS for hiring decisions. Notification may be made using an automatic reply mechanism or on the job posting.
LA
Introduced
Covered insurers must disclose to consumers at the time of application, renewal, or any adverse action whether an ADS was used in the insurance decision, using prescribed or substantially similar clear and conspicuous language that includes notice of the right to request an explanation.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Introduced
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime who were identified using a facial recognition search that they were subject to such a search and (2) make readily available to defendants and their attorneys all records pertaining to facial recognition searches performed during the investigation, including match results, algorithm details, accuracy rates, audit testing, operator identities, training records, and the selection methodology.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Introduced
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime that a facial recognition search was used in their identification, and (2) make readily available to defendants and their attorneys all records pertaining to facial recognition searches conducted during the investigation — including search results, alternative matches, the algorithm used, system accuracy rates, audit testing records, officer identity and training, and the match-selection process.
MA
Introduced
Employers must disclose to affected employees no less than 30 days before a monitoring-based employment decision goes into effect: (1) that the decision was based on electronically-monitored data, (2) the specific monitoring tools used and how they work, (3) the specific data and judgments used, and (4) any non-monitoring information used in the decision.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that the tool will be used, (2) the qualifications and data attributes assessed and outputs produced, (3) data sources and retention policy, (4) the most recent impact assessment results, (5) how to request an alternative non-automated selection process, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all employee-facing languages, provided directly to candidates, and accessible to individuals with disabilities.
MA
Introduced
Deployers must (1) notify consumers when an AI system materially influences a consequential decision, (2) provide consumers with the purpose of the system and an explanation of how the system influenced the decision, and (3) provide a process to appeal or correct adverse decisions.
MA
Introduced
Deployers must, before a consequential decision is made, notify the consumer that a high-risk AI system has been deployed to make or be a substantial factor in making the decision. Deployers must also provide a statement disclosing: (1) the purpose of the system and the nature of the consequential decision; (2) the deployer's contact information; (3) a plain-language description of the system; and (4) instructions on how to access the deployer's public website summary. If applicable, deployers must inform the consumer of the right to opt out of personal data processing for profiling in furtherance of decisions with legal or similarly significant effects. Notices must be provided directly to the consumer, in plain language, in all languages in which the deployer ordinarily communicates with consumers, and in a format accessible to consumers with disabilities. If direct delivery is not possible, the deployer must make the information available in a manner reasonably calculated to reach the consumer.
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Introduced
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime that they were identified using a facial recognition search and (2) make readily available to defendants and their attorneys all records pertaining to facial recognition searches conducted during the investigation, including search results, alternative matches, the algorithm and accuracy rate, audit testing, searcher identity, training records, and the match-selection process.
MA
Introduced
When an employer makes a hiring, promotion, termination, disciplinary, or compensation decision based in whole or part on electronic monitoring data, the employer must disclose to affected employees no less than thirty days before the decision takes effect: (1) that the decision was based in whole or part on electronic monitoring data; (2) the specific monitoring tools used, how they gather and analyze data, and the time increments of data collection; (3) the specific data and judgments used in the decision-making process; and (4) any non-monitoring information used in the decision.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool to assess or evaluate them. The notice must include: (1) that an automated tool will be used; (2) the qualifications and characteristics the tool assesses, the data or attributes used, and the types of outputs produced; (3) what data is collected, its source, and the data retention policy; (4) results of the most recent impact assessment including any disparate impact findings and employer response; (5) how to request an alternative selection process or accommodation not involving the automated tool; and (6) how to request reevaluation of the tool's decision and the right to file a civil complaint. The notice must be written in plain language, included in job postings, posted on the employer's website in all employee-communication languages, provided directly to each candidate in their language, accessible to persons with disabilities, and otherwise presented to ensure clear and effective communication.
MI
Introduced
Employers using a monitoring or automated decisions tool must display a conspicuous workplace poster giving notice of that use.
MN
Introduced
Employers must provide a written pre-use notice to every worker (or their authorized representative) and any representing union before deploying an automated decision system for employment-related decisions. The notice must be provided: (1) at least 30 days before introducing a new ADS; (2) no later than September 1, 2026 for existing ADS; (3) prominently to job applicants or new workers before collecting personal information for ADS processing; (4) at least 30 days before any significant change; and (5) to unions on a timeline allowing meaningful bargaining. The notice must be a standalone plain-language communication in the worker's routine language and must include: the nature, purpose, and scope of the ADS; the specific data categories and sources; the system logic and key parameters; the identity of the ADS creator and operators; the job qualifications assessed and evaluation outputs; results of any impact assessments; a list of all ADS the employer currently uses; and a description of worker rights. A copy of every notice must be submitted to the commissioner of labor and industry within ten days.
MN
Introduced
Employers must provide a post-decision written notice to every worker affected by an ADS-informed employment decision. The notice must be provided: (1) at the time the worker is informed of the decision, or no later than 15 business days after the decision, whichever is earlier; or (2) for discipline or termination, at least 30 days before it takes effect. The notice must acknowledge that an ADS was used, describe worker rights, include a form or link to appeal or request detailed information, and state that retaliation is prohibited. For repeated same-use ADS within a quarter, a full notice is required for the first use each quarter and a summary notice at quarter-end covering the number and dates of uses and worker rights.
MN
Introduced
Employers must provide detailed written pre-use notice to workers, authorized representatives, and unions at least 30 days before introducing or significantly changing any electronic monitoring tool, and must submit a copy to the Commissioner of Labor and Industry within ten days. The notice must include a description of data collected, the monitoring purpose and necessity justification, storage practices, vendor names, whether data feeds into automated decision systems, and a description of worker rights.
MN
Introduced
Employers must provide affected workers with written post-decision notice when monitoring data was used in an employment-related decision — at the time of the decision or within 15 business days, or at least 30 days before discipline or termination takes effect. The notice must acknowledge monitoring-data use, describe worker rights, provide an appeal form link, and state the anti-retaliation prohibition.
MN
MN HF 4537 (AI Employment Discrimination) § Minn. Stat. § 363A.08, subd. 9
Introduced
Employers must provide notice to employees and applicants for employment that the employer is using artificial intelligence in recruitment, hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure, or the terms, privileges, or conditions of employment.
MN
Introduced eff 2027-01-01
Employers must provide workers, their authorized representatives, and any applicable union with a detailed written pre-use notice at least 30 days before deploying or significantly changing an electronic monitoring tool, containing twelve enumerated categories of information including the data collected, the purpose and necessity justification, whether data feeds automated decisions, and worker rights. A copy must be filed with the Commissioner of Labor and Industry within ten days.
MN
Introduced eff 2027-01-01
Employers must provide workers with written post-decision notice when monitoring data was used in an employment-related decision — within 15 business days of the decision, or at least 30 days before discipline or termination takes effect. The notice must acknowledge use of monitoring data, describe worker rights, include an appeal form, and state the anti-retaliation prohibition.
MN
Introduced eff 2027-01-01
Employers must provide affected workers, their authorized representatives, and any representing union with a written, plain-language pre-use notice at least 30 days before introducing or significantly modifying an automated decision system, disclosing the system's purpose, data categories, logic, key parameters, creator and operator identity, job qualifications assessed, impact assessment results, a current list of all automated decision systems in use, and a description of worker rights.
MN
Introduced eff 2027-01-01
Employers must provide each affected worker with a written post-decision notice — at the time of the decision or within 15 business days (30 days before discipline takes effect) — acknowledging use of an automated decision system, describing worker rights, providing an appeal form, and stating the anti-retaliation protection. For repeat use of the same system, a full notice for the first quarterly use plus a quarterly summary is required.
MO
Introduced
Employers must provide each employee at hiring (and all current employees by October 1, 2026) a written description of every work performance standard to which the employee is subject, including any potential adverse employment action for failure to meet the standard.
MO
Introduced
Employers must (1) notify employees of any change to a work performance standard as soon as possible and before the new standard takes effect, (2) provide a written description of the new standard within two business days, and (3) deliver all written descriptions in person through a human manager during work hours.
MO
Introduced
Employers must notify an employee of termination for failure to meet a work performance standard at least fourteen days before the termination becomes effective. At least thirty days must elapse between a first warning and termination, and the employer may not rely on warnings issued more than one year prior.
NJ
Introduced
Employers must notify each covered individual at least 10 business days before use that an automated employment decision tool subject to a bias audit will be used in connection with the individual's application or employment assessment. For candidates, notice must be provided on the employment section of the employer's website, in a job posting, or via mail or email. For current employees, notice must be provided in a written policy, a job posting, or via mail or email.
NJ
Introduced
Employers must, before requesting a video interview analyzed by AI, (1) notify the applicant that AI may be used to analyze the video and assess fitness, (2) explain how the AI works and what characteristics it evaluates, and (3) obtain written consent (which may be electronic) before proceeding with AI evaluation.
NJ
Introduced
Employers and public entities must provide employees and their recognized bargaining representative with written notice as required by section 6, and must respond to concerns raised by the employee representative regarding AEDS, ABSDS, or EMT compliance, before implementing any such system.
NJ
Introduced
Employers and public entities must provide written notice to all affected employees, service beneficiaries, and recognized bargaining representatives at least 60 days before implementing any AEDS, ABSDS, or EMT. Notice must include: the type of system and decisions affected; impact assessment summaries with registry directions; descriptions of data collected and outputs used; employee and beneficiary rights; productivity quotas or performance standards (employees only); and the employer's obligation to respond to union concerns. Notice must also be given at least 60 days before any significant changes. New hires must receive notice within 30 days with written acknowledgment.
NJ
Introduced
Employers and public entities must not take any adverse employment action based in whole or in part on a productivity quota or performance standard that was not previously disclosed to the affected employee.
NJ
Introduced
All notices to employees and service beneficiaries and impact assessment summaries must be written in clear plain language, translated into any language spoken by at least 5% of the workforce, provided in hard copy and electronic form, posted conspicuously in the workplace, and include a statement that retaliation is prohibited.
NJ
Introduced
Employers and employment agencies must notify candidates for employment and employees being considered for promotion at least 10 business days before using an AEDT, including instructions for requesting an alternative selection process or reasonable accommodation. Notice may be provided via the employment website, job posting, written policy, or direct communication.
NJ
Introduced
Employers must, before requesting an AI-analyzed video interview, (1) notify the applicant that AI may be used to analyze the video and assess fitness, (2) explain how the AI works and what characteristics it evaluates, and (3) obtain written consent to be evaluated by AI. Employers may not use AI to evaluate an applicant who has not consented.
NJ
Introduced
Employers and public entities must give affected workers, service beneficiaries, and any bargaining representative at least 60 days' written notice before implementing or materially changing an EMT, AEDS, or ABSDS, disclosing the system, affected decisions, impact-assessment summary and registry access, collected data and outputs, contest rights, and any performance standards or quotas.
NJ
Introduced
Employers and public entities must provide all required notices and impact-assessment summaries in clear plain language, translated for any language spoken by at least five percent of the workforce, in hard copy and electronic form, posted conspicuously, and disclosing the anti-retaliation protection.
NJ
Introduced
Employers and public entities must give at least 10 days' advance written notice of an adverse decision made using an EMT, AEDS, or ABSDS (or notice at decision time for application rejections), explaining the reasons, providing access to all relevant data and a full explanation of how the system was used, and stating access, contest, and relief rights.
NJ
Introduced
Covered entities must provide clear notice to an individual when an automated decision system is used in a housing or credit decision affecting that individual.
NM
Introduced eff 2026-07-01
Deployers must notify consumers before an AI system is used to make or contribute to a consequential decision, including the developer name, trade name, version number or other identifying information about the AI system, and the deployer's contact information.
NY
Introduced
Food delivery platforms must provide delivery workers with clear, written, plain-language notice of (1) the factors the algorithmic management system considers in assigning deliveries and evaluating performance, (2) any metrics that may affect work access or compensation, and (3) the circumstances under which a worker may be suspended, deactivated, or penalized.
NY
Introduced
Employers must provide each worker (or authorized representative) foreseeably affected by an ADS with a written, plain-language, standalone pre-use notice at least 30 days before first deploying the ADS (or by January 1, 2027 for systems already in use), and within 30 days of hiring a new worker. The notice must describe: (1) the types of employment-related decisions affected, (2) categories and sources of worker input data, (3) parameters disproportionately affecting output, (4) ADS vendor contact information, (5) applicable quotas and adverse consequences, (6) data access and correction rights, and (7) the employer's anti-retaliation obligation.
NY
Introduced
Employers must notify job applicants upon receiving an application that the employer uses an ADS in making hiring decisions for the position being applied to. Notification may be made via automatic reply or job posting.
NY
Introduced
Employers and employment agencies that use an automated employment decision tool to screen job applicants must notify each candidate of: (1) that an automated employment decision tool will be used in connection with the assessment or evaluation of the candidate; (2) the job qualifications and characteristics the tool will use in assessing the candidate; and (3) the type of data collected for the tool, the source of that data, and the employer's or employment agency's data retention policy.
NY
Introduced
Employers and employment agencies must provide the required notice at least ten business days before using the automated employment decision tool, and must allow the candidate to request an alternative selection process or accommodation.
NY
NY AB 3125 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must notify each housing applicant, at least 24 hours before the automated housing decision making tool is used, that (1) an automated tool will be used in connection with the assessment or evaluation of the applicant, (2) the characteristics the tool will use in the assessment, and (3) the type of data collected, the source of that data, and the landlord's data retention policy.
NY
Introduced
Employers must notify employees and candidates, before or at the time of an employment decision, that an AEDT is being used, what qualifications and data it assesses, what outputs it produces, the data sources and retention policy, and (for 100+ employee employers) the most recent impact assessment results. Notice must be in clear and plain language, included in every relevant job posting, and posted on the employer's website in English and the ten most commonly spoken non-English languages in the state.
NY
Introduced
Landlords must notify each housing applicant at least 24 hours before using an automated decision tool that (1) the tool will be used, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's retention policy, and (4) the reason for any denial. The notice must allow the applicant to request an alternative selection process or accommodation.
NY
Introduced
Banks must notify each loan applicant at least 24 hours before using an automated decision tool that (1) the tool will be used, (2) the characteristics it will evaluate, (3) the type and source of data collected and the bank's retention policy, and (4) the reason for any denial. The notice must allow the applicant to opt out of or consent to the use and retention of their personal information.
NY
Introduced
Before deploying a high-risk AI decision system to make or substantially factor into a consequential decision concerning a consumer, the deployer must: (1) notify the consumer that the system is being used; (2) provide a statement disclosing the system's purpose and the nature of the consequential decision; (3) provide deployer contact information; (4) provide a plain-language description of the system; and (5) provide instructions for accessing the deployer's public website statement on deployed systems. All notices must be provided directly to the consumer, in plain language, in all languages the deployer ordinarily uses for consumer communications, and in a format accessible to consumers with disabilities.
NY
Introduced
Covered entities must notify each loan applicant at least 24 hours before using an automated lending decision-making tool that (1) an automated tool will be used in their assessment, (2) the criteria the tool will apply, (3) the types and sources of data collected and the entity's data retention policy, and (4) within 24 hours after any denial, to the extent practicable, the reason for the denial.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 108
Introduced
Covered deployers must inform the covered subject (and any covered agent) at the immediate onset of an engagement, in clear consumer-friendly terms and in every service language, that a high-risk AI system will be used to make or assist in a consequential decision; this notice is waived only where urgent benefit decisions would otherwise harm the subject.
NY
Introduced
Employers must notify applicants that an automated system will be used in the hiring process, describe in plain language the type of data the system analyzes, and describe the role of the human reviewer in the final employment decision.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 110
Introduced
Deployers must provide a short-form notice (≤500 words) regarding each covered algorithm they develop, offer, license, or use. The notice must be concise, clear, conspicuous, plain-language, not misleading, accessible to individuals with disabilities, contextually appropriate, free, and must include an overview of each applicable individual right and disclosure — drawing attention to practices that may be unexpected or that involve a consequential action. For individuals with whom the deployer has a relationship, the deployer must deliver an electronic version of the short-form notice directly upon the individual's first interaction with the covered algorithm. For individuals without a relationship, the deployer must post the notice on its website.
NY
Introduced
Employers must notify employees and candidates before or at the time of an employment decision that an AEDT will be used, including what qualifications and data the tool assesses, what data is collected and its source, the employer's data retention policy, and (for employers with 100+ employees) the most recent impact assessment results. Notices must be in plain language, included in job postings, and posted on the employer's website in English and the ten most commonly spoken non-English languages in the state.
NY
Introduced
Employers must provide prior written notice to all employees and candidates subject to electronic monitoring, covering monitoring purpose, data collected, dates/times/frequency, AEDT integration, productivity standards use, storage/retention, and least-invasiveness justification. Notice must be multilingual, accessibility-compliant, in clear and plain language, provided at hiring and annually, posted conspicuously, and must constitute actual (not conditional) notice. For random or periodic monitoring, employers must inform affected employees of the specific events being monitored at the time monitoring takes place.
NY
Introduced
Employers must notify employees and candidates at least 10 business days before using an AEDT to assess or evaluate them, disclosing: that an AEDT will be used; the qualifications assessed, data inputs, and output types; what data is collected and its source and retention policy; the most recent impact assessment results including any disparate impact findings; how to request an alternative non-AEDT selection process or accommodation; and how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all languages regularly used with employees, provided directly to each candidate in their language, and available in accessible formats.
