CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must cover purpose, algorithmic discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. Deployers must retain all impact assessments and records for at least three years after final deployment, and must conduct at least annual reviews to verify each system is not causing algorithmic discrimination.
CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment and at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must include: (1) a statement of purpose, intended use cases, deployment context, and benefits; (2) an analysis of algorithmic discrimination risks with mitigation steps; (3) categories of input data and outputs; (4) data used to customize the system if applicable; (5) performance metrics and known limitations; (6) transparency measures including consumer disclosure of AI use; and (7) post-deployment monitoring and user safeguards. After a substantial modification, the assessment must also disclose the extent to which actual use was consistent with the developer's intended uses. A single assessment may cover a comparable set of systems. An assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect. Deployers must retain the most recent impact assessment, all associated records, and all prior assessments for at least three years following final deployment. In addition, deployers must review deployment of each high-risk AI system at least annually to ensure it is not causing algorithmic discrimination.
VA
Enacted eff 2026-07-01
Developers must exercise a reasonable duty of care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of each high-risk AI system. Compliance with all requirements of § 59.1-608 creates a rebuttable presumption that the developer has satisfied this duty.
VA
Enacted eff 2026-07-01
Deployers must exercise a reasonable duty of care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with all requirements of § 59.1-609 creates a rebuttable presumption that the deployer has satisfied this duty.
VA
Enacted eff 2026-07-01
Deployers must complete a detailed impact assessment for each high-risk AI system before initial deployment and before each significant update. The impact assessment must include at minimum: purpose and use case disclosure, algorithmic discrimination risk identification and mitigation steps, data input and output categories, customization data categories, performance metrics and limitations, transparency measures, post-deployment monitoring descriptions, and validity and reliability analysis. A single assessment may cover comparable systems. Impact assessments completed for other applicable laws are accepted if reasonably similar in scope. Assessments and all records must be retained for three years.
CA
Engrossed
Developers must conduct performance evaluations of each covered ADS — covering purpose, developer-approved uses, expected accuracy and reliability, intended disparate treatment (with necessity and alternatives analysis), reasonably foreseeable disparate impacts (with necessity, alternatives, and mitigation analysis), and effects of fine-tuning — before initial deployment (for systems first available on or after January 1, 2026; by January 1, 2027 for pre-existing systems), after each substantial modification or material fine-tuning, and at least annually.
CA
Engrossed eff 2026-01-01
Developers must perform a formal impact assessment on each high-risk automated decision system before making it publicly available for use (for systems available on or after January 1, 2026). For systems first made publicly available before January 1, 2026, developers must perform an impact assessment upon making a substantial modification to the system.
CA
Engrossed eff 2026-01-01
Deployers must perform an impact assessment on each high-risk automated decision system within two years of deploying the system (for systems first deployed after January 1, 2026). A state-agency deployer may opt out of this requirement if it uses the system only for its intended use as determined by the developer, makes no substantial modification, the developer complies with the Public Contract Code procurement and confidential-submission requirements, the state agency has no reasonable basis to believe deployment is likely to result in algorithmic discrimination, and the state agency maintains a governance program under § 22756.3.
CA
Engrossed eff 2026-01-01
Developers must make the statements from their impact assessment available to deployers and potential deployers. The impact assessment must include: (1) a statement of purpose, intended benefits, intended uses, and intended deployment contexts; (2) a description of intended outputs; (3) a summary of data types used as inputs and recommended processing; (4) a summary of reasonably foreseeable disproportionate or unjustified impacts on protected classifications; (5) a description of safeguards to mitigate known algorithmic discrimination risks; (6) a description of how deployers can monitor for algorithmic discrimination; (7) a statement of the extent to which the deployer's use varies from the developer's intended use; (8) a description of deployer-side safeguards against discrimination; and (9) a description of how the system has been and will be monitored and evaluated.
CA
Engrossed eff 2026-01-01
Developers and deployers must not deploy or make available for deployment a high-risk automated decision system if its impact assessment determines the system is likely to result in algorithmic discrimination — unless the entity implements safeguards to mitigate the known risks of algorithmic discrimination and performs an updated impact assessment verifying that the discrimination has been mitigated and is not reasonably likely to occur.
NY
Engrossed
Developers and deployers must take reasonable care to prevent foreseeable risk of algorithmic discrimination arising from the use, sale, or sharing of a high-risk AI system or a product featuring a high-risk AI system.
VA
Engrossed eff 2026-07-01
Deployers must complete an impact assessment before initially deploying a high-risk AI system and within 90 days of each significant update, covering purpose, discrimination risks, data categories, customization data, performance metrics, transparency measures, and post-deployment monitoring. Impact assessments and all related records must be retained for five years. A single assessment may cover a comparable set of systems, and assessments completed under other applicable laws may satisfy this requirement if reasonably similar in scope.
CT
Introduced eff 2025-10-01
Employers must contract with an impartial third party to complete an impact assessment of any high-risk AI system no later than one year before deployment. The assessment must cover the system's purpose, use cases, deployment context, performance metrics, known limitations, error rates, algorithmic discrimination risk, accessibility, employee-rights impacts, and effects on job quality or well-being. For systems deployed before October 1, 2025, the assessment must be completed by October 1, 2026.
CT
Introduced eff 2026-10-01
Deployers must not deploy or continue deploying an automated employment-related decision process if the most recent bias audit identified disparate impact, unless the deployer can demonstrate: (1) business necessity, (2) implementation of corrective actions approved by the Labor Commissioner, and (3) either that no less discriminatory alternative is available or that a less discriminatory alternative has been implemented.
GA
Introduced
Deployers (or a contracted third party) must complete a formal impact assessment for each automated decision system before deployment and at least annually thereafter, and within 90 days after any intentional and substantial modification. The assessment must include, at minimum: (1) a statement of purpose, use cases, deployment context, and benefits; (2) analysis of risks of algorithmic discrimination, accessibility limitations, labor-law violations, and privacy intrusions; (3) description of data inputs and outputs; (4) overview of customization data; (5) validity and reliability analysis per contemporary social science standards with performance metrics; (6) description of transparency measures; (7) description of post-deployment monitoring and user safeguards; and (8) for post-modification assessments, a statement on whether the system was used consistently with or varying from the developer's intended uses. Subject to small-deployer exemption in § 10-16-6.
GA
Introduced
Deployers must not deploy an automated decision system if the impact assessment reveals a risk of algorithmic discrimination until the developer or deployer takes reasonable steps to search for and implement less discriminatory alternative decision methods.
