H-02
Human Oversight & Fairness
Non-Discrimination & Bias Assessment
Deployers must test and formally assess AI systems used in high-stakes contexts for discriminatory impact across protected characteristics before deployment, and document and retain the results.
Sub-obligations10
Bills179
Jurisdictions32
Enacted8
Show
Sort bills within section

10 sub-obligations of H-02

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
H-02.1 Internal bias testing
The developer or deployer must conduct testing across protected characteristics using appropriate statistical methods before deployment.
7Enacted 85Live 73Failed 165Total Jump →
H-02.2 Documented methodology
The testing methodology must be documented in sufficient detail for third-party review, including: protected characteristics tested, statistical measures used, datasets tested, and results.
1Enacted 30Live 18Failed 49Total Jump →
H-02.3 Algorithmic impact assessment
A formal written assessment of the AI system's potential discriminatory impact must be completed before deployment, identifying risks and mitigation measures. Must be retained and available to regulators on request.
5Enacted 78Live 77Failed 160Total Jump →
H-02.4 Regulator submission of assessment
Proactive submission of the impact assessment to a regulatory authority on a defined schedule or upon request.
0Enacted 18Live 6Failed 24Total Jump →
H-02.5 Public disclosure of assessment
Deployers must make the algorithmic impact assessment, in summary or full, publicly available so affected individuals, advocates, and researchers can review the system's discriminatory risks and mitigations; permitted redactions for trade secrets, security, or privilege must be described in the published version.
0Enacted 28Live 12Failed 40Total Jump →
H-02.6 Independent third-party audit
A qualified independent auditor with no material relationship to the developer or deployer must evaluate the system for bias and disparate impact. Currently required primarily for automated employment decision tools.
0Enacted 53Live 20Failed 73Total Jump →
H-02.7 Public disclosure of audit results
Audit results, including selection rates and impact ratios across protected categories, must be published prior to or contemporaneous with deployment.
0Enacted 20Live 13Failed 33Total Jump →
H-02.8 Periodic Post-Deployment Discrimination Review
Deployers must conduct periodic (at least annual) reviews of each deployed high-risk AI system to affirmatively verify the system is not causing algorithmic discrimination, separate from pre-deployment bias assessments. Reviews may be conducted internally or by a contracted third party.
3Enacted 46Live 41Failed 90Total Jump →
H-02.9 Impact Assessment Records Retention
Deployers must retain all impact assessments, associated records, and prior impact assessments for a period of time following the final deployment of each high-risk AI system, and make them available to regulators upon request.
3Enacted 19Live 18Failed 40Total Jump →
H-02.10 Substantive algorithmic discrimination prohibition
Deployers must not use AI or algorithmic decision-making systems in a manner that results in discrimination or disparate impact on the basis of protected characteristics in consequential decision-making contexts.
3Enacted 8Live 4Failed 15Total Jump →
Bills That Map This Requirement 755 mappings
H-02.1
Internal bias testing
The developer or deployer must conduct testing across protected characteristics using appropriate statistical methods before deployment.
Enacted
7
Live
85
Failed
73
Total
165
CO
Enacted eff 2026-02-01
Developers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of their systems.
CO
Enacted eff 2026-02-01
Deployers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
CO
Enacted eff 2026-02-01
Developers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the system. Compliance with this section and AG rules creates a rebuttable presumption of reasonable care in enforcement actions.
CO
Enacted eff 2026-02-01
Deployers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination. Compliance with this section and AG rules creates a rebuttable presumption of reasonable care in enforcement actions.
KY
KY SB 176 (Facial Recognition Technology) § KRS Chapter 61, Section 1(3)
Enacted eff 2022-04-08
The model policy must specify a minimum accuracy standard for face matches across all demographic groups to ensure nondiscrimination, with reference to a NIST Face Recognition Vendor Test.
VA
Enacted eff 2026-07-01
Developers must exercise a reasonable duty of care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of each high-risk AI system. Compliance with all requirements of § 59.1-608 creates a rebuttable presumption that the developer has satisfied this duty.
VA
Enacted eff 2026-07-01
Deployers must exercise a reasonable duty of care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with all requirements of § 59.1-609 creates a rebuttable presumption that the deployer has satisfied this duty.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must conduct performance evaluations of each covered ADS — covering purpose, developer-approved uses, expected accuracy and reliability, intended disparate treatment (with necessity and alternatives analysis), reasonably foreseeable disparate impacts (with necessity, alternatives, and mitigation analysis), and effects of fine-tuning — before initial deployment (for systems first available on or after January 1, 2026; by January 1, 2027 for pre-existing systems), after each substantial modification or material fine-tuning, and at least annually.
NY
Engrossed
Developers and deployers must take reasonable care to prevent foreseeable risk of algorithmic discrimination arising from the use, sale, or sharing of a high-risk AI system or a product featuring a high-risk AI system.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2107
Introduced eff 2026-01-01
Healthcare insurers must ensure that AI algorithms used in the quality assurance testing process are consistent with state and federal antidiscrimination laws and meet defined parameters of safety and fairness.
AZ
Introduced
AI businesses must implement bias mitigation measures, including technical or procedural methods to reduce discriminatory outcomes in high-risk AI systems.
CT
Introduced eff 2026-10-01
Deployers must, before deploying an automated employment-related decision process and annually thereafter, contract with a Labor Commissioner-approved independent auditor to complete a bias audit. The audit must: (A) evaluate performance and error rates across relevant subgroups, (B) assess disparate impact against protected classes, (C) examine data sources and output quality, (D) evaluate threshold, scoring, and ranking criteria effects, and (E) test for less discriminatory alternatives. The auditor must have no financial or operational interest in the deployer or developer and must be approved by the Labor Commissioner.
CT
Introduced eff 2026-10-01
Employers must not use an automated employment-related decision process in any manner that has the effect of causing discriminatory employment actions on the basis of protected characteristics (race, color, religious creed, age, sex, gender identity or expression, marital status, national origin, ancestry, disability status, veteran status, or victim status). In any discrimination action involving an automated process, the commission or court must consider evidence — or lack of evidence — of anti-bias testing or proactive efforts to avoid discrimination, including the quality, efficacy, recency, and scope of such testing, its results, and the employer's response.
GA
Introduced
Developers must not sell, distribute, or otherwise make available to deployers an automated decision system that results in algorithmic discrimination — i.e., that discriminates, causes a disparate impact, or makes unavailable the equal enjoyment of goods, services, or opportunities on the basis of protected characteristics in connection with a consequential decision.
GA
Introduced
Developers must take steps to address risks of algorithmic discrimination, invalidity, and errors, including ensuring suitability and representativeness of data sources, implementing data governance measures, testing for disparate impact, and searching for less discriminatory alternative decision methods. This is a continuing obligation that persists as long as any deployer uses the system. Developers must also disclose to the Attorney General and all known deployers any known or reasonably foreseeable risks of algorithmic discrimination arising from intended uses, without unreasonable delay but no later than 90 days after (A) the developer discovers through ongoing testing that the system has caused or is reasonably likely to have caused algorithmic discrimination, or (B) the developer receives a credible report from a deployer that the system has caused algorithmic discrimination.
GA
Introduced
Deployers must not use an automated decision system in a manner that results in algorithmic discrimination.
IA
Introduced
Developers must use reasonable care to protect individuals from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of their high-risk AI systems. Compliance with the statute's enumerated requirements and attorney general rules creates a rebuttable presumption of reasonable care.
IL
Introduced
Health care entities deploying AI in direct patient care must maintain validation and bias monitoring records for each AI system and make those records available to the Department of Financial and Professional Regulation upon request.