NY
Introduced
Deployers must, before deploying a high-risk AI decision system to make or substantially factor into a consequential decision about a consumer, notify the consumer that the system has been deployed and provide: (1) a statement disclosing the system's purpose and the nature of the consequential decision; (2) the deployer's contact information; (3) a plain-language description of the system; and (4) instructions for accessing the deployer's public website statement under subdivision 6. All notices and statements must be provided directly to the consumer, in plain language, in all languages used in the deployer's ordinary course of business, and in a format accessible to consumers with disabilities.
NY
Introduced
Deployers must notify each individual subject to a consequential employment decision, at or before the time of the decision, that an AEDT is in use, and must provide the tool's purpose, a plain-language description of how it is the controlling factor, and deployer contact information.
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must notify each applicant (1) that an automated housing decision making tool will be used, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's data retention policy, and (4) if the application is denied, the reason for denial.
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must deliver the required notice at least 24 hours before using the automated housing decision making tool and must allow the applicant to request an alternative selection process or accommodation.
NY
Introduced
Covered entities must notify each loan applicant at least 24 hours before using an automated lending decision-making tool, disclosing (1) that the tool will be used, (2) the criteria the tool will apply, and (3) the type and source of data collected and the entity's data retention policy.
NY
Introduced
Employers must provide notice to employees that the employer is using artificial intelligence for recruitment, hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure, or the terms, privileges, or conditions of employment. The specific circumstances requiring notice, the time period for providing notice, and the means of notice will be established by Division of Human Rights rulemaking.
NY
Introduced
Food delivery platforms must provide delivery workers with clear, written, plain-language notice of (1) the factors the algorithmic management system considers in assigning deliveries and evaluating performance, (2) the metrics that may affect the worker's access to work opportunities or compensation, and (3) the circumstances under which a worker may be suspended, deactivated, or penalized.
PA
Introduced
Business entities must disclose in a clear and conspicuous manner that the consumer has a right to request human review whenever AI is used in a consumer interaction involving a high-impact decision.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must, before deploying a high-risk AI system to make or substantially factor in a consequential decision about a consumer, (1)notify the consumer of the AI system's use, (2) disclose the system's purpose and the nature of the decision, (3) provide the right to opt out of automated decision-making based on personal data, (4) provide deployer contact information, (5) provide a plain-language system description, and (6) provide instructions to access the deployer's public website statement.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must, before a high-risk AI system makes or is a substantial factor in making a consequential decision concerning a consumer: (1) notify the consumer that a high-risk AI system will be used; (2) provide a statement disclosing the system's purpose, the nature of the consequential decision, the deployer's contact information, a plain-language description of the system, and instructions on how to access the statement; and (3) inform the consumer of any applicable right to opt out of automated profiling for decisions producing legal or similarly significant effects. All notices must be provided directly to the consumer, in plain language, in all languages used in the deployer's ordinary course of business, and in a format accessible to consumers with disabilities. If direct notice is not feasible, the deployer must make the information available in a manner reasonably calculated to reach the consumer.
US
Introduced
Covered entities must evaluate and document consumer rights with respect to covered algorithms, including (1) whether consumers receive clear notice that an algorithm will be used, (2) whether consumers have an opt-out mechanism, (3) the transparency and explainability of the algorithm, (4) any mechanisms for consumers to contest, correct, or appeal a decision, and (5) the extent to which third-party decision recipients access algorithm results.
US
Introduced
Employers must disclose to covered individuals, before making an employment-related decision (or within 30 days for existing employees pre-enactment, or before accepting an application for post-enactment candidates): that ADS output is or will be used; the system's description, data types collected, characteristics measured, how they relate to job functions, and how to interpret outputs; the ADS operator's identity; how the output will be used; and the dispute/appeal process. Updated disclosures must be provided within 30 days of material changes.
US
Introduced
Covered entities must evaluate the extent to which they provide consumers with (1) clear notice of automated decision system use, (2) a mechanism for opting out, (3) transparency and explainability regarding contributing factors, (4) the ability to contest, correct, or appeal decisions, and (5) documentation of complaints and remediation outcomes. Covered entities must also document the categories of third-party decision recipients receiving decision results.
VA
Introduced
Landlords who use an algorithmic pricing device to set advertised rent, renewal rent, or rent offered to a prospective tenant must disclose such use in writing to the tenant or prospective tenant before lease execution (or before occupancy for oral rental agreements), including a statement that an algorithmic pricing device was used and the name of the software, platform, or service used.
VT
Introduced eff 2025-07-01
Employers must provide employees with written notice in plain, clear, and concise language before using an automated decision system to make an employment-related decision. The notice must include at minimum: (1) a plain language explanation of the ADS's nature, purpose, and scope, including specific employment decisions potentially affected; (2) the logic and key parameters affecting output; (3) the specific categories and sources of employee input data, including any data from electronic monitoring; (4) performance metrics the employer will use with the ADS; (5) the types of outputs the ADS will produce; (6) the developer(s) of the ADS; (7) the operator(s), monitor(s), and interpreter(s) of ADS results; (8) how to access the most recent impact assessment; (9) a description of the employee's rights to access and correct data under subsection (j); and (10) a statement that employees are protected from retaliation.
VT
Introduced eff 2025-07-01
Deployers must inform the consumer prior to the use of an automated decision system for a consequential decision, in clear, conspicuous, and consumer-friendly terms available in each language in which the company offers its end services. The notice must include: (1) a description of the personal characteristics or attributes the system will measure or assess; (2) the method of measurement or assessment; (3) how those attributes are relevant to the consequential decision; (4) any human components of the system; (5) how automated components inform the decision; and (6) a direct link to a publicly accessible page on the deployer's website with plain-language descriptions of the system's outputs, the types and sources of data collected and processed, and the results of the most recent impact assessment.
WA
Introduced eff 2028-07-01
Employers must notify employees and their exclusive bargaining representatives in writing at least 30 days before implementing electronic monitoring for performance evaluation purposes.
WA
Introduced eff 2028-07-01
Employers already using electronic monitoring for performance evaluations as of the effective date must provide written notice to affected employees and their exclusive bargaining representatives within 30 days of the effective date.
WA
Introduced eff 2028-07-01
Employers must provide written notice to new hires at the time the job offer is made stating that the employer uses or intends to use electronic monitoring to assist in performance evaluations.
WA
Introduced eff 2028-07-01
Employers must include in the written notice (1) a statement that the employer uses electronic monitoring, (2) a general list of the types of monitoring technology used for the primary purpose of monitoring job performance, and (3) a statement whether the employer has a verification process that includes meaningful human review to confirm monitoring data.
WA
Introduced eff 2026-07-01
Deployers must notify the consumer before any consequential decision is made using a high-risk AI system that the deployer has deployed such a system to make or substantially factor in the decision. The deployer must also provide a statement disclosing: (1) the purpose of the system and the nature of the consequential decisions; (2) the deployer's contact information; and (3) a plain-language description of the system.
WA
Introduced
Deployers must notify consumers before a consequential decision is made that a high-risk AI system has been deployed to make or substantially factor into the decision. Deployers must also provide a statement disclosing: (1) the purpose of the system and the nature of the consequential decisions it makes; (2) the deployer's contact information; and (3) a plain-language description of the system.
AK
Failed
State agencies must notify each individual who may be legally or significantly affected before using an AI system for a consequential decision concerning that individual.
AK
Failed
State agencies must inform prospective employees about any video interview that involves AI and obtain the prospective employee's consent before using AI in the interview.
AK
Failed
State agencies must notify each individual who may be legally or significantly affected before using a generative AI system to make consequential decisions about them.
AK
Failed
State agencies must inform prospective employees about any video interview that involves generative AI and obtain the prospective employee's consent before employing generative AI in the interview.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.2
Failed
Deployers must notify each individual subject to a consequential decision, at or before the time the automated decision tool is used, that the tool is being used, and must provide: the tool's purpose, deployer contact information, a plain-language description of the tool including its human and automated components, and information on how to request an alternative process.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.2
Failed
Deployers must notify any natural person, at or before the time an automated decision tool is used, that an automated decision tool is being used to make or be a controlling factor in making a consequential decision about them.
CA
Failed
Employers must provide a written pre-use notice to each worker (or their authorized representative) who will foreseeably be directly affected by an ADS used for employment-related decisions other than hiring. The notice must be provided: (1) at least 30 days before an ADS is first deployed; (2) no later than April 1, 2026 for ADS already in use when the law takes effect; and (3) within 30 days of hiring a new worker. The notice must be written in plain language as a separate, stand-alone communication, in the worker's routine language, and delivered via a simple method such as email, hyperlink, or other written format. The notice must contain: the types of employment-related decisions affected; a general description of the categories, sources, and collection methods for worker input data; key parameters known to disproportionately affect ADS output; the ADS vendor or creator; any quota set or measured by the ADS (including task quantities, potential adverse actions for failure, and whether quotas are subject to change); a description of the worker's right to access and correct data used by the ADS; and a statement that retaliation for exercising those rights is prohibited.
CA
Failed
Employers must notify job applicants upon receiving the application that the employer uses an ADS in making hiring decisions, if the ADS will be used for that position. Notification may be provided via an automatic reply mechanism or on the job posting.
CO
Failed
Deployers must, no later than the time of deployment, provide consumers with required disclosures when using a high-risk AI system to make or substantially factor in a consequential decision.
CO
Failed
Deployers must notify consumers before deploying a high-risk AI system to make or substantially factor in a consequential decision about them.
CO
Failed eff 2025-05-05
Deployers must, before each use of a high-risk AI system to make or substantially factor in a consequential decision about a consumer, disclose the system's purpose, trade name, developer name, deployer contact information, a plain-language description including the roles of AI and human components, the personal aspects evaluated, the evaluation method, relevance to the decision, accommodation information, and instructions for accessing the deployer's public statement.
CO
Failed
Deployers must provide pre-deployment notice to consumers before using a high-risk AI system to make or substantially factor into a consequential decision concerning the consumer. Effective June 30, 2026.
CT
Failed
Deployers must, before making a consequential decision using a high-risk AI system, notify the consumer that AI is being used, disclose the system's purpose and the nature of the decision, offer opt-out rights, and provide contact information and a plain-language system description. If the decision is adverse, the deployer must disclose the principal reasons (including AI's contribution and the data types and sources used), provide an opportunity to examine and correct personal data, and offer an appeal with human review where technically feasible. All notices must be in plain language, multilingual, accessible, and delivered directly to the consumer.
HI
Failed
Covered entities must, upon taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure that includes (1) the entity's contact information, (2) the factors the determination depended on, and (3) an explanation that the individual may access any personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
IL
Failed
Hospitals must inform patients when a diagnostic algorithm will be used to diagnose them, before the algorithm is applied.
IL
Failed
Hospitals must inform patients when a diagnostic algorithm will be used to diagnose them, present the option of being diagnosed without the algorithm, and obtain the patient's consent before using the algorithm.
IL
Failed
Deployers must notify any natural person subject to a consequential decision, at or before the time the automated decision tool is used, that an automated tool is being used and must provide (1) the tool's purpose, (2) the deployer's contact information, and (3) a plain-language description of the tool including its human and automated components.
IL
IL HB 69 (Diagnostic Algorithm) § 410 ILCS 50/3.5
Failed
Healthcare providers must inform the patient when a diagnostic algorithm will be used to diagnose them.
IL
IL HB 69 (Diagnostic Algorithm) § 410 ILCS 50/3.5
Failed
Healthcare providers must, before using a diagnostic algorithm on a patient, (1) present the patient with the option of being diagnosed without the algorithm and (2) obtain the patient's consent to the algorithm's use.
IL
Failed
Deployers must, at or before the time an automated decision tool is used to make a consequential decision, notify the individual who is the subject of the decision that an automated decision tool is being used. The notification must include: (1) a statement of the tool's purpose; (2) the deployer's contact information; and (3) a plain language description of the tool, including its human components and how the automated component informs the consequential decision.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(f)
Failed
Law enforcement agencies and district attorneys must (1) notify individuals charged with a crime that they were identified using a facial recognition search, and (2) make readily available to defendants and their attorneys all records about facial recognition searches in the investigation, including search results, alternative matches, algorithm details, accuracy rates, audit testing, operator identities, training records, and the match-selection process.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(f)
Failed
Law enforcement agencies and district attorneys must notify all individuals charged with a crime who were identified via facial recognition search, and must disclose to defendants and their attorneys all facial recognition search records — including results, all possible matches, the algorithm used, accuracy rates, audit testing results, operator identity and training, and the match-selection process.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(f)
Failed
Law enforcement agencies and district attorneys must (1) notify all individuals charged with a crime that they were identified using a facial recognition search, and (2) provide defendants and their attorneys with all records of facial recognition searches conducted during the investigation, including search results, other possible matches, the algorithm used, accuracy rates, audit testing results, operator identity and training, and the process for selecting the defendant as the most likely match.
MD
MD HB 1255 (Automated Employment Decision Tools) § Md. Code, Lab. & Empl. § 3-718(D)
Failed
Employers must notify each applicant within 30 days after use of an automated employment decision tool that (1) the tool was used in connection with their application, (2) the tool was subject to an impact assessment, and (3) the tool assessed the applicant's job qualifications or characteristics.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must make available at the time of deployment a standardized disclosure meeting the requirements of § 14–5005, notifying consumers that a high-risk AI system is in use.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5005
Failed
Deployers must provide consumers with a standardized disclosure that (1) notifies the consumer a high-risk AI system is in use, (2) discloses the purpose of the system and the nature, reason, and degree of the AI's involvement in the decision, (3) identifies the data used and its source, (4) includes deployer contact information, and (5) is delivered directly to the consumer in plain language, in all languages the deployer regularly uses, and in an accessible format.
MD
MD SB 957 (Automated Employment Decision Tools) § Md. Code, Lab. & Empl. § 3–718(D)
Failed
Employers must notify each applicant within 30 days after use of an automated employment decision tool that (1) the tool was used in connection with the applicant's application, (2) the tool was subject to an impact assessment, and (3) the tool assessed the applicant's job qualifications or characteristics.
MT
Failed
Law enforcement agencies must disclose to criminal defendants the use of facial recognition technology on them in a timely manner prior to trial.
NC
Failed
Deployers must provide written notice to each affected applicant or employee at least 10 business days before using an AEDT, disclosing (1) that an AEDT will be used, (2) the qualifications or criteria it evaluates, (3) a link to the bias audit summary, and (4) the right to request an alternative non-AEDT evaluation process.
NE
Failed
Deployers must, prior to deploying a high-risk AI system to make or be a substantial factor in making any consequential decision concerning a consumer: (1) notify the consumer that a high-risk AI system will be used; (2) provide a statement disclosing the system's purpose and the nature of the consequential decision; (3) provide the deployer's contact information; (4) provide a plain-language description of the system; (5) provide instructions on how to access the deployer's public transparency statement; and (6) if applicable, inform the consumer of the right to opt out of processing of personal data for profiling in furtherance of legally significant decisions under Nebraska's data privacy law (section 87-1107(2)(e)(iii)).
NM
Failed
Deployers must, before using a high-risk AI system to make or substantially factor in a consequential decision, directly notify the consumer that the system will be used, describe the system and its purpose, explain how to access the deployer's public notice, and provide the deployer's contact information. All notices must be in plain language, in all business languages, and accessible to consumers with disabilities.
NY
Failed
Employers and employment agencies must notify each job candidate, before using an automated employment decision tool to screen them, that (1) an automated tool will be used in their assessment, (2) the job qualifications and characteristics the tool will evaluate, and (3) the type and source of data collected and the employer's data retention policy.
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must notify each housing applicant, at least 24 hours before using the automated decision tool, that (1) an automated tool will be used to assess the applicant, (2) the characteristics the tool will use in the assessment, and (3) the type of data collected, its source, and the landlord's data retention policy.
NY
Failed
Employers must notify employees and candidates at least 10 business days before using an automated employment decision tool, disclosing: (1) that an AEDT will be used, (2) the qualifications and characteristics assessed, data attributes used, and outputs produced, (3) data collected, its source, and the data retention policy, (4) the most recent bias audit results, (5) how to request an alternative selection process or accommodation, and (6) how to request internal review and the right to file a civil action.
NY
Failed
Employers must provide prior written notice to all employees and candidates subject to electronic monitoring, including the monitoring purpose, specific data collected, activities and locations monitored, monitoring schedule, relationship to AEDT inputs, use for productivity standards, data storage location and retention period, and least-invasiveness justification. Notice must be in plain language, provided at hiring and annually, posted conspicuously, accessible to employees with disabilities, and provided in the employee's primary language. A notice that monitoring 'may' take place or that the employer 'reserves the right' to monitor is not actual notice.
NY
Failed
Employers engaging in random or periodic electronic monitoring must inform affected employees of the specific events being monitored at the time monitoring takes place. Notice may be given after monitoring only if necessary to preserve the integrity of an investigation of illegal activity or to protect the immediate safety of employees, customers, or the public.
NY
Failed
Employers must notify employees and candidates at least ten business days before using an AEDT to assess or evaluate them, disclosing: (1) that an AEDT will be used, (2) the qualifications and characteristics assessed, data attributes used, and outputs produced, (3) what data is collected and from what source, along with the data retention policy, (4) results of the most recent impact assessment including any disparate impact findings, (5) how to request an alternative non-AEDT selection process or accommodation, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website, provided to each candidate in their language, and accessible to employees with disabilities.