HI
Introduced
Deployers must complete an internal impact assessment at least annually, and upon any intentional and substantial modification of a high-risk AI system, evaluating intended use, data categories and limitations, foreseeable risks of consumer harm, discrimination mitigation steps, and monitoring results.
IA
Introduced
Developers must use reasonable care to protect individuals from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of their high-risk AI systems. Compliance with the statute's enumerated requirements and attorney general rules creates a rebuttable presumption of reasonable care.
IA
Introduced
Deployers must use reasonable care to protect individuals from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with the statute's risk management, impact assessment, and annual review requirements and any attorney general rules creates a rebuttable presumption of reasonable care.
IA
Introduced
Deployers (or their contracted third parties) must complete an impact assessment for each high-risk AI system within 90 days of deployment or intentional and substantial modification, covering: purpose, context, and benefits; discrimination risk analysis and mitigation steps; data input categories and outputs; performance metrics and limitations; transparency measures; post-deployment monitoring and safeguards; and, for modifications, consistency with the developer's intended uses.
IL
Introduced
Employers must conduct an initial impact assessment at least 30 days before implementing any automated decision-making system. The assessment must bear the signature of (1) one or more individuals responsible for meaningful human review of the system, and (2) an independent auditor. An independent auditor is disqualified if, at any point in the 5 years preceding the assessment, that person was involved in developing or deploying the system under review, had an employment relationship with the developer or deployer, or had a direct or material indirect financial interest in the developer or deployer.
IL
Introduced
Employers must conduct additional impact assessments at least once every 2 years and before any material changes to the automated decision-making system. Each assessment must include, in plain language: (1) a description of the system's objectives; (2) an evaluation of the system's ability to achieve those objectives; (3) a description and evaluation of algorithms, computational models, and AI tools used, including a summary of underlying algorithms and a description of the design and training; (4) testing for: (A) disparate impact or discrimination based on protected characteristics (race, color, religious creed, national origin, sex, disability, gender identity, sexual orientation, genetic information, pregnancy, ancestry, veteran status) and mitigation actions; (B) accessibility limitations for persons with disabilities; (C) privacy and job quality impacts including wages, hours, conditions, and safeguards; (D) cybersecurity vulnerabilities and safeguards; (E) public health or safety risks; (F) foreseeable misuse and safeguards; and (G) use, storage, and control of sensitive or personal data; and (5) a notification mechanism for employees impacted by the system.
IL
Introduced
Auto insurers must demonstrate to the Department of Insurance that their marketing, underwriting, rating, claims handling, fraud investigations, and any algorithm or model used for those practices do not disparately impact customers on the basis of race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression.
IN
Introduced eff 2026-07-01
Employers must ensure that any automated decision system used to generate output for employment-related decisions has undergone predeployment testing and validation covering: (i) efficacy of the system; (ii) compliance with enumerated federal employment discrimination statutes (Title VII, ADEA, ADA Title I, GINA Title II, Equal Pay Act, Rehabilitation Act Sections 501/505, Pregnant Workers Fairness Act); (iii) absence of discriminatory impact based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, and genetic information (including family medical history); and (iv) compliance with the NIST AI Risk Management Framework (January 26, 2023) or a successor framework.
LA
Introduced
Covered insurers must conduct an annual disparate impact audit of each ADS, performed by a qualified independent actuary (FCAS/FSA/FAAA) or data scientist with algorithmic-fairness expertise, analyzing outcomes disaggregated by protected class and geographic area, assessing each variable's contribution, evaluating less discriminatory alternatives, and documenting methodology, findings, and corrective actions.
MA
Introduced
Controllers must conduct and document a data protection assessment before engaging in targeted advertising, data sales, profiling with foreseeable consumer harm risks, sensitive data processing, or processing data from products predominantly used by minors. Assessments must identify data categories, processing purposes, weigh benefits against consumer risks, and account for de-identification and consumer expectations.
MA
Introduced
Employers must not use electronic monitoring (alone or with an ADS) unless the monitoring has been the subject of an impact assessment conducted within one year by an independent, impartial auditor evaluating data protection/security practices, allowable purposes, potential legal violations, and impact on employee privacy and job quality.
MA
Introduced
Employers must not use an automated employment decision tool unless it has undergone an independent impact assessment within the prior year evaluating scientific validity of attributes, protected-class proxy risk, training data disparities, output disparate impact, disability accessibility, post-deployment discrimination risks, and privacy/job quality impacts. Results must be submitted to the Department of Labor Standards within 60 days for inclusion in a public registry and distributed to affected employees.
MA
Introduced
Employers must cease using an automated employment decision tool if an impact assessment finds disparate impact or disability accessibility limitations, until the employer (1) takes reasonable remediation steps and describes them in writing to employees, the auditor, and the department, and (2) if disputing the finding, demonstrates in writing that the tool is the least discriminatory method available.
MA
Introduced
Deployers must complete an annual impact assessment for each high-risk AI system covering: (i) the purpose and intended use, (ii) data categories used and outputs generated, and (iii) potential risks of discrimination and mitigation measures. Impact assessments must be updated after any substantial modification to the system.
MA
Introduced
Deployers must complete an impact assessment for each deployed high-risk AI system at the time of initial deployment, at least annually thereafter, and within 90 days after any intentional and substantial modification. The impact assessment must include, at a minimum: (1) purpose, intended use cases, deployment context, and benefits; (2) analysis of known or reasonably foreseeable risks of algorithmic discrimination and mitigation steps; (3) categories of input data and system outputs; (4) categories of data used to customize the system, if applicable; (5) performance metrics and known limitations; (6) transparency measures, including consumer disclosure; and (7) post-deployment monitoring and user safeguards. Assessments following an intentional and substantial modification must also disclose the extent to which the system was used consistently with or varied from the developer's intended uses. A single impact assessment may cover a comparable set of high-risk AI systems. An impact assessment completed for another applicable law satisfies this requirement if reasonably similar in scope and effect.
MA
Introduced
Employers must not use electronic monitoring, alone or with an automated employment decision system, unless the monitoring has been the subject of an impact assessment. The assessment must: (1) be conducted no more than one year before use (or within six months of the effective date for pre-existing monitoring); (2) be conducted by an independent and impartial party with no financial or legal conflicts of interest; (3) evaluate whether data protection and security practices are consistent with applicable law and cybersecurity best practices; (4) identify the allowable purpose(s); (5) consider and describe any other ways the monitoring could violate applicable law and steps to prevent such violations; and (6) consider and describe whether the monitoring may negatively impact employees' privacy and job quality, including wages, hours, and working conditions.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MA
Introduced
If an impact assessment finds that any data set, feature, or application of an automated employment decision tool results in a disparate impact based on protected characteristics or unlawfully limits accessibility for persons with disabilities, the employer must refrain from using the tool until it: (1) takes reasonable and appropriate steps to remedy the disparate impact or accessibility limitation and describes those steps in writing to employees, the auditor, and the department; and (2) if the employer believes the finding is erroneous or that remedial steps sufficiently address the findings, describes in writing how the feature at issue is the least discriminatory method of assessing performance or ability to perform essential job functions.