IL
Introduced
Employers must conduct additional impact assessments at least once every 2 years and before any material changes to the automated decision-making system. Each assessment must include, in plain language: (1) a description of the system's objectives; (2) an evaluation of the system's ability to achieve those objectives; (3) a description and evaluation of algorithms, computational models, and AI tools used, including a summary of underlying algorithms and a description of the design and training; (4) testing for: (A) disparate impact or discrimination based on protected characteristics (race, color, religious creed, national origin, sex, disability, gender identity, sexual orientation, genetic information, pregnancy, ancestry, veteran status) and mitigation actions; (B) accessibility limitations for persons with disabilities; (C) privacy and job quality impacts including wages, hours, conditions, and safeguards; (D) cybersecurity vulnerabilities and safeguards; (E) public health or safety risks; (F) foreseeable misuse and safeguards; and (G) use, storage, and control of sensitive or personal data; and (5) a notification mechanism for employees impacted by the system.
IL
Introduced
Auto insurers must demonstrate to the Department of Insurance that their marketing, underwriting, rating, claims handling, fraud investigations, and any algorithm or model used for those practices do not disparately impact customers on the basis of race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression.
IN
Introduced eff 2026-07-01
Employers must ensure that any automated decision system used to generate output for employment-related decisions has undergone predeployment testing and validation covering: (i) efficacy of the system; (ii) compliance with enumerated federal employment discrimination statutes (Title VII, ADEA, ADA Title I, GINA Title II, Equal Pay Act, Rehabilitation Act Sections 501/505, Pregnant Workers Fairness Act); (iii) absence of discriminatory impact based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, and genetic information (including family medical history); and (iv) compliance with the NIST AI Risk Management Framework (January 26, 2023) or a successor framework.
LA
Introduced
Covered insurers must not use an ADS that intentionally considers protected-class membership, uses proxy variables producing disparate impact without actuarial justification and least-discriminatory-alternative showing, or produces arbitrary or capricious decisions. Six enumerated variable categories are presumptive proxy variables subject to heightened scrutiny and burden-shifting.
LA
Introduced
Covered insurers must conduct an annual disparate impact audit of each ADS, performed by a qualified independent actuary (FCAS/FSA/FAAA) or data scientist with algorithmic-fairness expertise, analyzing outcomes disaggregated by protected class and geographic area, assessing each variable's contribution, evaluating less discriminatory alternatives, and documenting methodology, findings, and corrective actions.
MA
Introduced
Employers must not use an automated employment decision tool unless it has undergone an independent impact assessment within the prior year evaluating scientific validity of attributes, protected-class proxy risk, training data disparities, output disparate impact, disability accessibility, post-deployment discrimination risks, and privacy/job quality impacts. Results must be submitted to the Department of Labor Standards within 60 days for inclusion in a public registry and distributed to affected employees.
MA
Introduced
Developers must use reasonable care to identify, mitigate, and disclose risks of algorithmic discrimination in their AI systems. This is a general duty of care applicable to all AI systems, not limited to high-risk systems.
MA
Introduced
Developers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the system. Compliance with Section 2 and any attorney general rules creates a rebuttable presumption that the developer exercised reasonable care.
MA
Introduced
Deployers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination. Compliance with Section 3 and any attorney general rules creates a rebuttable presumption that the deployer exercised reasonable care.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MA
MA SB 46 (AI in Healthcare Decision-Making) § M.G.L. c. 176O, § 12(g)
Introduced
Carriers and utilization review organizations must ensure that the use of AI, algorithms, or other software tools does not discriminate, directly or indirectly, against any insured in violation of state or federal law (including Chapter 151B), is fairly and equitably applied in accordance with applicable regulations and guidance, and does not directly or indirectly cause harm to the insured.
MD
MD HB 1385 (Health Insurance AI Human Evaluation) § Md. Code Ann., Insurance § 15–10B–05.1(c)
Introduced eff 2026-10-01
Covered entities must ensure that the use of AI, algorithms, or other software tools for utilization review does not result in unfair discrimination, and that such tools are fairly and equitably applied, including in accordance with any applicable regulations and guidance issued by the federal Department of Health and Human Services.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must maintain an overall algorithmic error rate below 0.5% compared to human review, discriminatory data rates based on protected characteristics below 0.1%, and data input accuracy of at least 99.9%.
MD
MD HB 795 (AI Health Insurance Accountability) § Md. Code Ann., Insurance § 15–10B–05.1
Introduced eff 2026-10-01
Carriers must ensure that AI, algorithm, or other software tools used in utilization review do not result in unfair discrimination and are fairly and equitably applied, including in accordance with any applicable regulations and guidance issued by the federal Department of Health and Human Services.
MI
Introduced
Before using any automated decisions tool or electronic monitoring tool, employers must commission an impact assessment by an independent and impartial third party with no financial or legal conflicts of interest. The assessment must be conducted one year before implementation (or within 6 months of the act's effective date for tools already in use) and must: (a) evaluate the tool's objectives, algorithms, data, cybersecurity vulnerabilities, and potential biases including discriminatory outcomes based on race, gender, or disability; (b) identify the attributes and modeling techniques the tool uses; (c) evaluate whether those attributes are scientifically valid means of evaluating performance and whether they may function as proxies for protected classes under the Elliott-Larsen Civil Rights Act; (d) identify disparate-impact risks in training data and outputs and describe remedial actions; (e) evaluate disability accessibility limitations and describe remedies; (f) describe potential sources of post-implementation adverse impact; (g) assess whether any feature causing disparate impact is the least discriminatory method available; (h) identify other potential legal violations and steps to prevent them; and (i) describe potential negative effects on privacy, wages, hours, and working conditions.
NJ
Introduced
Each bias audit must calculate selection rates or scoring rates and impact ratios for each protected category — including sex, race/color/national origin/ethnicity, age, marital/familial status, disability, religion, sexual orientation, gender identity, income source, and intersectional categories of sex, ethnicity, and race — and must indicate the number of individuals excluded from calculations because they fall within an unknown category. Categories representing less than two percent of the audit data may be excluded from impact-ratio calculations if justified and disclosed.
NJ
Introduced
Employers using AI analysis of video interviews to screen for in-person interviews must collect demographic data on the race and ethnicity of applicants who are and are not selected for in-person interviews, and of applicants who are offered positions or hired.
NJ
Introduced
Employers, public entities, and vendors must not use AEDS, ABSDS, EMT, or surveillance to obtain, infer, analyze, or use protected-class characteristics, union membership, or any classification not directly related to work performance, qualifications, or benefit eligibility in employment or public-benefit decisions. A narrow carve-out permits ABSDS to retain information essential to specific public services (e.g., student records, health information) and eligibility determination.
NJ
Introduced
Bias audits must calculate selection rates, scoring rates, and impact ratios for each EEO-1 category, separately analyzed across sex, race/ethnicity, and intersectional categories, and must report the number of individuals in unknown categories. Categories representing less than two percent of the data may be excluded if the auditor provides justification and reports the excluded category's applicant count and rate.
NJ
Introduced
Employers using AI analysis of video interviews to determine in-person interview selection must collect demographic data on the race and ethnicity of applicants who are and are not afforded in-person interviews, and of applicants who are offered positions or hired.
NJ
Introduced
Employers that use AI analysis of video interviews to determine whether an applicant will be selected for an in-person interview must collect demographic data on (1) the race and ethnicity of applicants who are and are not afforded the opportunity for an in-person interview after AI analysis, and (2) the race and ethnicity of applicants who are offered a position or hired.