NY
Failed
Employers must provide affected employees written notice at least 14 calendar days before any employment decision based on monitoring data or AEDT outputs takes effect, disclosing: (1) performance standards used, (2) the employee's monitoring data used, (3) aggregated data for similarly situated employees for the prior 90 days, (4) any AEDT outputs used, (5) the most recent impact assessment of any AEDT used, and (6) any other information used in the decision.
NY
Failed
Employers who monitor employee telephone, email, or internet usage must give prior written notice upon hiring to all monitored employees, post the notice conspicuously, and ensure the notice complies with all requirements of Labor Law Article 36. Notice must be in writing or electronic form and acknowledged by the employee.
NY
Failed
Deployers must notify individuals at or before the time of a consequential employment decision that an automated employment decision tool is in use, and must provide the individual with (1) a statement of the tool's purpose, (2) a plain-language description of how the tool is the controlling factor in the decision, and (3) deployer contact information.
NY
Failed
Employers using an automated employment decision tool to screen candidates must notify each candidate that an automated tool subject to disparate impact reporting was used and must disclose the specific job qualifications or characteristics the tool assessed.
NY
Failed
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that an AEDT will be used; (2) the qualifications assessed, data inputs and attributes used, and output types; (3) data collected, its source, and the retention policy; (4) the most recent bias audit results and employer response; (5) how to request an alternative selection process or accommodation; and (6) how to request internal reevaluation and the right to file a civil action.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must notify each housing applicant (1) that an automated decision tool will be used to assess the applicant, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's data retention policy, and (4) if the application is denied, the reason for the denial.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must provide the required applicant notice at least 24 hours before the automated decision tool is used and must allow the applicant to request an alternative selection process or accommodation.
OK
Failed
Deployers must notify affected individuals when high-risk AI systems influence decisions about them and provide avenues for appeal or human review.
PA
Failed
Employers and employment agencies must notify each candidate at least ten days before their interview that an automated employment decision tool may be used, and must provide an explanation of how the tool works and what general types of characteristics it evaluates.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-3
Failed
Deployers must notify individuals at or before the time an automated decision tool is used for a consequential decision, providing the tool's purpose, deployer contact information, and a plain-language description of the tool's human and automated components.
TX
Failed
Employers must, before using an automated employment decision tool on an applicant, (1) notify the applicant that an AEDT may be used, (2) describe how the tool will be used and what characteristics it evaluates, and (3) obtain the applicant's written consent.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of automated decision system use, have a mechanism to opt out, can access information about the factors contributing to a decision, and can contest, correct, or appeal a decision, and must document all complaints, disputes, and remediation outcomes.
US
Failed
Law enforcement agencies that use facial recognition to attempt to identify an arrested individual must provide the individual with notice of the agency and database used, a copy of the authorizing court order, accuracy and bias reports, all probe images and modifications, the ranked candidate list, and all related police documentation, in an appropriate language if the individual is not fluent in English.
US
Failed
Covered entities must evaluate consumer rights in the impact assessment, including assessing whether consumers receive clear notice that an automated system will be used, whether a mechanism for opting out exists, the transparency and explainability of the system, and the degree to which consumers may contest, correct, or appeal decisions.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3593
Failed
The OMB Director must issue guidance requiring agencies to establish a plain-language notification process for individuals or entities impacted by agency determinations made by or substantively assisted by a federal AI system.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must establish procedures for notifying individuals or entities when an agency determination has been made solely by or substantively assisted by a federal AI system.
US
Failed
Employers must disclose to covered individuals, before making an employment-related decision (or before accepting an application for candidates), that they use or intend to use an automated decision system, along with a description of the system's data inputs, measured characteristics, job relevance, measurement methodology, how to interpret outputs, the operator's identity, how outputs will be used, and how to dispute or appeal. Updated disclosures must be provided within 30 days of significant changes.
US
Failed
Employers must not use an automated decision system output in making an employment-related decision unless the employer has first provided the disclosure required under Sec. 3(a)(2) to the covered individual.
US
Failed
Employers must disclose to covered individuals, prior to making an employment-related decision (or within 30 days for pre-enactment employees): (1) the fact of ADS use, (2) a description of the system including data types, measured characteristics, job-relatedness, measurement methodology, and how to interpret the output, (3) the identity of the ADS operator, (4) how the output will be used, and (5) how to dispute or appeal. For candidates applying post-enactment, disclosure must occur before accepting the application. Updated disclosures must be provided within 30 days of material changes.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of system use, have an opt-out mechanism, can access information about factors driving their decision, and can contest, correct, or appeal decisions — and must document all consumer complaints, disputes, corrections, appeals, opt-out requests, and remediation outcomes.
US
Failed
Covered entities must evaluate consumer rights with respect to the automated decision system, including: (1) whether consumers receive clear notice that the system will be used, (2) whether consumers can opt out, (3) the transparency and explainability of the system including which contributing factors drive decisions, (4) consumer contestation, correction, and appeal mechanisms, and (5) the extent to which third-party decision recipients access decision results.
US
Failed
Deployers must provide a short-form notice of no more than 500 words regarding each covered algorithm, including an overview of individual rights and practices involving consequential actions. For individuals with an existing relationship, the notice must be delivered electronically upon first interaction with the algorithm; for others, it must be posted on the deployer's website.
VA
Failed
State agencies must disclose to affected individuals: (i) the fact that an automated decision system is being used; (ii) the intended use of the system (e.g., evaluating candidates, making compensation decisions, considering employees for promotion); (iii) the type of data inputs received by the system and the source of such data; (iv) how the system will be used in the agency's decision-making processes; and (v) the extent to which an individual's personal data will be shared with third parties or used as future inputs for the system.
VA
Failed
Local government entities must disclose to affected individuals: (i) the fact that an automated decision system is being used; (ii) the intended use of the system; (iii) the type of data inputs received and their source; (iv) how the system will be used in the entity's decision-making processes; and (v) the extent to which personal data will be shared with third parties or used as future inputs.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-605
Failed
Deployers must notify individuals no later than the time the deployer uses a high-risk AI system to make a consequential decision concerning them, and must provide a statement disclosing the purpose of the system.
VT
Failed
Deployers must, no later than the time of a consequential decision, (1) notify the affected individual that a high-risk AI system is being used, (2) disclose the system's purpose, (3) provide deployer contact information, and (4) provide a plain-language description of the system including its human and automated components.
WA
Failed
Public agencies must give clear, plain-language notice to each individual impacted by an automated decision system disclosing: the fact that the system is in use, the system's name, vendor, and version, what decisions it will make or support, whether it is an automated final or support system and what human verification process applies, applicable deployment policies, and how the individual may contest any decision.
WA
Failed
Agencies must give clear, plain-language notice to persons impacted by an automated decision system disclosing: (1) that the system is in use, (2) the system's name, vendor, and version, (3) what decisions it makes or supports, (4) whether it is a final or support system and how human review occurs, (5) applicable deployment policies, and (6) how to contest decisions.
H-01.4
Right to request human review
The individual must have a clear, accessible mechanism to request human review of an automated decision. The right must be disclosed at or near the time of the decision. Human review must be available but the individual must invoke it.
Enacted
7
Live
68
Failed
44
Total
119
CA
CA SB 892 (ADS Procurement Standards) § Pub. Contract Code § 12100.1(d)
Enacted eff 2025-01-01
State agencies or ADS vendors must provide notice to individuals likely to be affected by ADS decisions or outcomes, including information about how to appeal or opt out of those decisions.
CO
Enacted eff 2026-05-14
Deployers must, upon request from a consumer who experienced an adverse outcome from a consequential decision materially influenced by a covered ADMT, provide an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable. Meaningful human review requires a reviewer designated by the deployer who has authority to approve, modify, or override the decision; considers relevant primary evidence; is trained to conduct the review; does not default to the system output; and has access to sufficient information to understand the output's intended use, material limitations, categories of inputs, and principal factors used to generate the output. FERPA-subject deployers may comply through existing student record amendment and appeal processes.
CO
Enacted eff 2026-05-14
HIPAA-covered entities that use a covered ADMT to determine a patient's eligibility for financial assistance (including discounted care) must provide patients with: (1) a plain-language description of the consequential decision and the role of the covered ADMT; (2) the types of information relied upon in the eligibility determination (except trade secrets and legally protected information); (3) information on how to request correction of materially inaccurate personal data consistent with HIPAA and § 25.5-3-502; and (4) information on how to request meaningful human review or reconsideration, where applicable. Compliance may be through advance general disclosure or a notice within 30 calendar days after an adverse outcome. Additionally, all HIPAA-covered entities must provide patients with a general notice of use of advanced technologies, including covered ADMT, which may be incorporated with existing patient-rights notices.
CO
Enacted eff 2026-02-01
Deployers must, following an adverse consequential decision, provide the consumer with (1) a statement disclosing the principal reasons for the decision, including the degree of AI contribution, data types used, and data sources, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review where technically feasible.
CO
Enacted eff 2026-02-01
Deployers must, when a consequential decision made using a high-risk AI system is adverse to the consumer, provide the consumer with: (1) a statement of the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the source(s) of that data; (2) an opportunity to correct any incorrect personal data used in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless an appeal would not be in the consumer's best interest (e.g., where delay might endanger the consumer's life or safety).
VA
Enacted eff 2026-07-01
Deployers must transmit consequential decisions to consumers without undue delay. For adverse decisions based on personal data beyond what the consumer directly provided, deployers must (1) disclose the principal reasons for the decision, including the degree of AI contribution, data types processed, and data sources; (2) provide an opportunity to correct inaccuracies in personal data under the VCDPA; and (3) provide an opportunity to appeal, with human review where technically reasonable and practicable, unless delay would risk the consumer's life or safety.
WA
WA SB 5395 (Health Carrier Prior Authorization AI) § RCW 48.43.535 (as amended by Sec. 6/Sec. 7)
Enacted eff 2026-06-11
Health carriers must allow enrollees to bypass the carrier's internal grievance process and proceed directly to independent review by a certified independent review organization for retrospective denials of prior-authorized services under RCW 48.43.525.
IL
Enrolled
Health insurance issuers must provide physicians with a clear and accessible process for appealing downcoded claims, including written or electronic instructions, contact information for the managing physician, a submission window of no less than 180 days, and adjudication timelines consistent with state utilization review law. Physicians must be permitted to appeal in batches of similar claims without restriction.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must provide subjects with the opportunity within 30 business days after a consequential decision to (1) correct inaccurate personal information used by the ADS, with deployer response within 30 business days, rectification within 30 days if the correction would change the outcome, and explanation if it would not, and (2) appeal the decision outcome, with deployer review within 30 business days, rectification within 30 days if the original decision was incorrect, and explanation of denial basis if the decision is upheld. If a correction request is denied, the deployer must explain the basis and offer deletion of the subject's personal information.
CA
CA AB 1609 (Customer Service Chatbots) § Bus. & Prof. Code § 22627
Engrossed
Operators must provide consumers with human customer service support and communications during business hours of 8 a.m. to 6 p.m. daily. During those hours, operators must connect any person interacting with a customer service chatbot or automated customer support system to a customer service agent within five minutes after a request for human customer service is made.
CA
CA AB 1609 (Customer Service Chatbots) § Bus. & Prof. Code § 22627
Engrossed
Operators of telephonic customer service platforms must ensure that: (1) after a customer call is answered, the customer is not placed on hold for more than 5 minutes at any point and cumulative hold times for a call do not exceed 10 minutes total; and (2) if a call is answered by a customer service chatbot, the operator provides human assistance within five minutes after the call is made.
CA
CA AB 1609 (Customer Service Chatbots) § Bus. & Prof. Code § 22627
Engrossed
Operators of online customer service platforms must provide customers with the option to request customer service assistance from a human being and, upon that request, must provide human assistance within five minutes.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed eff 2026-01-01
Deployers must provide, as technically feasible, any natural person subject to a decision made by a high-risk automated decision system with an opportunity to appeal that decision for review by a natural person.
NY
NY SB 1169 (AI Algorithmic Discrimination) § Civ. Rights Law § 86-a
Engrossed
Deployers must inform end users at least five business days before using a high-risk AI system to make a consequential decision, in clear, conspicuous, and consumer-friendly terms available in each language in which the company offers its services. Deployers must allow sufficient time and opportunity for the end user to opt out of the automated decision process and have the decision made by a human representative instead. End users may not be punished for opting out, and the deployer must render a decision within 45 days. When the decision confers a benefit on the end user, the deployer must offer the option to waive the five-day advance notice. An urgent-necessity exception applies when compliance would cause imminent detriment to the end user's welfare, but the right to request human review may never be waived. End users are entitled to no more than one opt-out per consequential decision in a six-month period.
NY
NY SB 1169 (AI Algorithmic Discrimination) § Civ. Rights Law § 86-a
Engrossed
Deployers must inform end users within five days after a high-risk AI system has been used to make a consequential decision. Deployers must provide and explain an appeal process that allows the end user to (1) formally contest the decision, (2) provide supporting information, and (3) obtain meaningful human review. The deployer must respond to appeals within 45 days, extendable once by 45 additional days with notice and reasons. End users are entitled to no more than one appeal per consequential decision in a six-month period.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must, for adverse consequential decisions, provide the consumer with (1) a statement disclosing principal reasons for the decision including the AI system's contribution, data types processed, and data sources; (2) an opportunity to correct incorrect personal data used in the decision; and (3) an opportunity to appeal the decision with human review where technically feasible.
CT
Introduced eff 2025-10-01
Employers must, when a consequential decision made by or substantially based on a high-risk AI system is adverse to an employee, (1) disclose the principal reasons for the decision including the AI system's degree of contribution, the data types processed, and data sources, (2) allow the employee to examine and correct the personal data processed, and (3) provide an opportunity to appeal inaccurate-data-based decisions with human review.
CT
Introduced eff 2026-10-01
Deployers must, when an automated employment-related decision process makes or substantially factors into an adverse employment-related decision, provide the affected applicant or employee with: (1) a high-level statement disclosing the principal reasons for the adverse decision, including the degree and manner of the process's contribution, the type of data processed, and the source of that data; (2) an opportunity to examine and correct the data used and to appeal the decision with human review if it was based on incorrect data; and (3) upon request, a copy of the most recent bias audit. The high-level statement must be provided directly to the individual, in plain language, in all languages the deployer ordinarily uses in the state, and in a format accessible to individuals with disabilities.
CT
Introduced eff 2026-10-01
Deployers must implement human review over every automated employment-related decision process used to make or substantially factor into employment-related decisions. A qualified human reviewer — with authority to make or change decisions and understanding of the process's biases and limitations — must review the AI output and, when appropriate, modify or veto it prior to any adverse decision. Deployers must establish procedures to pause, correct, or reverse erroneous or harmful outputs, and must maintain logs of all human review reports and interventions. No automated employment-related decision process may be used for a final or determinative employment-related decision without human review.
GA
Introduced
Deployers must transmit to the consumer within one business day after an automated consequential decision a notice including: (1) a specific explanation of the principal factors and variables that led to the decision, including the degree and manner of AI contribution, the data sources processed, and a plain-language explanation of how the consumer's personal data informed those factors; (2) information about the consumer's right to correct data and how to submit corrections and supplementary information; (3) what actions the consumer might have taken to secure a different decision and may take in the future; (4) information on opportunities to correct incorrect personal data processed in the decision; and (5) information on opportunities to appeal an adverse decision, which appeal must allow for human review if technically feasible.
HI
HI SB 2167 (Healthcare AI & Prior Authorization) § HRS § 432E-5 (Complaints and appeals procedure for enrollees — amended by Section 5)
Introduced
Health carriers must provide enrollees with a universal external review request form and a clear, step-by-step guide explaining the enrollee's rights and procedures to request an internal appeal or external review upon any adverse determination.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Consequential decisions; notice; statement; opt-out; corrections; appeal)
Introduced eff 2028-07-01
Health care providers that used an AI system to make or substantially factor into a consequential decision must provide the patient or authorized representative with: (1) a written statement describing the consequential decision and its principal reasons, including the degree and manner of the AI system's contribution, the types of data the AI processed, and the sources of that data; (2) an opportunity to correct any incorrect health information or personal data the AI system processed in making the decision; and (3) an opportunity to appeal the consequential decision, including human review of all information relating to the decision to the extent technically feasible. The appeal right does not apply when providing an opportunity for appeal is not in the patient's best interest, including when any delay might pose a risk to the patient's life or safety.
HI
Introduced
Deployers must implement a reasonable process by which consumers may (1) request correction of inaccurate personal information used in a consequential decision, (2) submit additional information for reconsideration, and (3) obtain human review of an adverse action by a reviewer with authority to overturn the decision and subject-matter-relevant training. Narrow exceptions apply when human review would conflict with law or compromise security, but the deployer must document the basis and offer an alternative dispute channel.
ID
ID HB 945 (AI Medical Services Act) § Idaho Code § 54-6005
Introduced eff 2026-07-01
Fully autonomous (L3) AAASPs must, before delivering services, obtain affirmative patient acknowledgment of the prescribed disclosure that the provider is an AI system without routine human clinical oversight and that the patient may seek alternative human care at any time.