MI
Introduced
Before using any automated decisions tool or electronic monitoring tool, employers must commission an impact assessment by an independent and impartial third party with no financial or legal conflicts of interest. The assessment must be conducted one year before implementation (or within 6 months of the act's effective date for tools already in use) and must: (a) evaluate the tool's objectives, algorithms, data, cybersecurity vulnerabilities, and potential biases including discriminatory outcomes based on race, gender, or disability; (b) identify the attributes and modeling techniques the tool uses; (c) evaluate whether those attributes are scientifically valid means of evaluating performance and whether they may function as proxies for protected classes under the Elliott-Larsen Civil Rights Act; (d) identify disparate-impact risks in training data and outputs and describe remedial actions; (e) evaluate disability accessibility limitations and describe remedies; (f) describe potential sources of post-implementation adverse impact; (g) assess whether any feature causing disparate impact is the least discriminatory method available; (h) identify other potential legal violations and steps to prevent them; and (i) describe potential negative effects on privacy, wages, hours, and working conditions.
MI
Introduced
Before using an automated decisions or electronic monitoring tool, employers must commission an independent, conflict-free third-party impact assessment evaluating the tool's objectives, algorithms, data, cybersecurity, biases, proxy variables, disparate impact, accessibility limits, and privacy and job-quality effects, with remediation steps.
NJ
Introduced
Employers, public entities, and vendors must not deploy an AEDS or EMT until an independent auditor (or, for public employees, the Department of Labor) has conducted an impact assessment confirming the system serves only enumerated allowable purposes, uses the least invasive means, complies with anti-discrimination requirements (including disparate-impact analysis of training data), and implements effective human-oversight procedures. Vendors must provide the auditor full access to design documentation, training data sources, accuracy analyses, and economic-impact estimates. Assessments must be completed within one year before deployment, updated upon any substantial change, and the system may not operate until a compliant assessment is in place. Legacy systems must be assessed within six months of the effective date.
NJ
Introduced
Public entities and vendors must not deploy an ABSDS until the Department of Labor has conducted an impact assessment confirming compliance with anti-discrimination, proportionality, and human-oversight requirements, including effective procedures to prevent incorrect benefit denials based on mistaken fraud claims. Vendors must provide full documentation including design, training data, accuracy analysis, and economic-impact estimates. Assessments must be completed within one year before deployment, updated upon substantial changes, and the system may not operate until the assessment is complete. Legacy ABSDS systems must be assessed within one year of the effective date.
NJ
Introduced
High-risk AI systems implemented in New Jersey must undergo algorithmic impact assessments prior to deployment. The Office of Information Technology in the Department of the Treasury will perform the impact assessments, in a manner to be determined by OIT.
NJ
Introduced
Employers, public entities, and vendors must, before deploying an AEDS or EMT, have an independent auditor (or the Department of Labor for public-employee systems) conduct and affirm an impact assessment confirming Section 2 compliance, disparate-impact analysis, and human-oversight procedures, updated within one year before deployment and re-run on any substantial change.
NJ
Introduced
Public entities and vendors must not deploy an ABSDS unless the Department of Labor conducts and affirms an impact assessment confirming Section 2 compliance, analyzing training-data disparities and disparate adverse impact on beneficiaries, and requiring human-oversight procedures to prevent harmful outcomes including erroneous fraud-based benefit denials; re-run on any substantial change.
NJ
Introduced
State entities must cooperate with biannual Office audits of their high-risk algorithmic systems assessing intended purpose, data inputs, potential bias or disparate impact, and risk mitigation, and must develop and implement a corrective action plan within the director's timeframe if the Office identifies bias or discrimination risk. Audit summaries must be suitable for public disclosure.
NJ
Introduced
Covered entities must conduct an algorithmic impact assessment at least every two years evaluating whether the automated decision system results in a disparate impact on a protected class, in a form prescribed by the Director of the Division on Civil Rights.
NJ
Introduced
High-risk AI systems implemented in New Jersey must undergo algorithmic impact assessments prior to deployment. The assessments are performed by the Office of Information Technology in a manner to be determined by that office.
NY
Introduced
Designers, developers, and deployers of automated systems must take proactive and continuous measures to protect against algorithmic discrimination, including: (1) proactive equity assessments as part of system design, (2) use of representative data, (3) protection against proxies for demographic features, and (4) assurance of accessibility for persons with disabilities in design and development.
NY
Introduced
Employers with 100 or more employees must not use an AEDT for any employment decision unless the tool has been subjected to a disparate-impact assessment, conducted within the prior year by an impartial auditor with no financial or legal conflicts of interest. The assessment must identify modeling techniques, evaluate disparate impact on protected classes, assess whether the tool uses the least discriminatory method, and be submitted to the Department of Labor for a public registry within 60 days of completion and distributed to affected employees.
NY
Introduced
Employers must cease using an AEDT if an impact assessment finds disparate impact on a protected class, and may not resume use until the employer (1) takes reasonable and appropriate steps to remedy the disparate impact and (2) where the employer disputes the finding or believes remediation is sufficient, submits to the Commissioner a demonstration that the tool is the least discriminatory method available for assessing employee performance or ability to perform essential job functions.
NY
Introduced
Employers must conduct an impact assessment before utilizing or applying any artificial intelligence. The assessment must be repeated at least every two years and prior to any material change to the AI system that may change its outcome or effect. The impact assessment must include: (1) a description of the AI system's objectives; (2) an evaluation of the system's ability to achieve its stated objectives; (3) a description and evaluation of the system's development, including a summary of the underlying algorithms, computational modes, and tools, and the design and training data used; (4) the extent to which the system requires input of sensitive and personal data, how that data is used and stored, and any user control over their data; (5) an estimate of the number of employees already displaced due to AI; and (6) an estimate of the number of employees expected to be displaced or otherwise affected due to increased AI use in the workplace.