NJ
Introduced
Employers, public entities, and vendors must, before deploying an AEDS or EMT, have an independent auditor (or the Department of Labor for public-employee systems) conduct and affirm an impact assessment confirming Section 2 compliance, disparate-impact analysis, and human-oversight procedures, updated within one year before deployment and re-run on any substantial change.
NJ
Introduced
Public entities and vendors must not deploy an ABSDS unless the Department of Labor conducts and affirms an impact assessment confirming Section 2 compliance, analyzing training-data disparities and disparate adverse impact on beneficiaries, and requiring human-oversight procedures to prevent harmful outcomes including erroneous fraud-based benefit denials; re-run on any substantial change.
NJ
Introduced
State entities must cooperate with biannual Office audits of their high-risk algorithmic systems assessing intended purpose, data inputs, potential bias or disparate impact, and risk mitigation, and must develop and implement a corrective action plan within the director's timeframe if the Office identifies bias or discrimination risk. Audit summaries must be suitable for public disclosure.
NJ
Introduced
Covered entities (and their agents, third-party vendors, model developers, and external data sources) must not use an automated decision system in a manner that results in a disparate impact on a protected class in housing or credit decisions. An affirmative defense is available where the entity demonstrates a substantial, legitimate, nondiscriminatory purpose and the absence of any less discriminatory alternative.
NJ
Introduced
Deployers of AI systems must not produce AI-driven discrimination — output exhibiting biases against individuals based on age, race, religion, or other protected classes. Deployers must not engage in unreasonable AI workplace surveillance — using AI to monitor and analyze employee behavior and performance through tracking employee activities including computer usage and physical movements. The Attorney General may investigate complaints and enforce penalties under the Law Against Discrimination and the New Jersey Civil Rights Act.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Persons developing and deploying automated systems must ensure that no New York resident faces algorithmic discrimination and that all automated systems are used and designed in an equitable manner.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Designers, developers, and deployers of automated systems must take proactive and continuous measures to protect against algorithmic discrimination, including: (1) proactive equity assessments as part of system design, (2) use of representative data, (3) protection against proxies for demographic features, and (4) assurance of accessibility for persons with disabilities in design and development.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Persons developing and deploying automated systems must conduct pre-deployment and ongoing disparity testing and mitigation under clear organizational oversight.
NY
Introduced
Employers with 100 or more employees must not use an AEDT for any employment decision unless the tool has been subjected to a disparate-impact assessment, conducted within the prior year by an impartial auditor with no financial or legal conflicts of interest. The assessment must identify modeling techniques, evaluate disparate impact on protected classes, assess whether the tool uses the least discriminatory method, and be submitted to the Department of Labor for a public registry within 60 days of completion and distributed to affected employees.
NY
Introduced
Employers must conduct, no less than annually, a disparate impact analysis — conforming to the EEOC Uniform Guidelines on Employee Selection Procedures — assessing the actual impact of any automated employment decision tool used to select candidates for jobs within the state. The analysis must differentiate between selected and non-selected candidates across sex, race, ethnicity, and other protected classes. The full analysis must be provided to the employer but is not publicly filed and is subject to all applicable privileges.
NY
Introduced
Landlords must have an independent auditor conduct an annual disparate impact analysis assessing the actual impact of each automated decision tool used to screen housing applicants, including testing for adverse impact on the basis of sex, race, ethnicity, or other protected class.
NY
Introduced
Banks must annually (1) have an independent auditor conduct a disparate impact analysis assessing each automated decision tool used for lending decisions, differentiating between approved and non-approved applicants across protected classes, and (2) submit a summary of the most recent analysis and the tool's distribution date to the Attorney General's office.
NY
NY AB 3991 (AI in Utilization Review) § Insurance Law § 3224-e
Introduced
Health care service plans must ensure that AI, algorithms, or other software tools used in utilization review or utilization management do not adversely discriminate, directly or indirectly, against any individual on the basis of race, color, religion, national origin, ancestry, age, sex, gender, gender identity, gender expression, sexual orientation, present or predicted disability, expected length of life, degree of medical dependency, quality of life, or other health conditions. The tools must be fairly and equitably applied.
NY
Introduced
Developers of high-risk AI decision systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses. A rebuttable presumption of reasonable care applies if the developer complies with all requirements of this section and retains an independent third-party auditor — from a list the attorney general publishes at least annually — to complete bias and governance audits for the system.
NY
Introduced
Deployers of high-risk AI decision systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A rebuttable presumption of reasonable care applies if the deployer complies with all requirements of § 1552 and retains an AG-identified independent third-party auditor to complete bias and governance audits for the system.
NY
Introduced
Covered entities must conduct an impact assessment of each automated lending decision-making tool at least annually and prior to any material change, signed by an individual responsible for meaningful human review. The assessment must include bias and discrimination testing across enumerated protected characteristics, algorithm and training data descriptions, cybersecurity and privacy risk evaluation, misuse scenario analysis, and sensitive data handling practices. A summary report must be posted on the covered entity's website before initial deployment and updated after each subsequent assessment.
NY
Introduced
Real estate brokers using virtual agents and online housing platforms using virtual agents or AI tools must have an independent disparate impact analysis conducted at least annually. The analysis must test whether the automated tool produces adverse impacts across protected classes (sex, race, ethnicity, and other classes under the Human Rights Law), whether any differentiation serves a substantial, legitimate, nondiscriminatory interest, and whether a less discriminatory alternative exists. Covered entities must submit a summary of the most recent disparate impact analysis to the attorney general's office.
NY
Introduced
Real estate brokers and online housing platforms using virtual agents or AI tools must proactively identify discriminatory algorithmic results and modify their virtual agents or AI tools to adopt less discriminatory alternatives. This includes assessing the data used to train such systems and verifying that use of such data does not predict discriminatory outcomes.
NY
Introduced
Real estate brokers and online housing platforms must ensure that the AI or algorithmic systems underlying their virtual agents or AI tools are similarly predictive across groups on the basis of sex, race, ethnicity, or other protected classes. They must make adjustments to correct any identified disparities in predictiveness for any such groups.
NY
Introduced
Real estate brokers and online housing platforms must conduct regular end-to-end testing of their advertising, captioning, and chatbot systems to ensure that discriminatory outcomes are detected. Testing must include comparing the delivery of advertisements across different demographic audiences.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 102
Introduced
Developers and deployers must not offer, license, promote, sell, or use a covered algorithm in a manner that causes or contributes to disparate impact, otherwise discriminates, or makes unavailable the equal enjoyment of goods, services, or other activities or opportunities related to a consequential action on the basis of a protected characteristic. Exceptions exist for self-testing or auditing to identify, prevent, or mitigate discrimination; expanding applicant pools to increase diversity or redress historic discrimination; and good-faith non-commercial research.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Developers and deployers must, prior to deploying, licensing, or offering a covered algorithm for a consequential action (including material changes), conduct a preliminary evaluation of the plausibility that any expected or intended use may result in a harm. If harm is not plausible, the developer or deployer must record a finding of no plausible harm — including a description of expected/intended use, how the evaluation was conducted, and an explanation — and submit it to the Division of Consumer Protection. If harm is plausible, a full pre-deployment evaluation by an independent auditor is required. Material changes to previously-deployed algorithms trigger re-evaluation, which may be scoped to the change.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Developers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: the algorithm's design and methodology (inputs and outputs); creation, training, and testing details (performance metrics, benchmarks, demographic representation, testing outputs, stakeholder consultation, protected-characteristic testing methodology); precursor algorithms; data sources, types, legal authorization, and representativeness; training process details; potential for harm or disparate impact; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the developer.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: how the algorithm makes or contributes to a consequential action and its deployment purpose; necessity and proportionality relative to the baseline process being replaced; data inputs (type, collection, inference, processing, legal authorization, representativeness); expected and actual testing outputs; additional testing or training conducted by the deployer; stakeholder consultation; potential for harm or disparate impact in the deployment context; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the deployer.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must cease using an automated employment decision tool upon a finding of disparate impact until the employer has (1) taken reasonable steps to remedy the disparate impact, and (2) if the employer believes the finding is erroneous or remediated, submitted to the Commissioner a demonstration that the tool is the least discriminatory method of assessing employee performance or ability.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Deployers must not use an automated employment decision tool in a manner that violates the New York Human Rights Law (Executive Law Article 15).