IL
Introduced
Employers must, when using an automated decision-making system for any function covered by Section 10(a): (1) provide notice to each affected employee no later than the time a decision is issued that the decision was made using an automated decision-making system; (2) provide an appeals process for employees directly impacted by decisions made by the system; and (3) offer each affected employee the opportunity for an independent alternative review of the decision by an individual working for or on behalf of the employer, separate from the automated system.
IL
IL SB 3735 (Ed-Tech Rights / Biometric Info) § Student Educational Technologies Rights Act § 15
Introduced
Schools must honor a student's or parent's right to: (1) opt out of school-issued personal electronic devices, electronic textbooks, electronic required reading, or electronic or online assignments; (2) request a human teacher review any automated scored grade or scored grade generated by artificial intelligence; and (3) opt out of predictive analytics systems without academic penalty. When any of these rights is exercised, the school must provide the student with a comparable analog version of what the educational technology provides, including physical paper assignments, physical textbook copies, or physical copies of required reading.
IN
Introduced eff 2026-07-01
Employers must allow covered individuals, after receiving post-decision documentation, to: (i) dispute the automated decision system output in a manner that is accessible, equitable, and does not impose an unreasonable burden, to a human with appropriate and relevant experience; and (ii) appeal the employment-related decision to a human with appropriate and relevant experience who is not the same human who performed the corroboration under clause (E).
LA
Introduced
Employers that primarily rely on an ADS to make a discipline, termination, or deactivation decision must provide the affected worker with written notice at the time the decision is made. The notice must be a separate, standalone, plain-language communication in the worker's routine language, and must include: (1) the human individual to contact for more information and to request a copy of the worker's data relied on in the decision, (2) that the employer used an ADS in the decision, (3) that the worker has a right to request a copy of the data used by the ADS, (4) that retaliation is prohibited, and (5) the worker's right to appeal the decision under R.S. 23:975.
LA
Introduced
Employers or vendors that use an ADS to make an employment-related decision must provide the affected worker with a right to appeal that decision, request human review, submit additional information, and correct data errors. The employer or vendor must provide a form or hyperlink to an electronic appeal form within 30 days of the worker's notification. The form must include options to request ADS input/output data, corroborating evidence from the human reviewer, a field for the worker's reason and supporting evidence, and a designation for an authorized representative. The employer or vendor must respond to the appeal within 14 business days by designating a human reviewer who can objectively evaluate all evidence, has sufficient authority, discretion, and resources to evaluate and overturn the decision, and was not involved in the original decision. The response must be a clear written document describing the appeal result and reasons. If the reviewer overturns the decision, the employer or vendor must rectify it within 21 business days.
LA
Introduced
Covered insurers must, upon consumer request within 30 days of an adverse action, assign a qualified human underwriter or claims professional to independently review the decision, complete the review within 30 days, and provide a written explanation. The reviewer must have full authority to modify or reverse the adverse action based on the consumer's specific facts.
LA
Introduced eff 2026-08-01
Health insurance issuers must allow any insured to appeal a coverage determination that the insured has learned was made with a recommendation from AI or an automated decision system.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that the tool will be used, (2) the qualifications and data attributes assessed and outputs produced, (3) data sources and retention policy, (4) the most recent impact assessment results, (5) how to request an alternative non-automated selection process, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all employee-facing languages, provided directly to candidates, and accessible to individuals with disabilities.
MA
Introduced
Deployers must, when a consequential decision is adverse to the consumer, provide: (1) a statement disclosing the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the sources of that data; (2) an opportunity to correct any incorrect personal data the system processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless the appeal would not be in the consumer's best interest (e.g., where delay poses a risk to the consumer's life or safety).
MA
Introduced
Employers must not rely primarily on automated decision tool output when making hiring, promotion, termination, disciplinary, or compensation decisions. To satisfy this requirement: (1) employers must establish meaningful human oversight, considering the tool's complexity, the reviewer's experience and training, preparation time, and feasibility of expert consultation; (2) a human decision-maker must actually review each automated output and exercise independent judgment; (3) the human must consider non-automated information such as supervisory evaluations, personnel files, work products, or peer reviews; and (4) the employer must consider non-automated information in each such decision. Employers must not require employee or candidate consent to automated tool use as a condition of being considered for an employment decision, and must not discipline or disadvantage anyone for requesting accommodation.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must require all automated evaluations to be subject to human review within 24 hours before a decision is final, and must provide an expedited review process with human review within 48 hours after a consumer submits a review request.
MD
MD HB 795 (AI Health Insurance Accountability) § Md. Code Ann., Insurance § 15–10A–02(b)(2)
Introduced eff 2026-10-01
Carriers must ensure that their internal grievance process provides for human review of any adverse decision made using artificial intelligence, an algorithm, or other software tools when a member files a grievance challenging that decision. The human review must include an assessment of whether the AI tool complied with § 15–10B–05.1, which requires individualized clinical data inputs, prohibits sole reliance on group datasets, and imposes non-discrimination and oversight requirements.
MN
Introduced
Employers must provide each worker affected by an ADS-informed employment decision with a form or link to appeal the decision. The appeal form must include options to request ADS input/output data and human reviewer corroborating evidence, space for the worker's reasons and supporting evidence, and information on designating an authorized representative. Workers must file appeals within 30 days of post-use notification. Employers must respond within five business days by assigning a human reviewer who: objectively evaluates all evidence, has authority and training to evaluate the decision (including ADS limitations and worker rights), has authority to overturn the decision, and was not involved in the original decision. The reviewer must produce a written document explaining the appeal result and reasoning, provided to both the employer and worker. If the decision is overturned, the employer must rectify it within five business days.
MN
Introduced
Employers must provide workers with a form to appeal any employment-related decision based on electronic monitoring data. The employer must respond within five business days by designating an independent human reviewer — not involved in the original decision, with authority to overturn it — who must produce a written decision with reasoning. If overturned, the employer must rectify the decision within five business days.
MN
Introduced eff 2027-01-01
Employers must provide workers with a structured appeal form when monitoring data was used in an employment-related decision, respond within five business days by designating an independent, qualified human reviewer with authority to overturn the decision, produce a written decision with reasons, and rectify any overturned decision within five business days.
MN
Introduced eff 2027-01-01
Employers must provide workers with a form to appeal any employment-related decision made using an automated decision system. Within five business days of receiving an appeal, the employer must designate an independent human reviewer — not involved in the original decision, with authority to overturn it — who must objectively evaluate all evidence, produce a written decision explaining the result and reasons, and if the decision is overturned, the employer must rectify it within five business days.
MO
Introduced
Employers must, within thirty minutes of an employee's request, assign a human manager authorized to make discipline-related decisions to speak with the employee in person during work hours.
NJ
Introduced
Employers and public entities must provide at least 10 days' advance written notice before any adverse AI-assisted employment or public-benefit decision takes effect, explaining the reasons, providing access to all data, and informing the individual of appeal rights. Upon request within 30 days, the employer must (1) allow the individual to review and copy all data and receive a complete explanation of how the AEDS or ABSDS produced its outputs including factor weighting, (2) allow the individual to appeal on grounds of data inaccuracy, bias, or legal violations, and (3) designate a qualified human reviewer with authority and discretion to modify or overturn the decision. For applicants, notice must be provided no later than the time of the decision.
NJ
Introduced
On request within 30 days, employers and public entities must let the individual review and copy the decision data, personnel files, impact-assessment and oversight records, and factor-weighting explanation; permit an appeal to correct inaccurate or biased data and contest the decision; and designate a qualified, empowered human reviewer with authority to modify or overturn it who issues the final internal determination.
NJ
Introduced
Covered entities must provide individuals adversely affected by an automated decision system with the right to request meaningful human review of the decision.
NM
Introduced eff 2026-07-01
Deployers must provide consumers an opportunity to appeal any adverse consequential decision, and the appeal must be reviewed by a human being.
NY
Introduced
Employers that primarily relied on ADS output for a discipline, termination, or deactivation decision must provide the affected worker with a written, plain-language, standalone notice at the time the decision is communicated. The notice must identify a human contact, state that an ADS was used, disclose the worker's right to request a copy of their data, and state the employer's anti-retaliation obligation.
NY
NY AB 10764 (Utility Billing Integrity Act) § Pub. Serv. Law § 65-c(6)
Introduced
Utilities must, upon a residential customer's request for billing review, (1) suspend all adverse actions including late fees, collections, and service termination, (2) conduct a review including qualified human personnel review and error correction, and (3) provide a written determination to the customer within ten business days.
NY
NY AB 3125 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must allow housing applicants to request an alternative selection process or accommodation as an alternative to evaluation by the automated housing decision making tool. This right must be communicated in the required notice provided at least 24 hours before use of the tool.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 508
Introduced
Persons developing and deploying automated systems must provide New York residents with the right to opt out of automated systems in favor of a human alternative, where appropriate. Appropriateness is determined based on reasonable expectations in a given context, with a focus on ensuring broad accessibility and protecting the public from particularly harmful impacts.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 508
Introduced
Persons developing and deploying automated systems must provide New York residents with access to a timely human consideration and remedy through a fallback and escalation process if an automated system fails, produces an error, or if the resident wishes to appeal or contest the system's impacts. The fallback process must be accessible, equitable, effective, maintained, accompanied by appropriate operator training, and must not impose an unreasonable burden on the public.
NY
Introduced
Landlords must notify each housing applicant at least 24 hours before using an automated decision tool that (1) the tool will be used, (2) the characteristics the tool will evaluate, (3) the type and source of data collected and the landlord's retention policy, and (4) the reason for any denial. The notice must allow the applicant to request an alternative selection process or accommodation.
NY
Introduced
When a high-risk AI decision system has been used to make or substantially factor into an adverse consequential decision concerning a consumer, the deployer must provide the consumer: (1) a statement disclosing the principal reasons for the adverse decision, including the degree and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data the system processed; and (3) an opportunity to appeal the adverse decision, which must include human review if technically feasible, unless human review would not be in the consumer's best interest (e.g., where delay poses a risk to life or safety).
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 108
Introduced
Covered deployers must, within ten days of a consequential decision, notify the subject that a high-risk AI system was used and provide an appeal process allowing the subject to (1) contest the decision, (2) submit supporting information, and (3) obtain meaningful human review, responding within forty-five days (extendable once).
NY
Introduced
Employers must provide any applicant who receives an adverse employment decision made using an automated system with a human-conducted review of that decision upon the applicant's request.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 108
Introduced
Deployers must, once Division regulations are promulgated (within two years of the effective date), provide individuals a means to opt out of the use of a covered algorithm for a consequential action and to elect to have the consequential action undertaken by a human without the use of a covered algorithm. The opt-out and human-alternative mechanism must be clear and conspicuous, in plain language, easy to execute, and at no cost to the individual, as specified by Division regulations.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 108
Introduced
Deployers must, once Division regulations are promulgated (within two years of the effective date), provide individuals a mechanism to appeal to a human any consequential action resulting from the deployer's use of a covered algorithm. The appeal mechanism must be clear and conspicuous, in plain language, easy to execute, at no cost, proportionate to the consequential action, reasonably accessible to individuals with disabilities, timely, usable, effective, and non-discriminatory. Where appropriate, the mechanism must allow individuals to identify and correct personal data used by the algorithm. Human reviewers must meet Division-specified training requirements.
NY
Introduced
Employers must notify employees and candidates at least 10 business days before using an AEDT to assess or evaluate them, disclosing: that an AEDT will be used; the qualifications assessed, data inputs, and output types; what data is collected and its source and retention policy; the most recent impact assessment results including any disparate impact findings; how to request an alternative non-AEDT selection process or accommodation; and how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all languages regularly used with employees, provided directly to each candidate in their language, and available in accessible formats.
NY
Introduced
Employers must not require employees or candidates to consent to AEDT use as a condition of being considered for an employment decision, and must not discipline or disadvantage any employee or candidate who requests an alternative accommodation.
NY
Introduced
Deployers must, when a high-risk AI decision system makes or substantially factors into an adverse consequential decision concerning a consumer, provide the consumer with: (1) a statement disclosing the principal reasons for the adverse decision, including the degree to which and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless providing such opportunity would not be in the consumer's best interest (e.g., delay posing life or safety risk).
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Introduced
Landlords must deliver the required notice at least 24 hours before using the automated housing decision making tool and must allow the applicant to request an alternative selection process or accommodation.
PA
Introduced
Business entities must provide the consumer with timely access to a human representative upon request, if a human representative is reasonably available.
PA
Introduced
Business entities must provide consumers with the right to request that a human representing the business entity review any consumer interaction involving a high-impact decision. The business entity must commence the human review within 14 days of the request and complete the review with a decision delivered to the consumer within 28 days of the request.
PA
Introduced
Digital platforms must honor requests from a deceased user's estate representative (or designated personally authorized representative) to revoke consent, terminate the AI simulation, and delete AI-generated content created after death, and may not override a valid estate directive.
PA
Introduced
Board rules must guarantee each person receiving services the option to communicate directly with a human licensee rather than solely through AI, and must define the process for exercising that option.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must, when a consequential decision is adverse to a consumer, (1) explain the principal reasons including the degree and manner of AI contribution, data types, and data sources, (2) allow the consumer to examine and correct personal data used, and (3) provide an opportunity to appeal based on inaccurate personal data with human review where technically feasible. All notices must be provided directly to the consumer, in plain language, in all languages the deployer ordinarily uses, and in formats accessible to consumers with disabilities.
TX
TX HB 4390 (Machine Grading Parental Rights) § Tex. Educ. Code § 39.023(r)
Introduced eff 2025-09-01
When a student fails to perform satisfactorily on an assessment scored by machine grading, the agency must, upon written parental request, rescore the constructed-response portion using a traditional human scoring method at no cost to the parent.
US
Introduced
Covered entities must evaluate and document consumer rights with respect to covered algorithms, including (1) whether consumers receive clear notice that an algorithm will be used, (2) whether consumers have an opt-out mechanism, (3) the transparency and explainability of the algorithm, (4) any mechanisms for consumers to contest, correct, or appeal a decision, and (5) the extent to which third-party decision recipients access algorithm results.
US
Introduced
Deployers must, once FTC regulations are promulgated (within 2 years of enactment), provide individuals a means to opt out of covered algorithm use for a consequential action and elect to have the action undertaken by a human without algorithm involvement.
US
Introduced
Employers must enable covered individuals to (1) dispute the ADS output to a human with appropriate and relevant experience via an accessible, equitable, and non-burdensome process, and (2) appeal the employment-related decision to a different human with appropriate and relevant experience than the one who corroborated the ADS output.
US
Introduced
Covered entities must evaluate the extent to which they provide consumers with (1) clear notice of automated decision system use, (2) a mechanism for opting out, (3) transparency and explainability regarding contributing factors, (4) the ability to contest, correct, or appeal decisions, and (5) documentation of complaints and remediation outcomes. Covered entities must also document the categories of third-party decision recipients receiving decision results.
US
Introduced
Deployers must, pursuant to FTC regulations to be promulgated within two years of enactment, provide individuals a means to opt out of algorithmic consequential actions and elect a human alternative at no cost.
US
Introduced
Deployers must, pursuant to FTC regulations to be promulgated within two years of enactment, provide individuals a mechanism to appeal algorithmic consequential actions to a human reviewer. The mechanism must be accessible, proportionate, and include data correction capabilities and trained reviewers.
VA
Introduced
Landlords must, upon request by a tenant or prospective tenant, provide a human review of any rent determination or renewal increase generated or recommended by an algorithmic pricing device.
VA
Introduced
Landlords must provide tenants and prospective tenants, upon request, with a human review of any rent determination or renewal increase generated or recommended by an algorithmic pricing device.
VT
Introduced eff 2025-07-01
Deployers must provide and explain a process for consumers to appeal a consequential decision. The appeal process must allow the consumer to formally contest the decision, provide supporting information, and obtain meaningful human review. The deployer must designate a human reviewer who is trained and qualified, free of conflicts of interest, was not involved in the initial decision, is protected from retaliation for exercising their review functions, and is allocated sufficient resources. The human reviewer must consider the consumer's information and may consider other relevant sources. The deployer must respond within 45 days, extendable once by an additional 45 days with notice and explanation of the delay.
AK
Failed
State agencies must provide an appeals process that includes manual human review for any individual legally or significantly affected by an AI-assisted consequential decision.
AK
Failed
State agencies must provide an appeals process that includes manual human review for any individual legally or significantly affected by a generative AI consequential decision.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.2
Failed
Deployers must, when a consequential decision is made solely based on the output of an automated decision tool and if technically feasible, accommodate an individual's request to opt out and be subject to an alternative selection process or accommodation.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.2
Failed
Deployers must, if technically feasible, accommodate a natural person's request to opt out of a consequential decision made solely by an automated decision tool and provide an alternative selection process or accommodation. The deployer may require identifying information and is not obligated to accommodate if the person does not provide it.
CO
Failed
Deployers must, when a high-risk AI system makes or substantially factors in an adverse consequential decision concerning a consumer, provide the consumer with the required adverse-decision disclosures.
CO
Failed
Deployers must provide consumers with an explanation and appeal opportunity when a high-risk AI system makes or substantially factors in an adverse consequential decision about them.
CO
Failed eff 2025-05-05
Deployers must, within 30 days after an adverse consequential decision, provide a single notice disclosing the main reasons for the decision (including the AI system's contribution and the categories and sources of data that adversely affected the output, including sensitive data), information on how to exercise correction and appeal rights, and a copy of the notice. Deployers must offer an opportunity to correct incorrect personal data. For non-competitive, non-time-limited adverse decisions based on incorrect data or unlawful information, deployers must provide an opportunity to appeal with human review if technically feasible. The correction and appeal rights apply only to systems that are the principal basis of the decision.