NY
Introduced
Deployers (or their contracted third parties) must complete an impact assessment for each high-risk AI decision system before initial deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification. Each impact assessment must include: (1) a statement of the system's purpose, intended use cases, deployment context, and benefits; (2) analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (3) descriptions of data input categories, system outputs, customization data categories, performance metrics and known limitations; (4) a description of transparency measures including consumer disclosure; and (5) a description of post-deployment monitoring and user safeguards. Post-modification assessments must also disclose actual-vs-intended use. A single assessment may cover a comparable set of systems, and an assessment completed under another law is deemed sufficient if reasonably similar in scope and effect. Deployers must retain the most recent assessment, all records, and all prior assessments for at least three years following final deployment.
NY
Introduced
Covered entities must conduct an impact assessment of each automated lending decision-making tool at least annually and prior to any material change, signed by an individual responsible for meaningful human review. The assessment must include bias and discrimination testing across enumerated protected characteristics, algorithm and training data descriptions, cybersecurity and privacy risk evaluation, misuse scenario analysis, and sensitive data handling practices. A summary report must be posted on the covered entity's website before initial deployment and updated after each subsequent assessment.
NY
Introduced
Covered deployers must file staggered reports with the Department of Financial Services that include an impact assessment evaluating whether the high-risk AI system poses a risk of algorithmic discrimination, the steps taken to address it, monetization, and a consumer cost-benefit analysis.
NY
Introduced
Developers and deployers must, prior to deploying, licensing, or offering a covered algorithm for a consequential action (including material changes), conduct a preliminary evaluation of the plausibility that any expected or intended use may result in a harm. If harm is not plausible, the developer or deployer must record a finding of no plausible harm — including a description of expected/intended use, how the evaluation was conducted, and an explanation — and submit it to the Division of Consumer Protection. If harm is plausible, a full pre-deployment evaluation by an independent auditor is required. Material changes to previously-deployed algorithms trigger re-evaluation, which may be scoped to the change.
NY
Introduced
Developers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: the algorithm's design and methodology (inputs and outputs); creation, training, and testing details (performance metrics, benchmarks, demographic representation, testing outputs, stakeholder consultation, protected-characteristic testing methodology); precursor algorithms; data sources, types, legal authorization, and representativeness; training process details; potential for harm or disparate impact; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the developer.
NY
Introduced
Deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: how the algorithm makes or contributes to a consequential action and its deployment purpose; necessity and proportionality relative to the baseline process being replaced; data inputs (type, collection, inference, processing, legal authorization, representativeness); expected and actual testing outputs; additional testing or training conducted by the deployer; stakeholder consultation; potential for harm or disparate impact in the deployment context; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the deployer.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must cease using an automated employment decision tool upon a finding of disparate impact until the employer has (1) taken reasonable steps to remedy the disparate impact, and (2) if the employer believes the finding is erroneous or remediated, submitted to the Commissioner a demonstration that the tool is the least discriminatory method of assessing employee performance or ability.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
If an impact assessment finds disparate impact or unlawful accessibility limitations, the employer must immediately cease using the tool until it (1) takes reasonable remedial steps and describes those steps in writing to employees, the auditor, and the Department, and (2) demonstrates in writing that the flagged feature is the least discriminatory method available, if the employer believes the finding is erroneous or that remedial steps are sufficient.
NY
Introduced
Employers must conduct an impact assessment before utilizing or applying any artificial intelligence. The assessment must be repeated at least every two years, and a new assessment must be conducted prior to any material change to the AI that may change its outcome or effect. Each impact assessment must include: (a) a description of the AI's objectives; (b) an evaluation of the AI's ability to achieve those objectives; (c) a description of the underlying algorithms, computational modes, tools, and training data used to develop the AI; (d) the extent to which the AI requires sensitive and personal data input, how that data is used and stored, and any user controls over their data; (e) an estimate of the number of employees already displaced due to AI; and (f) an estimate of the number of employees expected to be displaced or otherwise affected by increased AI use.
NY
Introduced
Deployers must complete an impact assessment for each high-risk AI decision system before deployment, at least annually thereafter, and within 90 days after any intentional and substantial modification. Each impact assessment must include, to the extent reasonably known: (A) a statement of purpose, intended use cases, deployment context, and benefits; (B) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (C) descriptions of input data categories and system outputs; (D) if applicable, categories of data used for customization; (E) performance metrics and known limitations; (F) transparency measures including consumer notification; and (G) post-deployment monitoring and user safeguards. Impact assessments following intentional and substantial modifications must also disclose whether the system was used consistently with the developer's intended uses. A single assessment may cover comparable systems. An impact assessment completed under another law satisfying substantially similar requirements is deemed compliant. Deployers must retain the most recently completed impact assessment, all records, and all prior assessments for at least three years following final deployment.
NY
Introduced
Deployers must conduct an annual impact assessment for each AEDT in use, covering: the tool's purpose, benefits, and deployment context; how its output is the controlling factor; data types collected from individuals; consistency with the developer's intended-use statement; foreseeable discrimination risk and mitigation safeguards; monitoring practices; and validity or relevance evaluation.
NY
Introduced
Developers must conduct an annual impact assessment for each AEDT made available for sale or licensing, covering: intended purpose, benefits, and deployment contexts; intended output and controlling-factor role; intended data collection from individuals; foreseeable discrimination risk and mitigation safeguards; and deployer monitoring guidance.
NY
Introduced
Covered entities must conduct at least annual impact assessments of each automated lending decision-making tool — signed by a responsible human reviewer — covering accuracy, fairness, bias, discrimination across protected characteristics, cybersecurity, privacy, safety, misuse risks, data practices, and notification mechanisms, and must publish a summary report on their website before deployment and after each subsequent assessment. An additional assessment is required before any material change to the tool.
RI
Introduced
Employers must not use electronic monitoring, alone or in conjunction with an automated decision system, unless the proposed use has been the subject of an impact assessment. The impact assessment must: (1) be conducted no more than one year before use begins (or within six months of the effective date for pre-existing monitoring), (2) be conducted by an independent and impartial party with no financial or legal conflicts of interest, (3) evaluate whether data protection and security practices are consistent with applicable law and cybersecurity best practices, (4) identify the allowable purposes as defined in the chapter, (5) consider and describe any other ways the monitoring could result in a law violation and necessary steps to prevent it, (6) consider and describe whether the monitoring may negatively impact employees' privacy and job quality including wages, hours, and working conditions, and (7) be disclosed in full, in plain language, to all affected workers and their authorized representatives within 30 days of the employer's receipt. Workers and their authorized representatives have the right to comment on, challenge, and bargain over the proposed monitoring based on the assessment's findings.