NY
NY SB 7896 (AI Utilization Review) § Pub. Health Law § 4905-a(1)
Introduced
Utilization review agents must ensure that AI tools used for utilization review do not discriminate, directly or indirectly, against enrollees in violation of state or federal law, and that such tools are fairly and equitably applied in accordance with applicable HHS regulations and guidance.
NY
NY SB 7896 (AI Utilization Review) § Ins. Law § 4905-a(1)
Introduced
Disability insurers must ensure that AI tools used for utilization review or utilization management do not discriminate, directly or indirectly, against insureds in violation of state or federal law, and that such tools are fairly and equitably applied in accordance with applicable HHS regulations and guidance.
NY
Introduced
Covered entities must conduct at least annual impact assessments of each automated lending decision-making tool — signed by a responsible human reviewer — covering accuracy, fairness, bias, discrimination across protected characteristics, cybersecurity, privacy, safety, misuse risks, data practices, and notification mechanisms, and must publish a summary report on their website before deployment and after each subsequent assessment. An additional assessment is required before any material change to the tool.
PA
Introduced
Facilities must ensure that AI-based algorithms and training data sets do not directly or indirectly discriminate against patients in violation of federal or state law. The algorithms must be fairly and equitably applied, including in accordance with applicable HHS regulations and guidance.
PA
Introduced
Insurers must ensure that AI-based algorithms and training data sets do not directly or indirectly discriminate against covered persons in violation of federal or state law. The algorithms must be fairly and equitably applied in accordance with applicable HHS regulations and guidance.
PA
Introduced
MA or CHIP managed care plans must ensure that AI-based algorithms and training data sets do not directly or indirectly discriminate against enrollees in violation of federal or state law. The algorithms must be fairly and equitably applied in accordance with applicable HHS regulations and guidance.
PA
Introduced
Facilities must ensure that AI-based algorithms and their training data sets do not directly or indirectly discriminate against patients in violation of federal or state law, and must be fairly and equitably applied in accordance with applicable HHS regulations and guidance.
PA
Introduced
Insurers must ensure that AI-based algorithms and training data sets used in utilization review do not directly or indirectly discriminate against covered persons in violation of federal or state law, and must be fairly and equitably applied in accordance with applicable HHS regulations and guidance.
PA
Introduced
MA or CHIP managed care plans must ensure that AI-based algorithms and training data sets used in utilization review do not directly or indirectly discriminate against enrollees in violation of federal or state law, and must be fairly and equitably applied in accordance with applicable HHS regulations and guidance.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-3
Introduced eff 2025-10-01
Developers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the system.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-4
Introduced eff 2025-10-01
Integrators must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of integrated high-risk AI systems.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
TX
TX HB 5282 (AI Assessment Scoring) § Educ. Code § 39.023(q)–(r)
Introduced eff 2025-09-01
Before the agency may permit an AI scoring method for constructed responses, the method must (1) have been trained on representative samples including responses from educationally disadvantaged, emergent bilingual, and special-education-eligible students, (2) demonstrate validity and reliability consistent with industry-accepted standards including NAEP standards, and (3) be evaluated and certified by a qualified independent entity — unaffiliated with TEA or the scoring method developer — as valid, reliable, free of measurable bias against disadvantaged students, and compliant with applicable psychometric standards.
TX
TX HB 5496 (AI Transparency) § Bus. & Com. Code § 611.002
Introduced eff 2025-09-01
Persons using AI in conducting business or providing goods or services to Texas residents must ensure that AI does not demonstrate bias or discriminate against any individual on the basis of any legally protected classification.
US
Introduced
Covered entities must perform ongoing testing and evaluation of covered algorithms for differential performance across consumers' race, color, sex, gender, age, disability, religion, family status, socioeconomic status, veteran status, and any other characteristics the FTC deems appropriate, including documenting the methodology, proxy data methods used, and any subpopulation testing.
US
Introduced
Employers must ensure that any automated decision system used to generate outputs for employment-related decisions has undergone pre-deployment testing and validation for efficacy, compliance with seven enumerated federal employment discrimination laws, absence of discriminatory impact across protected characteristics, and compliance with the NIST AI RMF. The system must also be independently tested at least annually for discriminatory impact and bias, with results made publicly available.
US
Introduced
Covered entities must perform ongoing testing and evaluation of system performance using benchmarking datasets and historical data, document performance metrics and success criteria, compare test-condition and deployed-condition performance, evaluate differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status (including proxy data methods), and document any subpopulations used in testing.
US
Introduced
Developers and deployers must conduct a preliminary evaluation of whether any expected or intended use of a covered algorithm may plausibly result in harm before deployment, licensing, or offering. If no harm is plausible, a documented finding must be recorded and submitted to the FTC. If harm is plausible, a full pre-deployment evaluation by an independent auditor is required.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering design, methodology, training data, testing across protected characteristics, stakeholder consultation, potential for disparate impact, and mitigation recommendations. The auditor must submit a report with findings and recommendations.
WA
Introduced eff 2027-01-01
Developers must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the high-risk AI system. Compliance with all requirements of Section 2 creates a rebuttable presumption that the developer used reasonable care. Conformity with the NIST AI RMF, ISO/IEC 42001, or another nationally or internationally recognized AI risk management framework creates a further presumption of conformity with Section 2's requirements.
WA
Introduced eff 2027-01-01
Deployers must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination. Compliance with all provisions of Section 3 creates a rebuttable presumption of reasonable care.
WA
Introduced eff 2026-07-01
Deployers must use industry-standard means to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from each deployed high-risk AI system. Compliance with the full chapter creates a rebuttable presumption of reasonable care in any attorney general enforcement action.
WA
Introduced eff 2027-01-01
Developers must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of each high-risk AI system. Compliance with all of Section 2's requirements creates a rebuttable presumption that reasonable care was used.
WA
Introduced eff 2027-01-01
Deployers must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with all of Section 3's requirements creates a rebuttable presumption that reasonable care was used.
WA
Introduced
Deployers must use industry-standard means to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the deployment of a high-risk AI system. Compliance with the chapter creates a rebuttable presumption of reasonable care in enforcement actions.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.6
Failed
Deployers must not use an automated decision tool that results in algorithmic discrimination — unjustified differential treatment or impacts disfavoring people based on any protected classification under California law.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.6
Failed
Developers must not make available to potential deployers an automated decision tool that results in algorithmic discrimination.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.6
Failed
Deployers must not use an automated decision tool in a manner that contributes to algorithmic discrimination — unjustified differential treatment or impacts disfavoring people based on any classification protected by state law.
CA
CA SB 503 (Healthcare AI Bias Testing) § Health & Safety Code § 1339.76(c)
Failed
Developers of AI models or AI systems must, in conjunction with health facilities, clinics, physician's offices, or offices of group practices, test for biased impacts in the outputs produced by the AI model or AI system based on the health facility's patient population. Developers must use an existing testing system designated by the advisory board until the board develops its own standardized testing system, at which point developers may alternatively use the board's system. After the board creates its certification, developers may optionally use the board's standardized testing system to certify their AI models or AI systems.