CO
Failed
Deployers must provide consumers with specified information when a high-risk AI system makes or substantially factors into an adverse consequential decision, effective June 30, 2026.
CT
Failed
Deployers must, before making a consequential decision using a high-risk AI system, notify the consumer that AI is being used, disclose the system's purpose and the nature of the decision, offer opt-out rights, and provide contact information and a plain-language system description. If the decision is adverse, the deployer must disclose the principal reasons (including AI's contribution and the data types and sources used), provide an opportunity to examine and correct personal data, and offer an appeal with human review where technically feasible. All notices must be in plain language, multilingual, accessible, and delivered directly to the consumer.
HI
Failed
Covered entities must, upon taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure that includes (1) the entity's contact information, (2) the factors the determination depended on, and (3) an explanation that the individual may access any personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
HI
Failed
Covered entities must, upon taking any adverse action based on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's right to access their personal information used in the determination, submit corrections, and request a human-conducted reevaluation based on corrected data.
HI
Failed
Covered entities must, when taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's rights to access personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
IL
Failed
Hospitals must present the patient with the option of being diagnosed without the diagnostic algorithm and must obtain the patient's consent before using the algorithm.
IL
Failed
Deployers must, if technically feasible, accommodate a natural person's request to opt out of a consequential decision made solely by an automated decision tool and to be subject to an alternative selection process or accommodation.
IL
IL HB 69 (Diagnostic Algorithm) § 410 ILCS 50/3.5
Failed
Healthcare providers must, before using a diagnostic algorithm on a patient, (1) present the patient with the option of being diagnosed without the algorithm and (2) obtain the patient's consent to the algorithm's use.
IL
Failed
Deployers must, if technically feasible, accommodate an individual's request not to be subject to an automated decision tool when the consequential decision is made solely based on the tool's output, and must provide an alternative selection process or accommodation. The deployer may collect identifying information to process the request; if the individual does not provide it, the deployer is not obligated to provide the alternative.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must provide consumers subject to a high-risk AI system the opportunity to (1) correct any data used by the system in making a decision about the consumer, and (2) appeal an adverse decision, including human review. A deployer may decline to provide appeal where the delay would pose a risk to the consumer's safety.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must subject all automated evaluations to human review within 24 hours of the evaluation and must provide an expedited review process that includes human review within 48 hours of a consumer's review request.
NC
Failed
Deployers must provide an alternative selection or evaluation process that does not rely on the AEDT upon a timely written request from an applicant or employee, unless no reasonable alternative process exists.
NE
Failed
Deployers must, for each high-risk AI system that makes or is a substantial factor in making an adverse consequential decision concerning a consumer, provide to that consumer: (1) a statement disclosing each principal reason for the decision, including the degree and manner in which the AI system contributed to the decision, the type of data processed, and each source of that data; (2) an opportunity to correct any incorrect personal data that the system processed in making or contributing to the decision; and (3) an opportunity to appeal the adverse decision, unless an appeal is not in the consumer's best interest (e.g., where delay would risk life or safety), with human review if technically feasible. All notices, statements, and descriptions must be provided directly to the consumer, in plain language, in each language the deployer ordinarily uses in business communications, and in a format accessible to consumers with disabilities. If direct provision is not possible, the deployer must make the information available in a manner reasonably calculated to ensure the consumer receives it.
NM
Failed
Deployers must, after an adverse consequential decision, provide the consumer with (1) an explanation of the principal reasons, the degree and manner of AI contribution, and the source and type of data processed, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review if technically feasible.
NY
Failed
Employers and employment agencies must provide the required notice at least ten business days before using the automated employment decision tool and must allow the candidate to request an alternative selection process or accommodation.
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must allow housing applicants to request an alternative selection process or accommodation as part of the pre-use notice required at least 24 hours before the automated decision tool is used.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing or deploying automated systems must provide New York residents the right to opt out of automated systems in favor of a human alternative, where appropriate based on reasonable expectations in the given context.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing or deploying automated systems must provide New York residents with access to a timely, accessible, equitable, and effective human consideration and remedy process — including fallback and escalation — when a system fails, produces an error, or a resident wishes to appeal or contest the system's impact. The process must be accompanied by appropriate operator training and must not impose an unreasonable burden on the public.
NY
Failed
Employers must provide employees and candidates a meaningful opportunity to request reevaluation of AEDT-informed employment decisions within 30 days of the decision, where the individual believes the decision resulted from inaccuracy, error, bias, sole reliance on the tool, or other violation and was meaningfully harmed.
NY
Failed
Employers must notify employees and candidates at least ten business days before using an AEDT to assess or evaluate them, disclosing: (1) that an AEDT will be used, (2) the qualifications and characteristics assessed, data attributes used, and outputs produced, (3) what data is collected and from what source, along with the data retention policy, (4) results of the most recent impact assessment including any disparate impact findings, (5) how to request an alternative non-AEDT selection process or accommodation, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website, provided to each candidate in their language, and accessible to employees with disabilities.
NY
Failed
Employees who believe an employment decision resulted from inaccurate monitoring data or an erroneous AEDT output may request reevaluation in writing. Employers must investigate and respond within seven calendar days. If inaccuracy is confirmed, the employer must inform the employee in writing and reevaluate using corrected data or without the AEDT. If the employer finds no inaccuracy, it must provide the employee with evidence of accuracy and validity.
NY
Failed
Employers must offer employees and candidates a meaningful opportunity to request reevaluation of any employment decision made or assisted by an AEDT, where the person believes the decision resulted from inaccuracy, error, bias, sole reliance on the tool, or other statutory violation, and was meaningfully harmed. The written request must be submitted within thirty days of the decision and must include the person's identity, the decision at issue, the harm suffered, the basis for the belief, supporting evidence, and requested remedial action.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(3)
Failed
Landlords must provide the required applicant notice at least 24 hours before the automated decision tool is used and must allow the applicant to request an alternative selection process or accommodation.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing automated systems must provide residents, where appropriate, with the right to opt out of automated systems in favor of a human alternative, ensuring broad accessibility and protecting the public from particularly harmful impacts.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing automated systems must provide residents with access to a timely, accessible, equitable, and effective human-consideration and remedy process through a fallback and escalation mechanism when systems fail, produce errors, or when residents wish to appeal or contest outcomes. The process must be accompanied by operator training and must not impose an unreasonable burden on the public.
OK
Failed
Deployers must notify affected individuals when high-risk AI systems influence decisions about them and provide avenues for appeal or human review.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-3
Failed
Deployers must, if technically feasible, accommodate a natural person's request to opt out of a consequential decision made solely by the automated decision tool and provide an alternative selection process or accommodation.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of automated decision system use, have a mechanism to opt out, can access information about the factors contributing to a decision, and can contest, correct, or appeal a decision, and must document all complaints, disputes, and remediation outcomes.
US
Failed
Covered entities must evaluate consumer rights in the impact assessment, including assessing whether consumers receive clear notice that an automated system will be used, whether a mechanism for opting out exists, the transparency and explainability of the system, and the degree to which consumers may contest, correct, or appeal decisions.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3593
Failed
The OMB Director must issue guidance requiring agencies to review and modify their appeals processes to account for AI-assisted determinations and to provide impacted individuals the opportunity for alternative review independent of the AI system.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must modify the agency's appeals process to account for AI-assisted determinations and provide impacted individuals the opportunity for alternative review independent of the AI system.
US
Failed
Employers must enable covered individuals to (1) dispute the automated decision system output to a qualified human reviewer in an accessible manner and (2) appeal the employment-related decision to a different qualified human reviewer than the one who corroborated the original output.
US
Failed
Employers must enable the covered individual, after receiving post-decision documentation, to (1) dispute the automated decision system output to a qualified human reviewer in an accessible, equitable manner, and (2) appeal the employment-related decision to a different qualified human reviewer who was not the corroborating reviewer.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of system use, have an opt-out mechanism, can access information about factors driving their decision, and can contest, correct, or appeal decisions — and must document all consumer complaints, disputes, corrections, appeals, opt-out requests, and remediation outcomes.
US
Failed
Deployers must provide individuals a means to opt out of the use of a covered algorithm for a consequential action and elect to have the action undertaken by a human, in circumstances and manner to be specified by FTC rulemaking within 2 years of enactment.
WA
Failed
Public agencies must ensure that any decision made or informed by an automated decision system is subject to appeal, immediate suspension if a legal right, duty, or privilege is impacted, and potential reversal by a human decision maker through a clearly described and accessible process not to exceed 20 days.
WA
Failed
Agencies must ensure that any decision made or informed by an automated decision system is subject to appeal, immediate suspension if a legal right, duty, or privilege is impacted, and potential reversal by a human decision maker through a clearly described and accessible process not to exceed 20 days.
H-01.5
Appeal and contestation right
A defined process must exist for the individual to formally contest an automated decision and receive a substantive response explaining the outcome. The process must be accessible without unreasonable burden.
Enacted
6
Live
49
Failed
31
Total
86
CO
Enacted eff 2026-05-14
Deployers must, upon request from a consumer who experienced an adverse outcome from a consequential decision materially influenced by a covered ADMT, provide an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable. Meaningful human review requires a reviewer designated by the deployer who has authority to approve, modify, or override the decision; considers relevant primary evidence; is trained to conduct the review; does not default to the system output; and has access to sufficient information to understand the output's intended use, material limitations, categories of inputs, and principal factors used to generate the output. FERPA-subject deployers may comply through existing student record amendment and appeal processes.
CO
Enacted eff 2026-02-01
Deployers must, following an adverse consequential decision, provide the consumer with (1) a statement disclosing the principal reasons for the decision, including the degree of AI contribution, data types used, and data sources, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review where technically feasible.
CO
Enacted eff 2026-02-01
Deployers must, when a consequential decision made using a high-risk AI system is adverse to the consumer, provide the consumer with: (1) a statement of the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the source(s) of that data; (2) an opportunity to correct any incorrect personal data used in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless an appeal would not be in the consumer's best interest (e.g., where delay might endanger the consumer's life or safety).
CT
CT SB 4 (Consumer Privacy) § Section 14 (amending Conn. Gen. Stat. § 42-518(a))
Enacted eff 2026-10-01
Controllers using automated profiling that produces a decision denying a consumer an employment opportunity must, on consumer request: (1) inform the consumer whether any of the personal data processed for the profiling was submitted by a third party; (2) allow the consumer to correct any incorrect third-party-submitted personal data used in the profiling; and (3) re-evaluate the profiling decision based on the corrected personal data.
VA
Enacted eff 2026-07-01
Deployers must transmit consequential decisions to consumers without undue delay. For adverse decisions based on personal data beyond what the consumer directly provided, deployers must (1) disclose the principal reasons for the decision, including the degree of AI contribution, data types processed, and data sources; (2) provide an opportunity to correct inaccuracies in personal data under the VCDPA; and (3) provide an opportunity to appeal, with human review where technically reasonable and practicable, unless delay would risk the consumer's life or safety.
WA
WA SB 5395 (Health Carrier Prior Authorization AI) § RCW 48.43.535 (as amended by Sec. 6/Sec. 7)
Enacted eff 2026-06-11
Health carriers must allow enrollees to bypass the carrier's internal grievance process and proceed directly to independent review by a certified independent review organization for retrospective denials of prior-authorized services under RCW 48.43.525.
IL
Enrolled
Health insurance issuers must provide physicians with a clear and accessible process for appealing downcoded claims, including written or electronic instructions, contact information for the managing physician, a submission window of no less than 180 days, and adjudication timelines consistent with state utilization review law. Physicians must be permitted to appeal in batches of similar claims without restriction.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must provide subjects with the opportunity within 30 business days after a consequential decision to (1) correct inaccurate personal information used by the ADS, with deployer response within 30 business days, rectification within 30 days if the correction would change the outcome, and explanation if it would not, and (2) appeal the decision outcome, with deployer review within 30 business days, rectification within 30 days if the original decision was incorrect, and explanation of denial basis if the decision is upheld. If a correction request is denied, the deployer must explain the basis and offer deletion of the subject's personal information.
NY
NY SB 1169 (AI Algorithmic Discrimination) § Civ. Rights Law § 86-a
Engrossed
Deployers must inform end users within five days after a high-risk AI system has been used to make a consequential decision. Deployers must provide and explain an appeal process that allows the end user to (1) formally contest the decision, (2) provide supporting information, and (3) obtain meaningful human review. The deployer must respond to appeals within 45 days, extendable once by 45 additional days with notice and reasons. End users are entitled to no more than one appeal per consequential decision in a six-month period.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must, for adverse consequential decisions, provide the consumer with (1) a statement disclosing principal reasons for the decision including the AI system's contribution, data types processed, and data sources; (2) an opportunity to correct incorrect personal data used in the decision; and (3) an opportunity to appeal the decision with human review where technically feasible.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2103
Introduced eff 2026-01-01
Healthcare insurers must provide enrollees a process for contesting outcomes produced by automated decision-making systems.
CT
Introduced eff 2025-10-01
Employers must, when a consequential decision made by or substantially based on a high-risk AI system is adverse to an employee, (1) disclose the principal reasons for the decision including the AI system's degree of contribution, the data types processed, and data sources, (2) allow the employee to examine and correct the personal data processed, and (3) provide an opportunity to appeal inaccurate-data-based decisions with human review.
CT
Introduced eff 2026-10-01
Deployers must, when an automated employment-related decision process makes or substantially factors into an adverse employment-related decision, provide the affected applicant or employee with: (1) a high-level statement disclosing the principal reasons for the adverse decision, including the degree and manner of the process's contribution, the type of data processed, and the source of that data; (2) an opportunity to examine and correct the data used and to appeal the decision with human review if it was based on incorrect data; and (3) upon request, a copy of the most recent bias audit. The high-level statement must be provided directly to the individual, in plain language, in all languages the deployer ordinarily uses in the state, and in a format accessible to individuals with disabilities.
GA
Introduced
Deployers must transmit to the consumer within one business day after an automated consequential decision a notice including: (1) a specific explanation of the principal factors and variables that led to the decision, including the degree and manner of AI contribution, the data sources processed, and a plain-language explanation of how the consumer's personal data informed those factors; (2) information about the consumer's right to correct data and how to submit corrections and supplementary information; (3) what actions the consumer might have taken to secure a different decision and may take in the future; (4) information on opportunities to correct incorrect personal data processed in the decision; and (5) information on opportunities to appeal an adverse decision, which appeal must allow for human review if technically feasible.
HI
HI SB 2167 (Healthcare AI & Prior Authorization) § HRS § 432E-5 (Complaints and appeals procedure for enrollees — amended by Section 5)
Introduced
Health carriers must provide enrollees with a universal external review request form and a clear, step-by-step guide explaining the enrollee's rights and procedures to request an internal appeal or external review upon any adverse determination.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Consequential decisions; notice; statement; opt-out; corrections; appeal)
Introduced eff 2028-07-01
Health care providers that used an AI system to make or substantially factor into a consequential decision must provide the patient or authorized representative with: (1) a written statement describing the consequential decision and its principal reasons, including the degree and manner of the AI system's contribution, the types of data the AI processed, and the sources of that data; (2) an opportunity to correct any incorrect health information or personal data the AI system processed in making the decision; and (3) an opportunity to appeal the consequential decision, including human review of all information relating to the decision to the extent technically feasible. The appeal right does not apply when providing an opportunity for appeal is not in the patient's best interest, including when any delay might pose a risk to the patient's life or safety.
HI
Introduced
Deployers must provide a written response to consumer correction, reconsideration, or human review requests within a reasonable period, including the outcome, an explanation if the adverse action is upheld, and any additional steps available through internal appeal or external rights.
IL
Introduced
Employers must, when using an automated decision-making system for any function covered by Section 10(a): (1) provide notice to each affected employee no later than the time a decision is issued that the decision was made using an automated decision-making system; (2) provide an appeals process for employees directly impacted by decisions made by the system; and (3) offer each affected employee the opportunity for an independent alternative review of the decision by an individual working for or on behalf of the employer, separate from the automated system.
IN
Introduced eff 2026-07-01
Employers must allow covered individuals, after receiving post-decision documentation, to: (i) dispute the automated decision system output in a manner that is accessible, equitable, and does not impose an unreasonable burden, to a human with appropriate and relevant experience; and (ii) appeal the employment-related decision to a human with appropriate and relevant experience who is not the same human who performed the corroboration under clause (E).
LA
Introduced
Employers or vendors that use an ADS to make an employment-related decision must provide the affected worker with a right to appeal that decision, request human review, submit additional information, and correct data errors. The employer or vendor must provide a form or hyperlink to an electronic appeal form within 30 days of the worker's notification. The form must include options to request ADS input/output data, corroborating evidence from the human reviewer, a field for the worker's reason and supporting evidence, and a designation for an authorized representative. The employer or vendor must respond to the appeal within 14 business days by designating a human reviewer who can objectively evaluate all evidence, has sufficient authority, discretion, and resources to evaluate and overturn the decision, and was not involved in the original decision. The response must be a clear written document describing the appeal result and reasons. If the reviewer overturns the decision, the employer or vendor must rectify it within 21 business days.