RI
Introduced eff 2025-10-01
Deployers must complete an impact assessment of each high-risk AI system before deployment and at least annually thereafter (and within 90 days of any intentional and substantial modification), covering purpose, discrimination risk analysis, data categories, customization data, performance metrics, transparency measures, and post-deployment monitoring.
SC
Introduced
Developers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the system. A rebuttable presumption of reasonable care applies if the developer complies with all requirements of Section 37-31-20 and any rules adopted by the Attorney General.
SC
Introduced
Deployers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination. A rebuttable presumption of reasonable care applies if the deployer complies with all requirements of Section 37-31-30 and any rules adopted by the Attorney General.
SC
Introduced
Deployers, or third parties contracted by deployers, must complete an impact assessment for each deployed high-risk AI system before or at deployment, and at least annually thereafter and within 90 days after any intentional and substantial modification. The impact assessment must include, at minimum: (1) a statement of the system's purpose, intended uses, deployment context, and benefits; (2) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (3) a description of data inputs and outputs; (4) an overview of data used to customize the system, if applicable; (5) performance metrics and known limitations; (6) transparency measures including consumer disclosure; and (7) post-deployment monitoring and user safeguards. Post-modification assessments must also disclose whether the system was used consistently with or varied from the developer's intended uses. A single impact assessment may cover comparable systems. An impact assessment completed for another applicable law or regulation satisfies this requirement if reasonably similar in scope and effect. Small deployers with fewer than 50 employees are exempt if other conditions in subsection (F) are met.
US
Introduced
Covered entities must perform impact assessments of each covered algorithm both before and after deployment, and maintain documentation of those assessments for three years beyond the duration of deployment.
US
Introduced
Covered entities must identify and measure any likely material negative impact of the covered algorithm on consumers, document steps taken to eliminate or mitigate each identified impact, document any impacts left unmitigated with justification (including a non-discriminatory compelling interest analysis), and maintain standard protocols for identifying, measuring, and mitigating negative impacts.
US
Introduced
Developers and deployers must conduct a preliminary evaluation of the plausibility that any expected or intended use of a covered algorithm for a consequential action may result in harm before deploying, licensing, or offering it. If harm is not plausible, a finding must be recorded and submitted to the FTC. If harm is plausible, a full pre-deployment evaluation must be conducted.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering the algorithm's design, methodology, training data, testing across demographic groups, potential for disparate impact, and mitigation recommendations, and receive a written report from the auditor.
US
Introduced
Covered entities must perform impact assessments of any deployed automated decision system intended for use in an augmented critical decision process and of any augmented critical decision process, both before and after deployment.
US
Introduced
Covered entities must, for any new augmented critical decision process, evaluate the previously existing decision-making process it replaces, including the baseline process description, known harms or negative impacts, and the intended benefits and purpose of the new process.
US
Introduced
Covered entities must identify and measure any likely material negative impact of each automated decision system or augmented critical decision process on consumers, document steps taken to eliminate or mitigate those impacts, document which impacts were left unmitigated with justification (including the compelling non-discriminatory interest and why alternatives are insufficient), and maintain standard protocols for identifying, measuring, and mitigating negative impacts with associated staff training.
US
Introduced
Developers and deployers must conduct a preliminary evaluation of whether any expected or intended use of a covered algorithm may plausibly result in harm before deployment, licensing, or offering. If no harm is plausible, a documented finding must be recorded and submitted to the FTC. If harm is plausible, a full pre-deployment evaluation by an independent auditor is required.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering design, methodology, training data, testing across protected characteristics, stakeholder consultation, potential for disparate impact, and mitigation recommendations. The auditor must submit a report with findings and recommendations.
VT
Introduced eff 2025-07-01
Employers must create a written impact assessment before utilizing any automated decision system. The assessment must include at minimum: (1) a detailed description of the ADS and its purpose; (2) a description of data used; (3) outputs produced and the types of employment decisions those outputs may inform; (4) an assessment of necessity including reasons for supplementing nonautomated decision-making; (5) a validity and reliability assessment per contemporary social science standards, including performance metrics and known limitations; (6) a detailed risk assessment covering discrimination across protected classes, chilling effects on legal rights, harms to health/safety/dignity/autonomy, privacy risks including data breaches, and negative economic/material impacts to employees; (7) a summary of risk mitigation measures; and (8) a description of the assessment methodology.
WA
Introduced eff 2026-07-01
Employers must create a written impact assessment before utilizing any automated decision system, covering the system's description, data used, outputs, rationale, risks (including errors, discrimination across enumerated protected classes, chilling effects on legal rights, physical and mental health harms, privacy risks, and negative economic impacts), mitigation measures, and methodology. The assessment must be updated upon any significant change to the system.
WA
Introduced eff 2027-01-01
Deployers must complete an impact assessment for each high-risk AI system before initial deployment and before any significant update is used for consequential decisions. The impact assessment must include at minimum: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) whether deployment poses known or reasonably foreseeable algorithmic discrimination risks, the nature of such discrimination, and mitigation steps taken; (3) for post-deployment assessments, whether actual use cases were consistent with or varied from the developer's intended uses; (4) categories of input data and system outputs; (5) categories of data used to customize the system, if applicable; (6) performance metrics and known limitations; (7) transparency measures taken, including consumer-facing AI disclosure; (8) post-deployment monitoring and user safeguards, including oversight processes; and (9) an analysis of the system's validity and reliability per standard industry practices. An impact assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect. A single impact assessment may address a comparable set of high-risk AI systems.
WA
Introduced eff 2026-07-01
Deployers must complete an impact assessment for each high-risk AI system before deployment on or after July 1, 2027, and within 90 days after any intentional and substantial modification. Each assessment must include, to the extent reasonably known: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (3) categories of input data, system outputs, performance metrics and limitations, transparency measures taken, and post-deployment monitoring and user safeguards. Assessments following a substantial modification must also disclose the extent to which the system was used consistently with or in variance from the developer's intended uses. A single assessment may cover comparable systems, and an assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect.
WA
Introduced eff 2027-01-01
Deployers must complete an impact assessment for each high-risk AI system before initial deployment and before any significant update is used to make a consequential decision. The impact assessment must include, at minimum: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) whether the deployment poses any known or reasonably foreseeable risk of algorithmic discrimination, the nature of such discrimination, and mitigation steps taken; (3) for postdeployment assessments, whether updated use cases are consistent with the developer's intended uses; (4) categories of data inputs and outputs; (5) categories of data used by the deployer to customize the system; (6) performance metrics and known limitations; (7) transparency measures taken, including consumer disclosures; (8) postdeployment monitoring and user safeguards, including any oversight process; and (9) an analysis of the system's validity and reliability in accordance with standard industry practices.