CO
Failed
Developers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses. Compliance with this section and attorney general rules creates a rebuttable presumption of reasonable care.
CO
Failed
Deployers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination. Compliance with this section and attorney general rules creates a rebuttable presumption of reasonable care.
CO
Failed
Developers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of those systems.
CO
Failed
Deployers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
CO
Failed
Developers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the system's intended and contracted uses, effective June 30, 2026.
CO
Failed
Deployers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination, effective June 30, 2026.
CT
Failed
Developers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses of the system.
CT
Failed
Integrators must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of any high-risk AI system they integrate into a product or service.
CT
Failed
Deployers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information availability determination practices to (1) determine whether practices discriminate in violation of § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a per-determination audit trail recording the determination type, data and sources, algorithm methodology, training data, subgroup performance testing results, methodology, and ultimate decision, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with relevant third parties including service providers, and (6) identify and implement reasonable measures to remediate identified disparate-impact risks, including risks from service-provider determinations.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate under § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a detailed audit trail recording determination type, data, sources, methodology, algorithm, training data, subgroup testing results, and ultimate decision for each determination, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable mitigation measures for disparate-impact risks.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate on the basis of protected characteristics, (2) analyze disparate-impact risks, (3) create and retain for at least five years a detailed audit trail for each determination (recording type, data, sources, methodology, training data, subgroup testing results, algorithm, and decision), (4) conduct annual impact assessments of existing systems and pre-implementation impact assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable measures to mitigate identified disparate-impact risks.
IL
Failed
Proprietors of diagnostic algorithms must regularly evaluate their algorithms for biases and discrimination against protected categories under the Illinois Human Rights Act and report findings annually to the Department of Public Health and the Department of Innovation and Technology.
IL
Failed
Proprietors must, upon a finding by the departments that the diagnostic algorithm has perpetuated biases or discrimination against Illinois Human Rights Act protected categories, remediate the identified biases within 3 months or face certification revocation.
IL
IL HB 5115 (Diagnostic Algorithm) § 210 ILCS 85/6.35
Failed
Proprietors of diagnostic algorithms must regularly evaluate their algorithms for biases and discrimination against protected categories under the Illinois Human Rights Act and report findings annually to the Department of Public Health and the Department of Innovation and Technology.
IL
IL HB 5115 (Diagnostic Algorithm) § 210 ILCS 85/6.35
Failed
Proprietors must, upon a finding by the departments that the diagnostic algorithm has perpetuated biases or discrimination against Illinois Human Rights Act protected categories, remediate the identified biases within 3 months or face certification revocation.
IL
Failed
Deployers must not use an automated decision tool that results in algorithmic discrimination — unjustified differential treatment or impacts disfavoring people based on protected characteristics. A private right of action is available beginning January 1, 2027, requiring proof of actual harm.
IL
Failed
Deployers must not use an automated decision tool that results in algorithmic discrimination — unjustified differential treatment or impacts disfavoring people based on protected characteristics including race, color, ethnicity, sex, religion, age, national origin, limited English proficiency, disability, veteran status, genetic information, or reproductive health. Beginning January 1, 2028, individuals who suffer actual harm from algorithmic discrimination may bring a civil action for compensatory damages, declaratory relief, and attorney's fees.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5002
Failed
Developers must take reasonable precautions to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended uses of a high-risk AI system they produce.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5003
Failed
Deployers must take reasonable precautions to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination posed by the intended uses of a deployed high-risk AI system.
MD
MD SB 957 (Automated Employment Decision Tools) § Md. Code, Lab. & Empl. § 3–718(B)–(C)
Failed
Employers must not use an automated employment decision tool to screen applicants or determine employment terms unless the tool (1) was subject to an impact assessment in the year before first use, (2) undergoes an annual impact assessment each year of use, and (3) each assessment determines the tool would not involve a high-risk action likely to result in unlawful discrimination or disparate impact.
MN
Failed
Agency heads must establish testing procedures for facial recognition systems, in consultation with NIST, that (1) periodically test system performance in operational conditions, (2) identify error rates across subpopulations by skin tone, age, and gender, and (3) take action to improve accuracy when disparate error rates are found.
MN
MN HF 465 (Facial Recognition Technology) § Minn. Stat. § 626A.53
Failed
Each agency head must, in consultation with NIST, establish testing procedures for facial recognition systems that (1) periodically conduct independent performance tests under operational conditions, (2) identify disparate error rates across subpopulations by skin tone, age, and gender, and (3) take corrective action to improve accuracy when disparities are found.
MT
Failed eff 2025-05-20
Health insurance issuers must ensure that AI, algorithms, or other software tools used in utilization review do not discriminate, directly or indirectly, against enrollees in violation of state or federal law, including MCA § 49-2-309, and are fairly and equitably applied in accordance with applicable federal HHS regulations and guidance.
NY
Failed
Employers must conduct at least annually a disparate impact analysis — conforming to the EEOC Uniform Guidelines on Employee Selection Procedures — assessing the actual impact of any automated employment decision tool used to select candidates for jobs within the state, differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must conduct at least an annual disparate impact analysis assessing the actual impact of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers must take proactive and continuous measures to prevent algorithmic discrimination, including proactive equity assessments during system design, use of representative data, protection against proxies for demographic features, and accessibility assurance for persons with disabilities.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers must conduct both pre-deployment and ongoing disparity testing and mitigation for all automated systems, under clear organizational oversight.
NY
Failed
Employers must not use an automated employment decision tool unless the tool has been the subject of a bias audit conducted within the past year by an independent, impartial auditor with no financial or legal conflicts of interest. The audit must (1) identify modeling techniques and attributes, (2) evaluate scientific validity and proxy-variable risk for protected classes, (3) assess training data and output disparities and recommend remedial actions, (4) evaluate disability accessibility limitations, (5) determine whether features causing disparate impact are the least discriminatory method available, and (6) be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Failed
Where a bias audit finds disparate impact or accessibility limitations, employers must (1) take reasonable steps to reduce or remedy the impact and describe those steps in writing to employees, the auditor, and the department; or (2) if the employer disputes the finding, explain in writing why the tool is the least discriminatory method available; or (3) if the finding results from a lawful affirmative action plan, describe that plan in writing to employees, the auditor, and the department.
NY
Failed
Employers must conduct at least annual disparate impact analyses of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must not use any AEDT unless it has been the subject of an impact assessment conducted by an independent auditor within the past year (or within six months of the effective date for pre-existing tools). The assessment must evaluate the tool's attributes and modeling techniques for scientific validity, proxy-variable risk across protected classes, training-data disparities, output-level disparate impact, disability accessibility, post-deployment discrimination risk, and least-discriminatory-method analysis. The completed assessment or an accessible summary must be submitted to the Department of Labor for inclusion in a public registry within 60 days and distributed to affected employees.
NY
Failed
Deployers must not use an automated employment decision tool in a manner that violates the New York Human Rights Law (Executive Law Article 15), which prohibits employment discrimination based on protected characteristics.
NY
Failed
Vendors must conduct a disparate impact report at least one year before selling or offering for sale an automated employment decision tool, and must file annual public disclosure reports with the Department of Labor that include the most recent disparate impact results and the vendor's disability accommodation policy.