LA
Introduced
Covered insurers must, upon consumer request within 30 days of an adverse action, assign a qualified human underwriter or claims professional to independently review the decision, complete the review within 30 days, and provide a written explanation. The reviewer must have full authority to modify or reverse the adverse action based on the consumer's specific facts.
LA
Introduced eff 2026-08-01
Health insurance issuers must allow any insured to appeal a coverage determination that the insured has learned was made with a recommendation from AI or an automated decision system.
MA
Introduced
Controllers must establish a conspicuously available appeal process for consumers whose data rights requests are denied, respond in writing within 60 days with a substantive explanation, and provide a mechanism to contact the attorney general if the appeal is denied.
MA
Introduced
Employers must notify employees and candidates at least ten business days before using an automated employment decision tool, disclosing: (1) that the tool will be used, (2) the qualifications and data attributes assessed and outputs produced, (3) data sources and retention policy, (4) the most recent impact assessment results, (5) how to request an alternative non-automated selection process, and (6) how to request reevaluation and the right to file a civil complaint. Notice must be in plain language, included in job postings, posted on the employer's website in all employee-facing languages, provided directly to candidates, and accessible to individuals with disabilities.
MA
Introduced
Deployers must (1) notify consumers when an AI system materially influences a consequential decision, (2) provide consumers with the purpose of the system and an explanation of how the system influenced the decision, and (3) provide a process to appeal or correct adverse decisions.
MA
Introduced
Deployers must, when a consequential decision is adverse to the consumer, provide: (1) a statement disclosing the principal reasons for the decision, including the degree and manner of the AI system's contribution, the type of data processed, and the sources of that data; (2) an opportunity to correct any incorrect personal data the system processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless the appeal would not be in the consumer's best interest (e.g., where delay poses a risk to the consumer's life or safety).
MD
MD HB 795 (AI Health Insurance Accountability) § Md. Code Ann., Insurance § 15–10A–02(b)(2)
Introduced eff 2026-10-01
Carriers must ensure that their internal grievance process provides for human review of any adverse decision made using artificial intelligence, an algorithm, or other software tools when a member files a grievance challenging that decision. The human review must include an assessment of whether the AI tool complied with § 15–10B–05.1, which requires individualized clinical data inputs, prohibits sole reliance on group datasets, and imposes non-discrimination and oversight requirements.
MN
Introduced
Employers must provide each worker affected by an ADS-informed employment decision with a form or link to appeal the decision. The appeal form must include options to request ADS input/output data and human reviewer corroborating evidence, space for the worker's reasons and supporting evidence, and information on designating an authorized representative. Workers must file appeals within 30 days of post-use notification. Employers must respond within five business days by assigning a human reviewer who: objectively evaluates all evidence, has authority and training to evaluate the decision (including ADS limitations and worker rights), has authority to overturn the decision, and was not involved in the original decision. The reviewer must produce a written document explaining the appeal result and reasoning, provided to both the employer and worker. If the decision is overturned, the employer must rectify it within five business days.
MN
Introduced
Employers must provide workers with a form to appeal any employment-related decision based on electronic monitoring data. The employer must respond within five business days by designating an independent human reviewer — not involved in the original decision, with authority to overturn it — who must produce a written decision with reasoning. If overturned, the employer must rectify the decision within five business days.
MN
Introduced eff 2027-01-01
Employers must provide workers with a structured appeal form when monitoring data was used in an employment-related decision, respond within five business days by designating an independent, qualified human reviewer with authority to overturn the decision, produce a written decision with reasons, and rectify any overturned decision within five business days.
MN
Introduced eff 2027-01-01
Employers must provide workers with a form to appeal any employment-related decision made using an automated decision system. Within five business days of receiving an appeal, the employer must designate an independent human reviewer — not involved in the original decision, with authority to overturn it — who must objectively evaluate all evidence, produce a written decision explaining the result and reasons, and if the decision is overturned, the employer must rectify it within five business days.
NJ
Introduced
Employers must notify each covered individual within 30 days of use that an automated employment decision tool was used, disclose the job qualifications or characteristics assessed, the data sources, the employer's data retention policy, the tool name and vendor, and — if the outcome was adverse — provide a written statement of specific reasons and sufficient disclosures to enable the individual to contest the employment decision.
NJ
Introduced
If a recognized bargaining representative raises compliance concerns within 30 days of receiving notice, the employer or public entity must halt implementation and provide a written response addressing the concerns — including any agreed modifications or a compliance explanation — before proceeding. If the representative is not satisfied, they may pursue administrative, civil, or grievance remedies.
NJ
Introduced
Employers and public entities must provide at least 10 days' advance written notice before any adverse AI-assisted employment or public-benefit decision takes effect, explaining the reasons, providing access to all data, and informing the individual of appeal rights. Upon request within 30 days, the employer must (1) allow the individual to review and copy all data and receive a complete explanation of how the AEDS or ABSDS produced its outputs including factor weighting, (2) allow the individual to appeal on grounds of data inaccuracy, bias, or legal violations, and (3) designate a qualified human reviewer with authority and discretion to modify or overturn the decision. For applicants, notice must be provided no later than the time of the decision.
NJ
Introduced
Employers and public entities must not implement a system after a bargaining representative raises specific compliance concerns within 30 days until they provide a written response adopting any needed modification or explaining why none is necessary.
NJ
Introduced
On request within 30 days, employers and public entities must let the individual review and copy the decision data, personnel files, impact-assessment and oversight records, and factor-weighting explanation; permit an appeal to correct inaccurate or biased data and contest the decision; and designate a qualified, empowered human reviewer with authority to modify or overturn it who issues the final internal determination.
NM
Introduced eff 2026-07-01
Deployers must provide consumers an opportunity to appeal any adverse consequential decision, and the appeal must be reviewed by a human being.
NY
NY AB 10764 (Utility Billing Integrity Act) § Pub. Serv. Law § 65-c(6)
Introduced
Utilities must, upon a residential customer's request for billing review, (1) suspend all adverse actions including late fees, collections, and service termination, (2) conduct a review including qualified human personnel review and error correction, and (3) provide a written determination to the customer within ten business days.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 508
Introduced
Persons developing and deploying automated systems must provide New York residents with access to a timely human consideration and remedy through a fallback and escalation process if an automated system fails, produces an error, or if the resident wishes to appeal or contest the system's impacts. The fallback process must be accessible, equitable, effective, maintained, accompanied by appropriate operator training, and must not impose an unreasonable burden on the public.
NY
Introduced
Banks must provide loan applicants denied based on incorrect personal information a 30-day period to correct the information and appeal the denial.
NY
Introduced
When a high-risk AI decision system has been used to make or substantially factor into an adverse consequential decision concerning a consumer, the deployer must provide the consumer: (1) a statement disclosing the principal reasons for the adverse decision, including the degree and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data the system processed; and (3) an opportunity to appeal the adverse decision, which must include human review if technically feasible, unless human review would not be in the consumer's best interest (e.g., where delay poses a risk to life or safety).
NY
Introduced
Covered entities must allow applicants whose loan applications were denied based on incorrect personal information to correct the information and appeal the denial within 30 days of receiving the denial notice.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 108
Introduced
Covered deployers must, within ten days of a consequential decision, notify the subject that a high-risk AI system was used and provide an appeal process allowing the subject to (1) contest the decision, (2) submit supporting information, and (3) obtain meaningful human review, responding within forty-five days (extendable once).
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 108
Introduced
Deployers must, once Division regulations are promulgated (within two years of the effective date), provide individuals a mechanism to appeal to a human any consequential action resulting from the deployer's use of a covered algorithm. The appeal mechanism must be clear and conspicuous, in plain language, easy to execute, at no cost, proportionate to the consequential action, reasonably accessible to individuals with disabilities, timely, usable, effective, and non-discriminatory. Where appropriate, the mechanism must allow individuals to identify and correct personal data used by the algorithm. Human reviewers must meet Division-specified training requirements.
NY
Introduced
Employers must provide written notice at least 14 calendar days before any employment decision based on monitoring data or AEDT output takes effect, disclosing performance standards, the employee's monitored data, aggregated peer data for the prior 90 days, AEDT outputs, the most recent impact assessment, and all non-monitoring information used. Employees may request reevaluation in writing (including text or email) by identifying the disputed data or output and providing supporting evidence. Employers must investigate and respond within seven calendar days, providing evidence of accuracy or correcting the data and reevaluating the decision without the flawed input.
NY
Introduced
Deployers must, when a high-risk AI decision system makes or substantially factors into an adverse consequential decision concerning a consumer, provide the consumer with: (1) a statement disclosing the principal reasons for the adverse decision, including the degree to which and manner in which the AI system contributed, the type of data processed, and the source of that data; (2) an opportunity to correct any incorrect personal data processed in making the decision; and (3) an opportunity to appeal the adverse decision, which must allow for human review if technically feasible, unless providing such opportunity would not be in the consumer's best interest (e.g., delay posing life or safety risk).
NY
Introduced
Covered entities must provide loan applicants denied based on incorrect personal information a 30-day window to correct the information and appeal the denial.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must, when a consequential decision is adverse to a consumer, (1) explain the principal reasons including the degree and manner of AI contribution, data types, and data sources, (2) allow the consumer to examine and correct personal data used, and (3) provide an opportunity to appeal based on inaccurate personal data with human review where technically feasible. All notices must be provided directly to the consumer, in plain language, in all languages the deployer ordinarily uses, and in formats accessible to consumers with disabilities.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must, when a high-risk AI system has made or been a substantial factor in making an adverse consequential decision concerning a consumer, provide the consumer with: (1) a statement disclosing the principal reasons for the decision, including the degree to which and manner in which the AI system contributed, the type of data processed, and the source(s) of that data; (2) an opportunity to correct any incorrect personal data that the AI system processed in making the decision; and (3) an opportunity to appeal the adverse decision, which appeal must, if technically feasible, allow for human review — unless providing the appeal opportunity is not in the consumer's best interest (e.g., where delay might pose a risk to the consumer's life or safety).
US
Introduced
Covered entities must evaluate and document consumer rights with respect to covered algorithms, including (1) whether consumers receive clear notice that an algorithm will be used, (2) whether consumers have an opt-out mechanism, (3) the transparency and explainability of the algorithm, (4) any mechanisms for consumers to contest, correct, or appeal a decision, and (5) the extent to which third-party decision recipients access algorithm results.
US
Introduced
Deployers must, once FTC regulations are promulgated (within 2 years of enactment), provide individuals a mechanism to appeal to a human any consequential action resulting from the deployer's use of a covered algorithm, including the ability to identify and correct personal data used by the algorithm.
US
Introduced
Employers must enable covered individuals to (1) dispute the ADS output to a human with appropriate and relevant experience via an accessible, equitable, and non-burdensome process, and (2) appeal the employment-related decision to a different human with appropriate and relevant experience than the one who corroborated the ADS output.
US
Introduced
Covered entities must evaluate the extent to which they provide consumers with (1) clear notice of automated decision system use, (2) a mechanism for opting out, (3) transparency and explainability regarding contributing factors, (4) the ability to contest, correct, or appeal decisions, and (5) documentation of complaints and remediation outcomes. Covered entities must also document the categories of third-party decision recipients receiving decision results.
US
Introduced
Deployers must, pursuant to FTC regulations to be promulgated within two years of enactment, provide individuals a mechanism to appeal algorithmic consequential actions to a human reviewer. The mechanism must be accessible, proportionate, and include data correction capabilities and trained reviewers.
VT
Introduced eff 2025-07-01
Deployers must provide and explain a process for consumers to appeal a consequential decision. The appeal process must allow the consumer to formally contest the decision, provide supporting information, and obtain meaningful human review. The deployer must designate a human reviewer who is trained and qualified, free of conflicts of interest, was not involved in the initial decision, is protected from retaliation for exercising their review functions, and is allocated sufficient resources. The human reviewer must consider the consumer's information and may consider other relevant sources. The deployer must respond within 45 days, extendable once by an additional 45 days with notice and explanation of the delay.
AK
Failed
State agencies must provide an appeals process that includes manual human review for any individual legally or significantly affected by a generative AI consequential decision.
CO
Failed eff 2025-05-05
Deployers must, within 30 days after an adverse consequential decision, provide a single notice disclosing the main reasons for the decision (including the AI system's contribution and the categories and sources of data that adversely affected the output, including sensitive data), information on how to exercise correction and appeal rights, and a copy of the notice. Deployers must offer an opportunity to correct incorrect personal data. For non-competitive, non-time-limited adverse decisions based on incorrect data or unlawful information, deployers must provide an opportunity to appeal with human review if technically feasible. The correction and appeal rights apply only to systems that are the principal basis of the decision.
CT
Failed
Deployers must, before making a consequential decision using a high-risk AI system, notify the consumer that AI is being used, disclose the system's purpose and the nature of the decision, offer opt-out rights, and provide contact information and a plain-language system description. If the decision is adverse, the deployer must disclose the principal reasons (including AI's contribution and the data types and sources used), provide an opportunity to examine and correct personal data, and offer an appeal with human review where technically feasible. All notices must be in plain language, multilingual, accessible, and delivered directly to the consumer.
HI
Failed
Covered entities must, upon taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure that includes (1) the entity's contact information, (2) the factors the determination depended on, and (3) an explanation that the individual may access any personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
HI
Failed
Covered entities must, upon taking any adverse action based on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's right to access their personal information used in the determination, submit corrections, and request a human-conducted reevaluation based on corrected data.
HI
Failed
Covered entities must, when taking any adverse action based in whole or in part on an algorithmic eligibility determination, provide the individual a written or electronic disclosure identifying (1) the covered entity's contact information, (2) the factors the determination depended on, and (3) the individual's rights to access personal information used, submit corrections, and request a reasoned human reevaluation based on corrected data.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must provide consumers subject to a high-risk AI system the opportunity to (1) correct any data used by the system in making a decision about the consumer, and (2) appeal an adverse decision, including human review. A deployer may decline to provide appeal where the delay would pose a risk to the consumer's safety.
NE
Failed
Deployers must, for each high-risk AI system that makes or is a substantial factor in making an adverse consequential decision concerning a consumer, provide to that consumer: (1) a statement disclosing each principal reason for the decision, including the degree and manner in which the AI system contributed to the decision, the type of data processed, and each source of that data; (2) an opportunity to correct any incorrect personal data that the system processed in making or contributing to the decision; and (3) an opportunity to appeal the adverse decision, unless an appeal is not in the consumer's best interest (e.g., where delay would risk life or safety), with human review if technically feasible. All notices, statements, and descriptions must be provided directly to the consumer, in plain language, in each language the deployer ordinarily uses in business communications, and in a format accessible to consumers with disabilities. If direct provision is not possible, the deployer must make the information available in a manner reasonably calculated to ensure the consumer receives it.
NM
Failed
Deployers must, after an adverse consequential decision, provide the consumer with (1) an explanation of the principal reasons, the degree and manner of AI contribution, and the source and type of data processed, (2) an opportunity to correct incorrect personal data, and (3) an opportunity to appeal with human review if technically feasible.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing or deploying automated systems must provide New York residents with access to a timely, accessible, equitable, and effective human consideration and remedy process — including fallback and escalation — when a system fails, produces an error, or a resident wishes to appeal or contest the system's impact. The process must be accompanied by appropriate operator training and must not impose an unreasonable burden on the public.
NY
Failed
Employers must provide employees and candidates a meaningful opportunity to request reevaluation of AEDT-informed employment decisions within 30 days of the decision, where the individual believes the decision resulted from inaccuracy, error, bias, sole reliance on the tool, or other violation and was meaningfully harmed.
NY
Failed
Employers must respond in writing within 60 days to reevaluation requests, providing the AEDT outputs used, a description of non-AEDT information that contributed to the decision, the employer's assessment of the complaint (with supporting evidence if disputed), reprocessing results if requested, and an explanation for any refusal to take remedial action.
NY
Failed
Employees who believe an employment decision resulted from inaccurate monitoring data or an erroneous AEDT output may request reevaluation in writing. Employers must investigate and respond within seven calendar days. If inaccuracy is confirmed, the employer must inform the employee in writing and reevaluate using corrected data or without the AEDT. If the employer finds no inaccuracy, it must provide the employee with evidence of accuracy and validity.
NY
Failed
Employers must offer employees and candidates a meaningful opportunity to request reevaluation of any employment decision made or assisted by an AEDT, where the person believes the decision resulted from inaccuracy, error, bias, sole reliance on the tool, or other statutory violation, and was meaningfully harmed. The written request must be submitted within thirty days of the decision and must include the person's identity, the decision at issue, the harm suffered, the basis for the belief, supporting evidence, and requested remedial action.
NY
Failed
Employers must respond in writing within sixty days to a reevaluation request, disclosing: the AEDT outputs used in the decision, non-AEDT information that contributed, whether the employer agrees with the complaint and why, evidence supporting the tool's accuracy if the employer disagrees, reprocessing results if requested, and the reason for refusing any requested remedial action.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing automated systems must provide residents with access to a timely, accessible, equitable, and effective human-consideration and remedy process through a fallback and escalation mechanism when systems fail, produce errors, or when residents wish to appeal or contest outcomes. The process must be accompanied by operator training and must not impose an unreasonable burden on the public.