WA
Introduced
Deployers must complete an impact assessment for each high-risk AI system before or at the time of deployment, and within 90 days after any intentional and substantial modification. Each impact assessment must include, at a minimum: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of known or reasonably foreseeable risks of algorithmic discrimination and mitigation steps taken; (3) a description of input data categories, outputs, performance metrics and known limitations, transparency measures, and post-deployment monitoring and user safeguards. Impact assessments following a substantial modification must also disclose the extent to which the system was used consistently with or varied from the developer's intended uses. A single impact assessment may cover a comparable set of high-risk AI systems, and an impact assessment completed under another applicable law satisfies these requirements if reasonably similar in scope and effect.
CA
Failed
Deployers must perform a documented impact assessment on each automated decision tool before first using it and annually thereafter, covering the tool's purpose, outputs, data categories collected (mapped to CCPA categories), consistency with the developer's intended-use statement, adverse-impact analysis across protected classes, safeguards against algorithmic discrimination, human oversight description, and validity evaluation. For tools already in use before January 1, 2025, the initial assessment must be completed before January 1, 2026.
CA
Failed
Developers must perform a documented impact assessment on each automated decision tool before making it available to potential deployers and annually thereafter, covering the tool's purpose, outputs, data categories collected, adverse-impact analysis across protected classes, mitigation measures against algorithmic discrimination, and human oversight capabilities. For tools first made available before January 1, 2025, the initial assessment must be completed before January 1, 2026.
CA
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
CA
Failed
Deployers must perform an annual impact assessment for each automated decision tool, covering purpose, outputs, data types, consistency with the developer's intended-use statement, adverse impacts on the basis of sex, race, or ethnicity, discrimination safeguards, human oversight, and validity evaluation.
CA
Failed
Developers must complete and document an annual assessment for each automated decision tool they design, code, or produce, covering purpose, outputs, data types, adverse impacts on the basis of sex, race, or ethnicity, discrimination mitigation measures, and human oversight capabilities.
CA
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible for any significant update to an automated decision tool.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within ninety days after any intentional and substantial modification. Post-modification assessments must disclose the extent to which the system's actual use was consistent with or varied from the developer's intended uses.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification, including a statement on whether actual use deviated from the developer's intended uses.
CO
Failed eff 2025-05-05
Deployers must complete an impact assessment for each high-risk AI system prior to first deployment (or January 1, 2027, whichever is later) and annually thereafter, covering risks of algorithmic discrimination, accessibility limitations, unfair trade practices, labor law violations, and Colorado Privacy Act violations, along with data categories, sources, outputs, and performance metrics. This obligation applies only to systems that are the principal basis of consequential decisions.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within ninety days of any intentional and substantial modification. Effective June 30, 2026.
CO
Failed
Deployers must include in any post-modification impact assessment a statement disclosing the extent to which the high-risk AI system was used consistently with or varied from the developer's intended uses. Effective June 30, 2026.
CT
Failed
Deployers must complete an impact assessment of each high-risk AI system at deployment, at least annually thereafter, and within 90 days of an intentional and substantial modification, covering purpose, discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. Impact assessments and all associated records must be retained for at least three years after final deployment.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information availability determination practices to (1) determine whether practices discriminate in violation of § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a per-determination audit trail recording the determination type, data and sources, algorithm methodology, training data, subgroup performance testing results, methodology, and ultimate decision, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with relevant third parties including service providers, and (6) identify and implement reasonable measures to remediate identified disparate-impact risks, including risks from service-provider determinations.
HI
Failed
The Office of Enterprise Technology Services must develop, maintain, and periodically update guidelines for state agencies to assess the impact of adopting generative AI tools on vulnerable communities, including criteria for evaluating equitable outcomes in high-risk uses, in consultation with employee organizations, trust and safety experts, and academic researchers.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate under § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a detailed audit trail recording determination type, data, sources, methodology, algorithm, training data, subgroup testing results, and ultimate decision for each determination, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable mitigation measures for disparate-impact risks.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate on the basis of protected characteristics, (2) analyze disparate-impact risks, (3) create and retain for at least five years a detailed audit trail for each determination (recording type, data, sources, methodology, training data, subgroup testing results, algorithm, and decision), (4) conduct annual impact assessments of existing systems and pre-implementation impact assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable measures to mitigate identified disparate-impact risks.
IL
Failed
Deployers must perform an annual impact assessment for each automated decision tool, covering the tool's purpose, outputs, data types, potential adverse impacts across protected characteristics, discrimination safeguards, human oversight components, and validation methodology. The first assessment is due by January 1, 2026.
IL
Failed
Deployers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
IL
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering tool purpose, outputs, data types, consistency with the developer's intended-use statement, algorithmic discrimination risks, ethical AI safeguards, human oversight mechanisms, and validation methodology.
IL
Failed
Developers must complete and document an annual impact assessment for each automated decision tool they design, code, or produce, covering tool purpose, outputs, data types, algorithmic discrimination risks from intended use and foreseeable misuse, ethical AI mitigation measures, and intended human oversight mechanisms.
IL
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
IL
Failed
Deployers must perform an impact assessment for each automated decision tool by January 1, 2027, and annually thereafter. The assessment must include: (1) a statement of the tool's purpose, intended benefits, uses, and deployment contexts; (2) a description of the tool's outputs and how they inform consequential decisions; (3) a summary of data types collected from individuals and processed by the tool; (4) an analysis of potential adverse impacts across protected characteristics (sex, race, color, ethnicity, religion, age, national origin, limited English proficiency, disability, veteran status, genetic information); (5) a description of safeguards implemented or planned to address reasonably foreseeable algorithmic discrimination risks; (6) a description of human use or monitoring of the tool in consequential decision-making; and (7) a description of how the tool has been or will be evaluated for validity or relevance. This obligation does not apply to deployers with fewer than 25 employees unless the tool impacted more than 999 people in the prior calendar year.
IL
Failed
Deployers must perform an additional impact assessment as soon as feasible with respect to any significant update to an automated decision tool. A significant update is a new version, new release, or other update that changes the tool's use case, key functionality, or expected outcomes.
MA
Failed
Covered entities must comply with all regulations promulgated by the Office under subsection (c) and must not knowingly provide substantial assistance to any entity that violates those regulations, regardless of any contractual arrangement with consumers.
MA
Failed
Covered entities must conduct automated decision system impact assessments for all existing and new high-risk automated decision systems — with new systems assessed prior to implementation — and data protection impact assessments for all existing and new high-risk information systems, at frequencies determined by the Office.