NY
Failed
Employers must not use an automated employment decision tool unless it has been subjected to an independent bias audit conducted no more than one year prior to use (or within six months for tools in use at enactment). The audit must be conducted by an independent party with no conflicts of interest and must: identify modeling techniques and attributes; evaluate scientific validity and proxy-for-protected-class risk; analyze training data and output disparities across protected classes; evaluate disability accessibility impacts; assess all residual discrimination risks; and for any disparate impact finding, evaluate whether the feature at issue is the least discriminatory method. The audit must be submitted to the Department of Labor within sixty days and distributed to affected employees.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers of automated systems must take proactive and continuous measures to protect residents from algorithmic discrimination and must ensure all automated systems are used and designed in an equitable manner.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers must conduct proactive equity assessments during system design, use representative data, implement protections against demographic-proxy variables, ensure accessibility for persons with disabilities, and conduct both pre-deployment and ongoing disparity testing and mitigation under clear organizational oversight.
OK
Failed
Deployers must conduct assessments of AI systems to identify potential biases in training data, risks to safety, civil liberties, and fundamental rights, and mitigation strategies for identified risks.
OK
Failed
Entities must ensure their AI systems do not discriminate through algorithmic or model bias based on age, race, national origin, sex, disability, pregnancy, religious beliefs, veteran status, or any other legally protected classification, to the same extent as if the discrimination were perpetrated by a real person.
OK
OK HB 3835 (Ethical AI Act) § 75A O.S. § 1006
Failed
Deployers must not use an automated decision tool that results in algorithmic discrimination — unjustified differential treatment or impacts disfavoring people on the basis of any protected class under federal or Oklahoma law. Harmed parties may file a complaint with the Attorney General and bring a civil action.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-7
Failed
Deployers must not use an automated decision tool that results in algorithmic discrimination — unjustified differential treatment or impacts disfavoring people based on protected characteristics.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must conduct a design evaluation for each CAIDS that considers information relevant to the potential for unlawful bias in connection with the system's intended end use.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must conduct a design evaluation for each CAIDS that considers information relevant to the potential for unlawful bias in connection with the system's intended end use.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.003
Failed
Developers must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of their high-risk AI systems.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.004
Failed
Distributors must use reasonable care to protect consumers from algorithmic discrimination risks and must immediately withdraw, disable, or recall any non-compliant high-risk AI system from the market, notifying affected developers and deployers.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.005
Failed
Deployers must use reasonable care to protect consumers from algorithmic discrimination risks and must immediately suspend use of any non-compliant high-risk AI system, notifying developers and distributors.
TX
TX HB 4695 (AI Mental Health Services) § Health & Safety Code § 616.004
Failed
Persons providing AI mental health services must not discriminate against individuals on the basis of race, ethnicity, gender, sexual orientation, or any other characteristic.
US
Failed
Online platforms must not employ an algorithmic process that is not safe and effective: the process must either produce no disparate outcome across protected characteristics, or any disparate outcome must be justified by a non-discriminatory compelling interest that cannot be satisfied by less discriminatory means. Platforms must also take reasonable steps to ensure the process can produce its intended result.
US
Failed
Online platforms must not employ an algorithmic process that is not safe and effective. An algorithmic process is safe only if it produces no disparate outcome across protected characteristics, or any disparate outcome is justified by a non-discriminatory compelling interest that cannot be satisfied by less discriminatory means. An algorithmic process is effective only if the platform has taken reasonable steps to ensure it can produce its desired result.
US
Failed
Covered entities must perform ongoing testing and evaluation of system performance, including documenting performance metrics and success criteria, comparing test and deployed conditions, evaluating differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status, describing proxy data methods used, and identifying and documenting mitigation steps for material negative impacts including the rationale for any impacts left unmitigated.
US
Failed
Law enforcement agencies must not use any facial recognition system unless it has been annually submitted to NIST's benchmark test for law enforcement and has achieved a sufficiently high level of accuracy, including non-discriminatory variance by race, ethnicity, gender, and age, as determined by NIST.
US
Failed
Law enforcement agencies must not begin using any new facial recognition system unless it has first been submitted to independent testing for accuracy and demographic bias.
US
Failed
Law enforcement agencies must annually submit their facial recognition systems to operational testing by an independent entity, using NIST's protocol, to determine system accuracy, impact of human reviewers on accuracy, and whether accuracy varies by race, ethnicity, gender, orage.
US
Failed
Covered entities must perform ongoing testing and evaluation of automated decision system performance, including evaluating differential performance across consumers' race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status, documenting methodology and any use of proxy data.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact across protected characteristics, and (4) compliance with the NIST AI Risk Management Framework.
US
Failed
Online platforms must not employ algorithmic processes that are not safe and effective. An algorithmic process is safe only if it produces no disparate outcomes across protected characteristics, or any disparate outcome is justified by a non-discriminatory compelling interest not satisfiable by less discriminatory means. An algorithmic process is effective only if the platform has taken reasonable steps to ensure it produces its intended result.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) system efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact based on race, color, religion, sex, national origin, age, disability, and genetic information, and (4) compliance with the NIST AI Risk Management Framework or successor.
US
Failed
Covered entities must perform ongoing testing and evaluation of automated decision system performance, including documenting success metrics, test vs. deployed performance, and differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, veteran status, and any other FTC-designated characteristics, including methodology and proxy-data methods used.
US
Failed
Covered entities must perform ongoing testing and evaluation of system performance using benchmarking datasets and historical data, including documenting performance metrics, test and deployed condition results, and evaluation of differential performance across protected characteristics (race, color, sex, gender, age, disability, religion, family status, socioeconomic status, veteran status) using documented methodology including proxy data methods.
US
Failed
Developers and deployers must not offer, license, promote, sell, or use a covered algorithm in a manner that causes or contributes to disparate impact, otherwise discriminates in, or makes unavailable the equal enjoyment of goods, services, or opportunities related to a consequential action on the basis of a protected characteristic. Exceptions apply for self-testing to identify or mitigate discrimination and for expanding applicant pools to increase diversity.
VA
Failed
State agencies must ensure that any automated decision system used as a substantial factor in employment decisions, and the agency's use of that system, complies with federal and state law, including the Virginia Human Rights Act.
VA
Failed
State agencies must annually test the automated decision system for algorithmic discrimination — either directly or through an appropriate contractor — and certify the system's compliance with federal and state law.
VA
Failed
Local government entities must ensure that any automated decision system used as a substantial factor in employment decisions, and the entity's use of that system, complies with federal and state law, including the Virginia Human Rights Act.
VA
Failed
Local government entities must annually test the automated decision system for algorithmic discrimination — either directly or through a contractor — and certify compliance with federal and state law.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-605
Failed
Deployers must avoid any risk of algorithmic discrimination that is a reasonably foreseeable consequence of deploying or using a high-risk AI system to make a consequential decision.
VT
Failed
Developers must use reasonable care to avoid any risk of algorithmic discrimination that is a reasonably foreseeable consequence of developing or substantially modifying a high-risk AI system. Compliance with the remaining § 1002 requirements creates a rebuttable presumption of reasonable care.
VT
Failed
Deployers must use reasonable care to avoid any risk of algorithmic discrimination that is a reasonably foreseeable consequence of deploying or using a high-risk AI system to make a consequential decision. Compliance with the remaining § 1003 requirements creates a rebuttable presumption of reasonable care.
WA
Failed
Deployers must not use an automated decision tool that results in algorithmic discrimination. A violation constitutes an unfair practice under the Washington Law Against Discrimination (Chapter 49.60 RCW), enforceable through the Human Rights Commission or a private civil action.