OK
Failed
Deployers must notify affected individuals when high-risk AI systems influence decisions about them and provide avenues for appeal or human review.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.108
Failed
Deployers must provide consumers the right to appeal adverse consequential decisions made by high-risk AI systems and to obtain clear and meaningful explanations of the AI system's role in the decision and the main elements of the decision taken.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of automated decision system use, have a mechanism to opt out, can access information about the factors contributing to a decision, and can contest, correct, or appeal a decision, and must document all complaints, disputes, and remediation outcomes.
US
Failed
Covered entities must evaluate consumer rights in the impact assessment, including assessing whether consumers receive clear notice that an automated system will be used, whether a mechanism for opting out exists, the transparency and explainability of the system, and the degree to which consumers may contest, correct, or appeal decisions.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3593
Failed
The OMB Director must issue guidance requiring agencies to review and modify their appeals processes to account for AI-assisted determinations and to provide impacted individuals the opportunity for alternative review independent of the AI system.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must modify the agency's appeals process to account for AI-assisted determinations and provide impacted individuals the opportunity for alternative review independent of the AI system.
US
Failed
Employers must enable covered individuals to (1) dispute the automated decision system output to a qualified human reviewer in an accessible manner and (2) appeal the employment-related decision to a different qualified human reviewer than the one who corroborated the original output.
US
Failed
Employers must enable the covered individual, after receiving post-decision documentation, to (1) dispute the automated decision system output to a qualified human reviewer in an accessible, equitable manner, and (2) appeal the employment-related decision to a different qualified human reviewer who was not the corroborating reviewer.
US
Failed
Covered entities must evaluate consumer rights as part of the impact assessment, including assessing whether consumers receive clear notice of system use, have an opt-out mechanism, can access information about factors driving their decision, and can contest, correct, or appeal decisions — and must document all consumer complaints, disputes, corrections, appeals, opt-out requests, and remediation outcomes.
US
Failed
Covered entities must evaluate consumer rights with respect to the automated decision system, including: (1) whether consumers receive clear notice that the system will be used, (2) whether consumers can opt out, (3) the transparency and explainability of the system including which contributing factors drive decisions, (4) consumer contestation, correction, and appeal mechanisms, and (5) the extent to which third-party decision recipients access decision results.
US
Failed
Deployers must provide individuals a mechanism to appeal to a human any consequential action resulting from the deployer's use of a covered algorithm, in circumstances and manner to be specified by FTC rulemaking within 2 years of enactment. The appeal mechanism must be clear, conspicuous, accessible to individuals with disabilities, and at no cost.
VA
Failed
The Department of Human Resource Management must establish and publicize a process for applicants and employees to file concerns and complaints about the use of automated decision systems in the Commonwealth's employment decisions, and a process for investigation and resolution of those complaints. This process must be separate from the existing dispute resolution process under § 2.2-1202.1.
VA
Failed
Local government entities that use an automated decision system as a substantial factor in employment decisions must establish and publicize a process for applicants and employees to file concerns and complaints about the use of automated decision systems and a process for investigation and resolution of those complaints.
WA
Failed
Public agencies must ensure that any decision made or informed by an automated decision system is subject to appeal, immediate suspension if a legal right, duty, or privilege is impacted, and potential reversal by a human decision maker through a clearly described and accessible process not to exceed 20 days.
WA
Failed
Agencies must ensure that any decision made or informed by an automated decision system is subject to appeal, immediate suspension if a legal right, duty, or privilege is impacted, and potential reversal by a human decision maker through a clearly described and accessible process not to exceed 20 days.
H-01.6
Mandatory pre-action human sign-off
Before action is taken on an AI recommendation in defined high-stakes contexts, a qualified human reviewer must affirmatively review and authorize the decision. The human must have authority and practical ability to override — not merely ratify — the AI output.
Enacted
3
Live
64
Failed
43
Total
110
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-502
Enacted eff 2024-10-01
Law enforcement agencies must ensure FRT results never serve as the sole basis for probable cause or positive identification — independently obtained corroborating evidence is always required.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Enacted eff 2024-10-01
Law enforcement agencies must ensure that every FRT result is independently verified by a trained individual before the result is used for any purpose in a criminal investigation.
VA
Enacted eff 2025-07-01
Judicial officers and other authorized decision-makers must make all criminal justice decisions — including pre-trial detention or release, prosecution, adjudication, sentencing, probation, parole, correctional supervision, and rehabilitation — with human decision-maker involvement. No such decision may be made solely by an artificial intelligence-based tool, and any AI-generated recommendation or prediction must remain subject to challenge or objection permitted by law.
IL
Enrolled
Health insurance issuers must ensure that all downcoding appeals are reviewed by a physician who is (1) licensed to practice medicine in all its branches, (2) of the same or similar specialty as the treating physician, (3) experienced in the relevant health care services, (4) independent from the original downcoding decision, and (5) performs a documented review of all clinical information and medical records supporting the billed service.
CA
CA SB 947 (Workplace ADS) § Lab. Code § 1522
Engrossed
Employers must not rely solely on an ADS when making a disciplinary, termination, or deactivation decision. When an employer uses ADS output to assist in such a decision, the employer must direct a human reviewer to conduct an independent investigation and compile corroborating or supporting information — which may include supervisory evaluations, personnel files, work product, peer reviews, and witness interviews. If the employer cannot corroborate the ADS output, or the human reviewer concludes the output is inaccurate, incomplete, or misleading, the employer must not use the ADS output to discipline, terminate, or deactivate the worker.
NY
NY SB 8451 (FAIR News Act) § Gen. Bus. Law § 1154
Engrossed
News media content created in whole or in material part by generative AI must be reviewed by a human worker who has authority to approve, deny, or modify any decision recommended or made by the AI system before that content may be published.
CA
Introduced
The commission's standards must establish requirements for human review and approval for the deployment and use of AI models by electrical and gas corporations, including specifying where human review must be placed in the deployment workflow.
CA
Introduced
The commission's standards must require human review and approval for any AI model that (1) makes or directly implements operational decisions affecting utility infrastructure without a mandatory human approval step, (2) generates auto-implemented recommendations without case-by-case human review, or (3) performs acts that could foreseeably result in physical harm, service interruption, or public safety impact. Reviewing staff must have relevant expertise, sufficient information and time, unimpeded authority to reject or modify the AI output, and freedom from workflow pressure that renders rejection impractical.
CT
Introduced eff 2025-10-01
Employers must designate at least one internal reviewer with AI operational expertise, familiarity with the most recent impact assessment, understanding of the system's data processing, authority to change or influence AI outputs, and adequate time and resources to evaluate outputs. The internal reviewer must verify the accuracy of employee data inputs and consider the AI system's outputs.
CT
Introduced eff 2026-10-01
Deployers must implement human review over every automated employment-related decision process used to make or substantially factor into employment-related decisions. A qualified human reviewer — with authority to make or change decisions and understanding of the process's biases and limitations — must review the AI output and, when appropriate, modify or veto it prior to any adverse decision. Deployers must establish procedures to pause, correct, or reverse erroneous or harmful outputs, and must maintain logs of all human review reports and interventions. No automated employment-related decision process may be used for a final or determinative employment-related decision without human review.
GA
Introduced
Persons using AI or automated decision tools in determinations about the sale, rental, or financing of dwellings, or in brokerage services, must ensure an individual responsible for the determination participates in or reviews each determination.
HI
HI SB 2281 (AI in Health Care) § HRS § 321-__ (Consequential decisions; review and validation by qualified oversight personnel)
Introduced eff 2028-07-01
Health care providers that use AI to make or substantially factor into consequential decisions must maintain AI oversight personnel. The oversight personnel must be a natural person with the qualifications, experience, and expertise necessary to evaluate AI outputs in health care (including predictions, scoring, recommendations, decisions, and conclusions). The oversight personnel may be a third-party contractor. The oversight personnel must (1) monitor the health care provider's AI systems, and (2) before any AI output is used to make or substantially factor into a consequential decision, review and evaluate the output and either validate or override it.
HI
Introduced
Deployers must implement a reasonable process by which consumers may (1) request correction of inaccurate personal information used in a consequential decision, (2) submit additional information for reconsideration, and (3) obtain human review of an adverse action by a reviewer with authority to overturn the decision and subject-matter-relevant training. Narrow exceptions apply when human review would conflict with law or compromise security, but the deployer must document the basis and offer an alternative dispute channel.
IA
Introduced
Employers must not rely solely on an automated decision system when making a discipline, termination, or deactivation decision.
IA
Introduced
When an employer relies primarily on output from an automated decision system to make a discipline, termination, or deactivation decision, the employer must use a human reviewer to review the automated decision system output and compile and review other relevant information, which may include supervisory or managerial evaluations, personnel files, employee work product, peer reviews, and witness interviews (including relevant online customer reviews).
IL
Introduced
Health care entities must prohibit staffing, triage, admission, discharge, or transfer decisions that rely solely on AI. Human clinical review by a registered professional nurse is required for all such decisions.
IL
Introduced
Employers must ensure meaningful and continuing human review whenever an automated decision-making system is used — directly or indirectly — to perform any function related to public assistance administration, any function that will adversely impact employee rights, civil liberties, safety, or welfare, or any function affecting employees' statutory or constitutional rights. The human reviewer must understand the system's risks and limitations, be trained on the system, have authority to intervene or override outputs suspected of being invalid, inaccurate, or discriminatory (and must reject outputs that cannot be independently corroborated), and have adequate time and resources for review. This prohibition also extends to procurement, purchase, or acquisition of any service or system relying on an automated decision-making system for these functions.
IL
Introduced
Health care entities must prohibit staffing, triage, admission, discharge, or transfer decisions that rely solely on AI, and must require human clinical review by a registered professional nurse for all such decisions.
IN
Introduced eff 2026-07-01
Employers must not rely exclusively on an automated decision system in making any employment-related decision with respect to a covered individual. Every such decision must involve human judgment beyond the automated system's output.
IN
Introduced eff 2026-07-01
Employers must independently corroborate every automated decision system output through meaningful oversight by a human with appropriate and relevant experience before using it in an employment-related decision. The human must have the authority and ability to override the automated output.
LA
Introduced
Employers must not rely solely on an ADS when making a discipline, termination, or deactivation decision. A human must be involved in the decision.
LA
Introduced
Employers or vendors utilizing ADS output to assist in employment-related decisions must: (1) ensure the accuracy of the ADS output; (2) assign a designated internal reviewer to conduct a separate investigation and compile corroborating information (e.g., supervisory evaluations, personnel files, employee work products, peer reviews); and (3) ensure the reviewer has sufficient authority, discretion, resources, and time to corroborate output, sufficient expertise in similar systems and the ADS in question to interpret outputs and impact assessments, and sufficient education, training, or experience to make a well-informed decision. The reviewer must be protected from retaliation. Employers must not rely on ADS output to make an employment-related decision if the output cannot be corroborated or the human reviewer has concluded the output is inaccurate, incomplete, or misleading.
LA
Introduced
Covered insurers must not generate a final claims payment determination using an ADS without human review and approval by a licensed claims professional who has authority to override the algorithmic determination, access to the specific factors driving it, and who documents the basis for each approval, modification, or override.
LA
Introduced eff 2026-08-01
Health insurance issuers must be prepared to demonstrate, for any adverse determination in which AI or an automated decision system materially contributed, that the determination was independently reached through documented clinical judgment without reliance upon algorithmic output. Any such adverse determination is presumed invalid unless this showing is made.
LA
Introduced eff 2026-08-01
When an adverse determination is appealed on the basis of AI or automated decision system use, the insurer must not use any AI or automated decision system in any subsequent review of that claim.
MA
Introduced
Employers must not rely primarily on electronically-monitored data when making hiring, promotion, disciplinary, termination, or compensation decisions. Employers must establish meaningful human oversight, designate a human decision-maker who actually reviews the monitoring data for accuracy, reviews pending correction requests, exercises independent judgment, and considers non-monitoring information such as supervisory evaluations, personnel files, work products, or peer reviews.
MA
Introduced
Employers must not rely primarily on automated decision tool output for hiring, promotion, termination, disciplinary, or compensation decisions. Employers must establish meaningful human oversight with a qualified internal reviewer who actually reviews tool outputs, exercises independent judgment, and considers non-ADS information such as supervisory evaluations, personnel files, work products, or peer reviews.
MA
Introduced
Employers must not rely primarily on employee data collected through electronic monitoring when making hiring, promotion, disciplinary (including termination), or compensation decisions. To satisfy this requirement, employers must: (1) establish meaningful human oversight of such decisions — including designating at least one internal reviewer with sufficient expertise, familiarity with the most recent impact assessment, and understanding of tool outputs to identify biases, errors, discrepancies, or inaccuracies; (2) ensure a human decision-maker actually reviews the monitoring data, verifies its accuracy and currency, reviews any pending correction requests, and exercises independent judgment; and (3) require the human decision-maker to consider information beyond monitoring data, such as supervisory evaluations, personnel files, employee work products, or peer reviews.
MA
Introduced
Employers must not rely primarily on automated decision tool output when making hiring, promotion, termination, disciplinary, or compensation decisions. To satisfy this requirement: (1) employers must establish meaningful human oversight, considering the tool's complexity, the reviewer's experience and training, preparation time, and feasibility of expert consultation; (2) a human decision-maker must actually review each automated output and exercise independent judgment; (3) the human must consider non-automated information such as supervisory evaluations, personnel files, work products, or peer reviews; and (4) the employer must consider non-automated information in each such decision. Employers must not require employee or candidate consent to automated tool use as a condition of being considered for an employment decision, and must not discipline or disadvantage anyone for requesting accommodation.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must require all automated evaluations to be subject to human review within 24 hours before a decision is final, and must provide an expedited review process with human review within 48 hours after a consumer submits a review request.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must subject at least 10% of all algorithmic evaluations to random human review to prevent false positives.
MN
Introduced
Employers must never rely solely on an automated decision system when making an employment-related decision. When relying in part on an ADS, the employer must: (1) ensure the accuracy of the ADS output; and (2) assign a designated internal reviewer to investigate and compile corroborating information. The reviewer must have sufficient authority, discretion, resources, and time to corroborate ADS output; expertise in similar systems sufficient to interpret outputs and impact assessment results; training on ADS limitations, biases, and worker rights; and protection from retaliation. If the employer cannot corroborate the ADS output or the reviewer concludes it is inaccurate, incomplete, or misleading, the employer must not rely on the ADS for the employment-related decision.
MN
Introduced
Employers must not take any adverse action against a worker based on data from a continuous time-tracking tool, except in cases of egregious misconduct.
MN
Introduced
Employers must not rely solely on an electronic monitoring tool for employment-related decisions. When relying in part on monitoring data, employers must (1) ensure data accuracy and (2) designate a qualified internal human reviewer — with authority, expertise, training on monitoring-tool limitations and worker rights, and retaliation protection — to corroborate the monitoring data before the decision is made. If the data cannot be corroborated or is found inaccurate, incomplete, or misleading, the employer must not rely on it.
MN
Introduced eff 2027-01-01
Employers must not rely solely on electronic monitoring tool data when making employment-related decisions and must use a qualified designated internal reviewer — with sufficient authority, expertise, training on monitoring tool biases and worker rights, and retaliation protection — to corroborate the data before acting. If the data cannot be corroborated or is found inaccurate, incomplete, or misleading, the employer must not rely on it.
MN
Introduced eff 2027-01-01
Employers must not rely solely on an automated decision system for any employment-related decision. When relying in part on such a system, employers must (1) ensure the accuracy of the output and (2) designate a qualified internal reviewer with sufficient authority, expertise, and training to corroborate the output using independent evidence. If the reviewer cannot corroborate the output or finds it inaccurate, incomplete, or misleading, the employer must not rely on the system for that decision.
MO
Introduced
Employers must not take adverse employment action against an employee for failure to meet a work performance standard that violates the prohibited-standard restrictions, was not properly disclosed, is based solely on peer-ranking, is based on continuous time-increment tracking, or is based primarily on work speed data collected through automated electronic monitoring.
NJ
Introduced
Employers must not take adverse employment action against an employee based solely on data collected via continuous incremental time-tracking tools such as keystroke logging, idle-time trackers, or mouse-movement monitors.
NJ
Introduced
Employers and public entities must provide at least 10 days' advance written notice before any adverse AI-assisted employment or public-benefit decision takes effect, explaining the reasons, providing access to all data, and informing the individual of appeal rights. Upon request within 30 days, the employer must (1) allow the individual to review and copy all data and receive a complete explanation of how the AEDS or ABSDS produced its outputs including factor weighting, (2) allow the individual to appeal on grounds of data inaccuracy, bias, or legal violations, and (3) designate a qualified human reviewer with authority and discretion to modify or overturn the decision. For applicants, notice must be provided no later than the time of the decision.
NJ
Introduced
Employers and public entities must not base any employment or public-benefit decision exclusively or determinatively on AEDS, ABSDS, or EMT outputs. They must establish meaningful human oversight including: (1) designated internal reviewers trained in the AI system's operation who can identify errors, biases, and inaccuracies; (2) reviewer authority to dispute, revise, or reject AI outputs; (3) a requirement that human decision-makers exercise independent judgment and consider non-AI information (supervisory evaluations, personnel files, peer reviews) for consequential decisions; and (4) adequate time, resources, and direct communication availability for reviewers.
NJ
Introduced
On request within 30 days, employers and public entities must let the individual review and copy the decision data, personnel files, impact-assessment and oversight records, and factor-weighting explanation; permit an appeal to correct inaccurate or biased data and contest the decision; and designate a qualified, empowered human reviewer with authority to modify or overturn it who issues the final internal determination.