MA
Failed
Covered entities must reasonably address in a timely manner the results of all automated decision system and data protection impact assessments.
MD
Failed
Employers must not use an automated employment decision tool unless the tool has undergone an impact assessment within the year preceding first use and annually thereafter, and each assessment determines the tool's use would not involve a high-risk action (likely unlawful discrimination or disparate impact).
MD
Failed
Deployers must complete an impact assessment for any deployed high-risk AI system and retain all impact assessments and related records for at least 3 years after the end of deployment.
MD
Failed
Deployers must complete an impact assessment at least annually and within 90 days of any intentional and substantial modification, covering system purpose, deployment context, algorithmic discrimination risk analysis, mitigation steps, inputs and outputs, customization data, performance metrics, known limitations, transparency measures, oversight processes, and (for subsequent assessments) consistency with intended uses.
MD
Failed
Employers must not use an automated employment decision tool to screen applicants or determine employment terms unless the tool (1) was subject to an impact assessment in the year before first use, (2) undergoes an annual impact assessment each year of use, and (3) each assessment determines the tool would not involve a high-risk action likely to result in unlawful discrimination or disparate impact.
NE
Failed
Deployers must complete an impact assessment for each high-risk AI system deployed on or after February 1, 2026, and within 90 days after any intentional and substantial modification. The impact assessment must include, to the extent reasonably known: (1) a statement disclosing the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of whether deployment poses known risks of algorithmic discrimination and the mitigation steps taken; (3) a high-level summary of input data categories and outputs; (4) if the deployer used data to customize the system, an overview of the customization data categories; (5) any performance evaluation metrics and known limitations; (6) a description of transparency measures including consumer disclosure of AI use; and (7) a description of post-deployment monitoring and user safeguards. Impact assessments following substantial modifications must also disclose whether the system was used consistently with the developer's intended use. A single impact assessment may address a comparable set of systems. Deployers must maintain: the most recent impact assessment for each system, all records concerning the assessment, and for at least three years following final deployment, each prior impact assessment and associated records.
NM
Failed
Deployers must conduct an impact assessment for each deployed high-risk AI system (1) annually and (2) within 90 days of an intentional and substantial modification, covering intended uses, discrimination risks and mitigation, data categories, performance metrics including demographic test data breakdowns, transparency measures, and post-deployment monitoring. A single assessment may cover comparable systems. An exempt small deployer (fewer than 50 employees, no own-data training, intended-use-only deployment, consumer-accessible developer assessment) is excused.
NY
Failed
Employers must conduct at least annually a disparate impact analysis — conforming to the EEOC Uniform Guidelines on Employee Selection Procedures — assessing the actual impact of any automated employment decision tool used to select candidates for jobs within the state, differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must conduct at least an annual disparate impact analysis assessing the actual impact of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Designers, developers, and deployers must take proactive and continuous measures to prevent algorithmic discrimination, including proactive equity assessments during system design, use of representative data, protection against proxies for demographic features, and accessibility assurance for persons with disabilities.
NY
Failed
Employers must conduct at least annual disparate impact analyses of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must not use any AEDT unless it has been the subject of an impact assessment conducted by an independent auditor within the past year (or within six months of the effective date for pre-existing tools). The assessment must evaluate the tool's attributes and modeling techniques for scientific validity, proxy-variable risk across protected classes, training-data disparities, output-level disparate impact, disability accessibility, post-deployment discrimination risk, and least-discriminatory-method analysis. The completed assessment or an accessible summary must be submitted to the Department of Labor for inclusion in a public registry within 60 days and distributed to affected employees.
NY
Failed
Employers must immediately cease using any AEDT found by an impact assessment to cause disparate impact on a protected class or unlawfully limit disability accessibility, and may not resume use until (1) the employer takes reasonable steps to remedy the disparate impact or accessibility limitation and describes those steps in writing to employees, the auditor, and the Department, and (2) if the employer contests the finding, it describes in writing how the tool is the least discriminatory method of assessing the relevant performance criteria.
NY
Failed
Deployers must perform an impact assessment for each automated employment decision tool in use within one year of the effective date and annually thereafter, covering at minimum the tool's purpose, output, data types collected, consistency with the developer's intended-use statement, foreseeable discrimination risks and mitigation safeguards, monitoring practices, and validity evaluation.
NY
Failed
Developers must perform an impact assessment for each automated employment decision tool made available for sale or licensing within one year of the effective date and annually thereafter, covering at minimum the tool's intended purpose, intended output, intended data collection, foreseeable discrimination risks and mitigation safeguards, and deployer monitoring capabilities.
NY
Failed
When a bias audit finds disparate impact or accessibility limitations, employers must (1) take reasonable steps to reduce or remedy the impact and describe those steps in writing to employees, the auditor, and the department; (2) if the employer disputes the finding or believes remediation suffices, describe in writing why the tool is the least discriminatory method; or (3) if the finding results from a lawful affirmative action plan, describe the plan in writing to employees, the auditor, and the department.
NY
Failed
Designers, developers, and deployers must conduct proactive equity assessments during system design, use representative data, implement protections against demographic-proxy variables, ensure accessibility for persons with disabilities, and conduct both pre-deployment and ongoing disparity testing and mitigation under clear organizational oversight.
NY
Failed
Employers must conduct an impact assessment before utilizing or applying any artificial intelligence, covering the AI's objectives, effectiveness, underlying algorithms and training data, sensitive-data use, and both current and projected employee displacement. Reassessments must be conducted at least every two years and before any material change to the AI system.
OK
Failed
Deployers must conduct assessments of AI systems to identify potential biases in training data, risks to safety, civil liberties, and fundamental rights, and mitigation strategies for identified risks.
OK
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering the tool's purpose, outputs, data types collected, consistency with developer statements, algorithmic discrimination risks, ethical AI safeguards, human oversight mechanisms, and validation evaluations.
OK
Failed
Developers must complete and document an annual impact assessment for each automated decision tool they design, code, or produce, covering the tool's purpose, outputs, data types collected, algorithmic discrimination risks, ethical AI measures, and intended human use patterns.
OK
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
RI
Failed
Deployers must perform an annual impact assessment for each automated decision tool they use, covering purpose, outputs, data types, consistency with developer's intended-use statement, adverse-impact analysis across protected characteristics, discrimination safeguards, human oversight mechanisms, and validity evaluation.
RI
Failed
Developers must complete and document an annual assessment of each automated decision tool they design, code, or produce, covering purpose, outputs, data types, adverse-impact analysis across protected characteristics, discrimination mitigation measures, and human oversight capabilities.