WA
Failed
Automated decision systems may not discriminate against an individual or treat an individual less favorably than another on the basis of protected characteristics enumerated in RCW 49.60.010, except where a criterion is specifically mandated by state or federal law. Violations constitute an unfair practice under Washington's Law Against Discrimination.
H-02.2
Documented methodology
The testing methodology must be documented in sufficient detail for third-party review, including: protected characteristics tested, statistical measures used, datasets tested, and results.
Enacted
1
Live
30
Failed
18
Total
49
VA
Enacted eff 2026-07-01
Deployers must complete a detailed impact assessment for each high-risk AI system before initial deployment and before each significant update. The impact assessment must include at minimum: purpose and use case disclosure, algorithmic discrimination risk identification and mitigation steps, data input and output categories, customization data categories, performance metrics and limitations, transparency measures, post-deployment monitoring descriptions, and validity and reliability analysis. A single assessment may cover comparable systems. Impact assessments completed for other applicable laws are accepted if reasonably similar in scope. Assessments and all records must be retained for three years.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must conduct performance evaluations of each covered ADS — covering purpose, developer-approved uses, expected accuracy and reliability, intended disparate treatment (with necessity and alternatives analysis), reasonably foreseeable disparate impacts (with necessity, alternatives, and mitigation analysis), and effects of fine-tuning — before initial deployment (for systems first available on or after January 1, 2026; by January 1, 2027 for pre-existing systems), after each substantial modification or material fine-tuning, and at least annually.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed eff 2026-01-01
Developers must make the statements from their impact assessment available to deployers and potential deployers. The impact assessment must include: (1) a statement of purpose, intended benefits, intended uses, and intended deployment contexts; (2) a description of intended outputs; (3) a summary of data types used as inputs and recommended processing; (4) a summary of reasonably foreseeable disproportionate or unjustified impacts on protected classifications; (5) a description of safeguards to mitigate known algorithmic discrimination risks; (6) a description of how deployers can monitor for algorithmic discrimination; (7) a statement of the extent to which the deployer's use varies from the developer's intended use; (8) a description of deployer-side safeguards against discrimination; and (9) a description of how the system has been and will be monitored and evaluated.
CT
Introduced eff 2026-10-01
Deployers must, before deploying an automated employment-related decision process and annually thereafter, contract with a Labor Commissioner-approved independent auditor to complete a bias audit. The audit must: (A) evaluate performance and error rates across relevant subgroups, (B) assess disparate impact against protected classes, (C) examine data sources and output quality, (D) evaluate threshold, scoring, and ranking criteria effects, and (E) test for less discriminatory alternatives. The auditor must have no financial or operational interest in the deployer or developer and must be approved by the Labor Commissioner.
GA
Introduced
Developers must take steps to address risks of algorithmic discrimination, invalidity, and errors, including ensuring suitability and representativeness of data sources, implementing data governance measures, testing for disparate impact, and searching for less discriminatory alternative decision methods. This is a continuing obligation that persists as long as any deployer uses the system. Developers must also disclose to the Attorney General and all known deployers any known or reasonably foreseeable risks of algorithmic discrimination arising from intended uses, without unreasonable delay but no later than 90 days after (A) the developer discovers through ongoing testing that the system has caused or is reasonably likely to have caused algorithmic discrimination, or (B) the developer receives a credible report from a deployer that the system has caused algorithmic discrimination.
IL
Introduced
Employers must conduct additional impact assessments at least once every 2 years and before any material changes to the automated decision-making system. Each assessment must include, in plain language: (1) a description of the system's objectives; (2) an evaluation of the system's ability to achieve those objectives; (3) a description and evaluation of algorithms, computational models, and AI tools used, including a summary of underlying algorithms and a description of the design and training; (4) testing for: (A) disparate impact or discrimination based on protected characteristics (race, color, religious creed, national origin, sex, disability, gender identity, sexual orientation, genetic information, pregnancy, ancestry, veteran status) and mitigation actions; (B) accessibility limitations for persons with disabilities; (C) privacy and job quality impacts including wages, hours, conditions, and safeguards; (D) cybersecurity vulnerabilities and safeguards; (E) public health or safety risks; (F) foreseeable misuse and safeguards; and (G) use, storage, and control of sensitive or personal data; and (5) a notification mechanism for employees impacted by the system.
IL
Introduced
Health care entities must maintain validation and bias monitoring records for each AI system deployed in direct patient care and make those records available to the Department of Financial and Professional Regulation upon request.
IN
Introduced eff 2026-07-01
Employers must ensure that any automated decision system used to generate output for employment-related decisions has undergone predeployment testing and validation covering: (i) efficacy of the system; (ii) compliance with enumerated federal employment discrimination statutes (Title VII, ADEA, ADA Title I, GINA Title II, Equal Pay Act, Rehabilitation Act Sections 501/505, Pregnant Workers Fairness Act); (iii) absence of discriminatory impact based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, and genetic information (including family medical history); and (iv) compliance with the NIST AI Risk Management Framework (January 26, 2023) or a successor framework.
LA
Introduced
Covered insurers must conduct an annual disparate impact audit of each ADS, performed by a qualified independent actuary (FCAS/FSA/FAAA) or data scientist with algorithmic-fairness expertise, analyzing outcomes disaggregated by protected class and geographic area, assessing each variable's contribution, evaluating less discriminatory alternatives, and documenting methodology, findings, and corrective actions.
MA
Introduced
Employers must not use an automated employment decision tool unless it has undergone an independent impact assessment within the prior year evaluating scientific validity of attributes, protected-class proxy risk, training data disparities, output disparate impact, disability accessibility, post-deployment discrimination risks, and privacy/job quality impacts. Results must be submitted to the Department of Labor Standards within 60 days for inclusion in a public registry and distributed to affected employees.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MI
Introduced
Before using any automated decisions tool or electronic monitoring tool, employers must commission an impact assessment by an independent and impartial third party with no financial or legal conflicts of interest. The assessment must be conducted one year before implementation (or within 6 months of the act's effective date for tools already in use) and must: (a) evaluate the tool's objectives, algorithms, data, cybersecurity vulnerabilities, and potential biases including discriminatory outcomes based on race, gender, or disability; (b) identify the attributes and modeling techniques the tool uses; (c) evaluate whether those attributes are scientifically valid means of evaluating performance and whether they may function as proxies for protected classes under the Elliott-Larsen Civil Rights Act; (d) identify disparate-impact risks in training data and outputs and describe remedial actions; (e) evaluate disability accessibility limitations and describe remedies; (f) describe potential sources of post-implementation adverse impact; (g) assess whether any feature causing disparate impact is the least discriminatory method available; (h) identify other potential legal violations and steps to prevent them; and (i) describe potential negative effects on privacy, wages, hours, and working conditions.
NJ
Introduced
Each bias audit must calculate selection rates or scoring rates and impact ratios for each protected category — including sex, race/color/national origin/ethnicity, age, marital/familial status, disability, religion, sexual orientation, gender identity, income source, and intersectional categories of sex, ethnicity, and race — and must indicate the number of individuals excluded from calculations because they fall within an unknown category. Categories representing less than two percent of the audit data may be excluded from impact-ratio calculations if justified and disclosed.
NJ
Introduced
Bias audits must use training data from the employer's or employment agency's own use of the automated employment decision tool. An employer may rely on pooled training data from other employers only if it contributed its own data or has never used the tool. Test data may be used only when insufficient training data is available for a statistically significant audit, and the audit summary must explain why training data was not used and describe how the test data was generated.