NJ
Introduced
Employers and public entities must not base any employment or public-benefit decision solely or determinatively on EMT/surveillance data, AEDS/ABSDS outputs, or third-party/data-broker information; such data must be corroborated by designated internal reviewers and remain subject to challenge by the affected individual.
NJ
Introduced
Employers and public entities must establish meaningful human oversight for all such decisions, designating trained internal reviewers with authority to dispute, revise, or reject outputs found inaccurate, discriminatory, or invalid, requiring a human decision-maker to exercise independent judgment and consider information beyond the system outputs, and giving reviewers adequate time, resources, and availability to communicate directly with affected individuals.
NY
Introduced
Employers must not rely solely on ADS output for discipline, termination, or deactivation decisions. When ADS output is the primary basis for such decisions, a human reviewer must review the ADS output and compile and review other relevant information (including supervisory evaluations, personnel files, work product, peer reviews, and witness interviews). Customer ratings may not be used as the only or primary ADS input for any employment-related decision.
NY
NY AB 10764 (Utility Billing Integrity Act) § Pub. Serv. Law § 65-c(3)
Introduced
Utilities must not issue any residential bill flagged as containing a billing anomaly as a final charge until qualified personnel have reviewed the anomaly and corrected any identified error.
NY
NY AB 10764 (Utility Billing Integrity Act) § Pub. Serv. Law § 65-c(10)
Introduced
Utilities must not make fully automated adverse billing determinations. All final determinations regarding disputed or anomalous bills must be subject to human review.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 508
Introduced
Persons developing and deploying automated systems intended for use in sensitive domains — including criminal justice, employment, education, and health — must additionally (1) tailor the system to its purpose, (2) provide meaningful access for oversight, (3) include training for residents interacting with the system, and (4) incorporate human consideration for adverse or high-risk decisions.
NY
Introduced
Employers must not solely rely on AEDT output when making hiring, promotion, termination, disciplinary, or compensation decisions. Employers must establish meaningful human oversight that requires consideration of non-AEDT information — including supervisory or managerial evaluations, personnel files, employee work products, or peer reviews.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 108
Introduced
Covered deployers must conduct meaningful human review — by a trained individual with authority to approve, deny, or modify the outcome — of each consequential decision made with a high-risk AI system.
NY
NY AB 8962 (FAIR News Act) § Gen. Bus. Law § 1154
Introduced
Any news media content created in whole or in material part by generative AI must be reviewed by a human worker before publication. The human reviewer must have authority to approve, deny, or modify any decision recommended or made by the automated system.
NY
Introduced
Employers must ensure that a qualified human reviewer with authority to modify or overturn the automated system's output conducts a deliberate evaluation of that output before making any final or adverse employment decision based on automated resume screening or applicant evaluation.
NY
Introduced
Employers must not deny employment to any applicant solely on the basis of an automated system's action, and must ensure that all automated recommendations, scores, rankings, and filters are subject to human evaluation and override authority.
NY
Introduced
Employers must not solely rely on AEDT output when making hiring, promotion, termination, disciplinary, or compensation decisions. Employers must establish meaningful human oversight requiring consideration of information beyond AEDT outputs, including supervisory evaluations, personnel files, employee work products, or peer reviews.
NY
Introduced
Employers must not rely primarily on electronically monitored data when making hiring, promotion, termination, disciplinary, or compensation decisions. Employers must establish meaningful human oversight, designate a qualified internal reviewer who actually reviews monitored data, verifies accuracy, reviews pending correction requests, and exercises independent judgment, and must ensure the decision-maker considers information beyond electronic monitoring outputs.
NY
Introduced
Employers must not rely primarily on AEDT output when making hiring, promotion, termination, disciplinary, or compensation decisions. Employers must establish meaningful human oversight, ensure a human decision-maker actually reviews AEDT output and exercises independent judgment, and require the decision-maker to consider information beyond AEDT outputs such as supervisory evaluations, personnel files, employee work products, or peer reviews.
OK
Introduced eff 2025-11-01
Deployers must ensure that the qualified end-user retains authority to amend or overrule AI device outputs based on their professional judgment. Deployers and all other entities are prohibited from pressuring qualified end-users to ignore or alter their professional judgment regarding AI device outputs.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not rely primarily on employee data collected through electronic monitoring when making hiring, promotion, disciplinary (including termination), or compensation decisions. Employers must establish meaningful human oversight of such decisions, including: (1) designating at least one internal reviewer with sufficient ADS expertise, familiarity with the most recent impact assessment, and understanding of system outputs to identify biases, errors, and inaccuracies; (2) granting the reviewer authority to dispute, rerun, or recommend rejection of outputs suspected to be invalid, inaccurate, or discriminatory; and (3) ensuring the reviewer has sufficient time and resources. A human decision-maker must review the electronically monitored information, verify accuracy, review pending data correction requests, and exercise independent judgment. The human decision-maker must also consider non-monitoring information — including supervisory evaluations, personnel files, employee work products, and peer reviews — in making each decision.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(C)
Introduced
School entities must ensure that AI does not replace a licensed teacher in providing core academic instruction or assigning final grades.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(C)
Introduced
School entities must ensure that any instructional content generated by AI is reviewed and approved by a licensed teacher before being provided to students.
US
Introduced
Employers must not rely exclusively on an automated decision system in making any employment-related decision with respect to a covered individual.
US
Introduced
Employers must independently corroborate each automated decision system output through meaningful oversight by a human with appropriate and relevant experience before using the output in an employment-related decision.
US
Introduced
Covered entities must adopt and adhere to a policy that (1) ensures AI/CDSS outputs are not substituted for the independent judgment of health care professionals acting within their scope of practice, (2) allows professionals to override AI/CDSS outputs in a timely manner when clinically appropriate or required by law, (3) provides a feedback channel for professionals to report incorrect or biased outputs, and (4) prohibits sharing override data identifying individual professionals or identifiable groups, except for patient-care communications or legal proceedings.
US
Introduced
The Department of Defense must not employ lethal force through autonomous weapon systems without appropriate levels of human judgment and supervision, and must ensure all other autonomous weapon system uses conform to DoD Directive 3000.09.
VA
VA HB 1294 (Law Enforcement AI Disclosure) § Va. Code § 19.2-11.14(B)
Introduced
All criminal justice decisions — including pre-trial detention or release, prosecution, adjudication, sentencing, probation, parole, correctional supervision, and rehabilitation — must be made by the judicial officer or other authorized person. No such decision may be made without human involvement. Any AI-generated recommendation or prediction must be subject to challenge or objection permitted by law.
VT
Introduced eff 2025-07-01
Employers must not solely rely on automated decision system outputs when making employment-related decisions. An employer may use an ADS in employment-related decisions only if all three conditions are met: (1) the ADS outputs are corroborated by human oversight of the employee, including supervisory or managerial observations, work documentation, personnel records, and consultations with coworkers; (2) the employer has conducted an impact assessment of the ADS under subsection (g); and (3) the employer has provided the required notice under subsection (f)(4).
VT
Introduced eff 2025-07-01
Deployers must provide and explain a process for consumers to appeal a consequential decision. The appeal process must allow the consumer to formally contest the decision, provide supporting information, and obtain meaningful human review. The deployer must designate a human reviewer who is trained and qualified, free of conflicts of interest, was not involved in the initial decision, is protected from retaliation for exercising their review functions, and is allocated sufficient resources. The human reviewer must consider the consumer's information and may consider other relevant sources. The deployer must respond within 45 days, extendable once by an additional 45 days with notice and explanation of the delay.
WA
Introduced eff 2026-07-01
Employers must not solely rely on automated decision system outputs when making employment-related decisions. An employer may use an automated decision system for employment-related decisions only if the outputs are corroborated by human oversight (including supervisory observations, personnel records, and coworker consultations), the employer has conducted an impact assessment, and the employer has complied with notice requirements.
AL
Failed
State and local law enforcement agencies must not use AI or facial recognition results as the sole basis for establishing probable cause or making an arrest; AI or facial recognition results may only be used in conjunction with other lawfully obtained information and evidence.
AL
Failed
State and local law enforcement agencies must not use facial recognition technology match results as the sole basis for establishing probable cause or making an arrest; match results may be used only in conjunction with other lawfully obtained information and evidence.
CA
Failed
Employers must not rely solely on an ADS when making a discipline, termination, or deactivation decision. When an employer relies primarily on ADS output for such a decision, a human reviewer must review the ADS output and compile and review other relevant information, which may include supervisory or managerial evaluations, personnel files, work product, peer reviews, and witness interviews (including relevant online customer reviews).
GA
Failed
Law enforcement officers must seek corroborating evidence independently supporting probable cause for any person identified through a facial recognition search, and must conduct all searches only through an authorized facial recognition specialist using lawfully acquired probe images and agency-authorized repositories.
GA
Failed
Law enforcement agencies must follow a mandatory sequential process for criminal suspect identification: (1) search by an authorized specialist, (2) human-based facial comparison of candidates, (3) independent peer review via blind search, (4) corroborating or exculpatory investigation, (5) superior-officer review of procedures and evidence sufficiency, and (6) judicial review before issuance of any warrants.
GA
GA HB 887 (AI Decision Restrictions) § O.C.G.A. § 49-4-11
Failed
County departments must not make any public assistance award, denial, reduction, or termination decision based solely on AI or automated decision tool outputs.
GA
GA HB 887 (AI Decision Restrictions) § O.C.G.A. § 49-4-11
Failed
County departments must ensure that any public assistance decision informed by AI or an automated decision tool is meaningfully reviewed by a human with override authority, under procedures established by the Board of Human Services.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must subject all automated evaluations to human review within 24 hours of the evaluation and must provide an expedited review process that includes human review within 48 hours of a consumer's review request.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must require at least 10% of all algorithmic evaluations to undergo random human review to prevent false positives.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-502
Failed
Law enforcement agencies must not introduce facial recognition results at trial or adjudicatory hearings. Results may only be used to establish probable cause or positive identification for warrants or at preliminary hearings, and must always be supported by additional, independently obtained corroborating evidence.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Failed
Law enforcement agencies must ensure that every facial recognition result is independently verified by a trained individual who has completed training under § 2-505 before the result is used for any purpose in a criminal investigation.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–503
Failed
Law enforcement agencies must ensure that every facial recognition result is independently verified by a trained and proficiency-tested individual before the result is used for any purpose in a criminal investigation.
MN
Failed
Agencies must require a trained officer to examine the output or recommendation of a facial recognition system before investigating or otherwise interacting with any individual identified by the system.
MN
Failed eff 2023-01-01
The Commissioner must ensure that every possible identity match flagged by the facial recognition software is reviewed by a department employee before any adverse action is taken. If the employee confirms the match, the Commissioner must (1) withhold issuance of a license or ID card until the match is invalidated, and (2) refer the matter to an appropriate law enforcement entity.
MN
Failed eff 2023-01-01
Law enforcement must independently reevaluate every identity match confirmed by the department and notify the Commissioner of the result. The Commissioner is prohibited from issuing a license or ID card if law enforcement confirms the match, and may issue if law enforcement invalidates it.
MN
Failed eff 2025-01-01
The Commissioner must ensure that every possible identity match flagged by facial recognition software is reviewed by a department employee before any adverse action is taken; if the employee confirms the match, the Commissioner must withhold the license or ID card and refer the matter to law enforcement.
MN
Failed eff 2025-01-01
Law enforcement entities receiving a confirmed identity match referral must independently reevaluate the match, notify the Commissioner of the results, and may refer the matter for criminal prosecution if the match is confirmed valid; the Commissioner must deny the license or ID card if law enforcement confirms the match.
MN
MN HF 465 (Facial Recognition Technology) § Minn. Stat. § 626A.53
Failed
Agencies must require a trained officer to examine the output or recommendation of a facial recognition system before the agency investigates or otherwise interacts with any individual identified by the system.
MT
Failed
Law enforcement agencies must not use facial recognition results as the sole basis to establish probable cause; results may only be used in conjunction with other lawfully obtained information and evidence.
MT
Failed
Law enforcement agencies must employ meaningful human review before making any adverse final decision based on facial recognition identification results.
NC
Failed
Agency staff must independently review, evaluate, and as appropriate modify all AI-assisted work product before any environmental permit application is approved, denied, delayed, conditioned, or otherwise acted upon. No permit decision may rest solely on AI output.
NV
Failed eff 2026-01-01
Persons who sell AI-powered legal document generation software must ensure that a Nevada-licensed attorney reviews each generated document before it is provided to a customer in Nevada, unless the customer is a licensed attorney, law firm, the State, or a court.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 408
Failed
Persons developing or deploying automated systems in sensitive domains — including criminal justice, employment, education, and health — must tailor the system to its purpose, provide meaningful access for oversight, include training for residents interacting with the system, and incorporate human consideration for adverse or high-risk decisions.
NY
Failed
Employers must not rely solely on employee data collected through electronic monitoring when making hiring, promotion, termination, disciplinary, or compensation decisions.
NY
Failed
Employers must not rely solely on AEDT output for hiring, promotion, termination, disciplinary, or compensation decisions and must establish meaningful human oversight by designating an internal reviewer with (1) sufficient expertise in the AEDT's operation and bias audit results to identify errors, (2) authority and discretion to dispute, rerun, or reject suspected invalid, inaccurate, or discriminatory outputs, and (3) adequate time and resources. Employers must also consider non-AEDT information such as supervisory evaluations, personnel files, work products, or peer reviews.
NY
Failed
Employers must not rely primarily on electronic monitoring data when making hiring, promotion, termination, disciplinary, or compensation decisions. Employers must establish meaningful human oversight — including a designated internal reviewer with expertise, authority to dispute or reject outputs, and adequate time and resources — who must actually review monitoring data for accuracy, check pending correction requests, exercise independent judgment, and consider non-monitoring information in making each decision.
NY
Failed
Employers must not rely primarily on AEDT output when making hiring, promotion, termination, disciplinary, or compensation decisions. Employers must establish meaningful human oversight — a human decision-maker must actually review any AEDT output, exercise independent judgment, and consider non-AEDT information (such as supervisory evaluations, personnel files, employee work products, or peer reviews) in making each decision.
NY
Failed
Employers must not rely solely on employee data collected through electronic monitoring when making hiring, promotion, termination, disciplinary, or compensation decisions.
NY
Failed
Employers must not rely solely on AEDT output for hiring, promotion, termination, disciplinary, or compensation decisions and must establish meaningful human oversight by designating an internal reviewer with (A) sufficient expertise in AEDT operations and familiarity with the most recent bias audit results, (B) authority and discretion to dispute, rerun, or recommend rejection of suspect outputs, and (C) adequate time and resources to review outputs. Employers must also consider information beyond AEDT outputs, such as supervisory evaluations, personnel files, and peer reviews.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 408
Failed
For automated systems used in sensitive domains — including criminal justice, employment, education, and health — developers and deployers must additionally tailor systems to their purpose, provide meaningful oversight access, include training for residents interacting with the system, and incorporate human consideration for adverse or high-risk decisions.
OK
Failed
Deployers must ensure that qualified human overseers validate high-risk AI system outputs before they are enacted and retain authority to override system recommendations.
US
Failed
A facial recognition match must not be the sole basis for establishing probable cause for a search, arrest, or other law enforcement action. Officers using facial recognition results must examine results with care and consider the possibility of inaccurate matches.
US
Failed
Employers must not rely exclusively on an automated decision system to make any employment-related decision with respect to a covered individual.
US
Failed
Employers must independently corroborate every automated decision system output through meaningful oversight by a human with appropriate and relevant experience before using it in an employment-related decision.
US
Failed
Employers must not rely exclusively on an automated decision system in making any employment-related decision with respect to a covered individual.
US
Failed
Employers must independently corroborate each automated decision system output through meaningful oversight by a human with appropriate and relevant experience before using it in an employment-related decision.
UT
UT SB 180 (Law Enforcement AI Usage) § Utah Code § 53-25-602
Failed
The author of a police report or law enforcement record created wholly or partially with generative AI must certify that they have personally read and reviewed the report or record for accuracy.
VA
Failed
State agencies may not make any employment decision without the involvement of a human decision maker. No state agency may solely use any recommendation or prediction from an automated decision system to make an employment decision.
VA
Failed
Local government entities may not make any employment decision without the involvement of a human decision maker. No local government entity may solely use any recommendation or prediction from an automated decision system to make an employment decision.
VA
Failed
Employers may not make any employment decision without the involvement of a human decision maker. No employer may solely use any recommendation or prediction from an automated decision system to make an employment decision. A knowing violation is subject to a civil penalty of up to $500 for a first violation and $1,500 for each subsequent violation.
VT
Failed
Employers must not solely rely on automated decision system outputs for employment-related decisions. ADS outputs may be used only when corroborated by human oversight (supervisory observations, personnel records, coworker consultations), the employer has completed a pre-deployment impact assessment, and the employer complies with statutory notice requirements.
WA
Failed
Public agencies must ensure that any decision made or informed by an automated decision system is subject to appeal, immediate suspension if a legal right, duty, or privilege is impacted, and potential reversal by a human decision maker through a clearly described and accessible process not to exceed 20 days.
WA
Failed
Agencies must ensure that any decision made or informed by an automated decision system is subject to appeal, immediate suspension if a legal right, duty, or privilege is impacted, and potential reversal by a human decision maker through a clearly described and accessible process not to exceed 20 days.