RI
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
RI
Failed
Deployers must perform an impact assessment before deploying any CAIDS, repeat the assessment annually, and conduct a new assessment whenever material changes are made to the system's purpose or data inputs.
RI
Failed
Deployers must maintain impact assessment documentation for a reasonable time period covering the CAIDS's purpose, consistency with developer's intended uses, discriminatory impact potential across protected characteristics and mitigation steps, data inputs and outputs, retraining data, performance metrics and limitations, transparency measures, and post-deployment monitoring and safeguards.
RI
Failed
Developers must maintain design evaluation documentation for a reasonable time period covering the CAIDS's purpose and intended uses, discriminatory impact potential across protected characteristics and mitigation steps, known limitations, training data collection and processing overview, and pre-sale performance metrics.
RI
Failed
Deployers must perform an impact assessment prior to deploying a CAIDS and annually thereafter, with a new assessment required upon material changes to the system's purpose or the type of data it receives.
RI
Failed
Deployers must maintain impact assessment documentation for a reasonable time period covering: system purpose and use cases, consistency with developer's intended uses, potential for discriminatory impact on protected characteristics, data inputs and outputs, retraining data, performance metrics, transparency measures including notice to individuals, and post-deployment monitoring and user safeguards.
RI
Failed
Developers must conduct a design evaluation for each CAIDS that considers information relevant to the potential for unlawful bias in connection with the system's intended end use.
TX
Failed
Deployers must complete a written impact assessment for each high-risk AI system, annually and within 90 days of any substantial modification, covering purpose, discrimination risk analysis, data categories, performance metrics, transparency measures, post-deployment monitoring, and cybersecurity threat modeling. Following a modification, the deployer must disclose whether the system was used consistently with the developer's intended uses.
US
Failed
Covered entities must perform impact assessments of all deployed automated decision systems used or expected to be used in augmented critical decision processes, both before and after deployment.
US
Failed
Covered entities must perform ongoing testing and evaluation of system performance, including documenting performance metrics and success criteria, comparing test and deployed conditions, evaluating differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status, describing proxy data methods used, and identifying and documenting mitigation steps for material negative impacts including the rationale for any impacts left unmitigated.
US
Failed
Covered entities must perform impact assessments of all deployed automated decision systems and augmented critical decision processes, both before and after deployment, evaluating the system's impact on consumers.
US
Failed
Covered entities must attempt to eliminate or mitigate, in a timely manner, any augmented critical decision process that demonstrates a likely material negative impact with legal or similarly significant effects on a consumer's life.
US
Failed
Covered entities must identify and document any likely material negative impact of the automated decision system or augmented critical decision process on consumers, document steps taken to eliminate or mitigate such impacts, document unmitigated impacts with justifying rationale, and document standard protocols for impact identification and staff training.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact across protected characteristics, and (4) compliance with the NIST AI Risk Management Framework.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) system efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact based on race, color, religion, sex, national origin, age, disability, and genetic information, and (4) compliance with the NIST AI Risk Management Framework or successor.
US
Failed
Covered entities must perform impact assessments of each deployed automated decision system and each augmented critical decision process, both prior to and after deployment.
US
Failed
Covered entities must perform impact assessments of all deployed automated decision systems developed for use in augmented critical decision processes, and of all augmented critical decision processes, both prior to and after deployment.
US
Failed
Covered entities must identify and measure all likely material negative impacts of the system on consumers, document steps taken to eliminate or mitigate them, document unmitigated impacts with compelling justification, and document standard protocols for identifying, measuring, mitigating, and eliminating negative impacts including staff training.
US
Failed
Developers and deployers must conduct a preliminary evaluation of the plausibility that any expected or intended use of a covered algorithm may result in harm before deploying, licensing, or offering the algorithm for a consequential action. If no harm is plausible, they must record and submit the finding to the FTC; if harm is plausible, they must proceed to a full pre-deployment evaluation.
US
Failed
Developers and deployers must engage an independent auditor to conduct a full pre-deployment evaluation when harm is plausible, covering the algorithm's design, methodology, training and testing data, demographic representation, testing across protected characteristics, potential for disparate impact, and mitigation recommendations. The independent auditor must submit a report to the developer or deployer.
VA
Failed
Deployers must complete an impact assessment before initial deployment and within 90 days of each significant update. Each assessment must include, at minimum: (1) purpose, use cases, deployment context, benefits, and any reasonably foreseeable algorithmic discrimination risks with mitigation steps; (2) for post-deployment assessments, whether updated use cases varied from the developer's intended uses; (3) categories of input data and outputs; (4) if applicable, data used to customize the system; (5) transparency measures taken; and (6) post-deployment monitoring and user safeguards. Assessments and all associated records must be maintained for a reasonable period. A cross-compliance safe harbor applies for assessments completed under other applicable laws of reasonably similar scope.
VT
Failed
Employers must create a written impact assessment before using any automated decision system, covering system description, data used, outputs, necessity justification, detailed risk assessment (errors, discrimination across protected characteristics, legal-rights chilling, employee health/dignity/privacy/economic impacts), mitigation measures, and methodology. The assessment must be updated upon any significant change to the system.
VT
Failed
Developers must provide deployers with the technical capability to access all information and documentation reasonably required for the deployer to complete an impact assessment under § 1003(c).
VT
Failed
Deployers must complete an impact assessment for each high-risk AI system (1) before initial deployment, (2) annually within 45 days of each calendar year-end, and (3) within 45 days of each significant update. Each assessment must cover purpose, discrimination risks, mitigation steps, data inputs and outputs, retraining data, performance metrics, transparency measures, and post-deployment monitoring. Assessments and all related records must be maintained for at least three years.
VT
Failed
Developers must complete an impact assessment for each generative AI system before offering it in Vermont. The assessment must evaluate intended purpose, extent of use, prior harms, potential harm intensity and breadth, user dependency, vulnerable-population exposure, and outcome reversibility. Assessments and all related records must be retained for at least three years.
WA
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering the tool's purpose, outputs, data types, consistency with the developer's intended-use statement, foreseeable algorithmic discrimination risks, safeguards aligned with ethical AI principles, human oversight mechanisms, and validation methodology. Deployers with fewer than 50 employees are exempt.
WA
Failed
Developers must complete and document an annual impact assessment for each automated decision tool they design, code, or produce, covering the tool's purpose, outputs, data types, foreseeable algorithmic discrimination risks from intended use or foreseeable misuse, ethical AI safeguards, and intended human oversight mechanisms.
WA
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible for any significant update to an automated decision tool.