NJ
Introduced
Bias audits must calculate selection rates, scoring rates, and impact ratios for each EEO-1 category, separately analyzed across sex, race/ethnicity, and intersectional categories, and must report the number of individuals in unknown categories. Categories representing less than two percent of the data may be excluded if the auditor provides justification and reports the excluded category's applicant count and rate.
NJ
Introduced
Bias audits must use historical data from the employer's own AEDT use. An employer may rely on a multi-employer audit only if it contributed its own historical data or has never used the AEDT. Test data may substitute only when insufficient historical data exists for statistical significance, and the audit summary must explain why historical data was unavailable and describe how the test data was generated.
NJ
Introduced
Employers, public entities, and vendors must, before deploying an AEDS or EMT, have an independent auditor (or the Department of Labor for public-employee systems) conduct and affirm an impact assessment confirming Section 2 compliance, disparate-impact analysis, and human-oversight procedures, updated within one year before deployment and re-run on any substantial change.
NJ
Introduced
State entities must cooperate with biannual Office audits of their high-risk algorithmic systems assessing intended purpose, data inputs, potential bias or disparate impact, and risk mitigation, and must develop and implement a corrective action plan within the director's timeframe if the Office identifies bias or discrimination risk. Audit summaries must be suitable for public disclosure.
NY
Introduced
Employers with 100 or more employees must not use an AEDT for any employment decision unless the tool has been subjected to a disparate-impact assessment, conducted within the prior year by an impartial auditor with no financial or legal conflicts of interest. The assessment must identify modeling techniques, evaluate disparate impact on protected classes, assess whether the tool uses the least discriminatory method, and be submitted to the Department of Labor for a public registry within 60 days of completion and distributed to affected employees.
NY
Introduced
Employers must conduct, no less than annually, a disparate impact analysis — conforming to the EEOC Uniform Guidelines on Employee Selection Procedures — assessing the actual impact of any automated employment decision tool used to select candidates for jobs within the state. The analysis must differentiate between selected and non-selected candidates across sex, race, ethnicity, and other protected classes. The full analysis must be provided to the employer but is not publicly filed and is subject to all applicable privileges.
NY
Introduced
Covered entities must conduct an impact assessment of each automated lending decision-making tool at least annually and prior to any material change, signed by an individual responsible for meaningful human review. The assessment must include bias and discrimination testing across enumerated protected characteristics, algorithm and training data descriptions, cybersecurity and privacy risk evaluation, misuse scenario analysis, and sensitive data handling practices. A summary report must be posted on the covered entity's website before initial deployment and updated after each subsequent assessment.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Developers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: the algorithm's design and methodology (inputs and outputs); creation, training, and testing details (performance metrics, benchmarks, demographic representation, testing outputs, stakeholder consultation, protected-characteristic testing methodology); precursor algorithms; data sources, types, legal authorization, and representativeness; training process details; potential for harm or disparate impact; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the developer.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: how the algorithm makes or contributes to a consequential action and its deployment purpose; necessity and proportionality relative to the baseline process being replaced; data inputs (type, collection, inference, processing, legal authorization, representativeness); expected and actual testing outputs; additional testing or training conducted by the deployer; stakeholder consultation; potential for harm or disparate impact in the deployment context; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the deployer.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Independent auditors, vendors, and employers must not manipulate, conceal, or misrepresent the results of an impact assessment.
US
Introduced
Covered entities must perform ongoing testing and evaluation of covered algorithms for differential performance across consumers' race, color, sex, gender, age, disability, religion, family status, socioeconomic status, veteran status, and any other characteristics the FTC deems appropriate, including documenting the methodology, proxy data methods used, and any subpopulation testing.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering the algorithm's design, methodology, training data, testing across demographic groups, potential for disparate impact, and mitigation recommendations, and receive a written report from the auditor.
US
Introduced
Employers must ensure that any automated decision system used to generate outputs for employment-related decisions has undergone pre-deployment testing and validation for efficacy, compliance with seven enumerated federal employment discrimination laws, absence of discriminatory impact across protected characteristics, and compliance with the NIST AI RMF. The system must also be independently tested at least annually for discriminatory impact and bias, with results made publicly available.
US
Introduced
Covered entities must perform ongoing testing and evaluation of system performance using benchmarking datasets and historical data, document performance metrics and success criteria, compare test-condition and deployed-condition performance, evaluate differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status (including proxy data methods), and document any subpopulations used in testing.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering design, methodology, training data, testing across protected characteristics, stakeholder consultation, potential for disparate impact, and mitigation recommendations. The auditor must submit a report with findings and recommendations.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information availability determination practices to (1) determine whether practices discriminate in violation of § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a per-determination audit trail recording the determination type, data and sources, algorithm methodology, training data, subgroup performance testing results, methodology, and ultimate decision, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with relevant third parties including service providers, and (6) identify and implement reasonable measures to remediate identified disparate-impact risks, including risks from service-provider determinations.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate under § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a detailed audit trail recording determination type, data, sources, methodology, algorithm, training data, subgroup testing results, and ultimate decision for each determination, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable mitigation measures for disparate-impact risks.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate on the basis of protected characteristics, (2) analyze disparate-impact risks, (3) create and retain for at least five years a detailed audit trail for each determination (recording type, data, sources, methodology, training data, subgroup testing results, algorithm, and decision), (4) conduct annual impact assessments of existing systems and pre-implementation impact assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable measures to mitigate identified disparate-impact risks.
MN
Failed
Agency heads must establish testing procedures for facial recognition systems, in consultation with NIST, that (1) periodically test system performance in operational conditions, (2) identify error rates across subpopulations by skin tone, age, and gender, and (3) take action to improve accuracy when disparate error rates are found.
MN
MN HF 465 (Facial Recognition Technology) § Minn. Stat. § 626A.53
Failed
Each agency head must, in consultation with NIST, establish testing procedures for facial recognition systems that (1) periodically conduct independent performance tests under operational conditions, (2) identify disparate error rates across subpopulations by skin tone, age, and gender, and (3) take corrective action to improve accuracy when disparities are found.
NY
Failed
Employers must conduct at least an annual disparate impact analysis assessing the actual impact of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must not use an automated employment decision tool unless the tool has been the subject of a bias audit conducted within the past year by an independent, impartial auditor with no financial or legal conflicts of interest. The audit must (1) identify modeling techniques and attributes, (2) evaluate scientific validity and proxy-variable risk for protected classes, (3) assess training data and output disparities and recommend remedial actions, (4) evaluate disability accessibility limitations, (5) determine whether features causing disparate impact are the least discriminatory method available, and (6) be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Failed
Employers must not use any AEDT unless it has been the subject of an impact assessment conducted by an independent auditor within the past year (or within six months of the effective date for pre-existing tools). The assessment must evaluate the tool's attributes and modeling techniques for scientific validity, proxy-variable risk across protected classes, training-data disparities, output-level disparate impact, disability accessibility, post-deployment discrimination risk, and least-discriminatory-method analysis. The completed assessment or an accessible summary must be submitted to the Department of Labor for inclusion in a public registry within 60 days and distributed to affected employees.
NY
Failed
Employers must not use an automated employment decision tool unless it has been subjected to an independent bias audit conducted no more than one year prior to use (or within six months for tools in use at enactment). The audit must be conducted by an independent party with no conflicts of interest and must: identify modeling techniques and attributes; evaluate scientific validity and proxy-for-protected-class risk; analyze training data and output disparities across protected classes; evaluate disability accessibility impacts; assess all residual discrimination risks; and for any disparate impact finding, evaluate whether the feature at issue is the least discriminatory method. The audit must be submitted to the Department of Labor within sixty days and distributed to affected employees.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must conduct a design evaluation for each CAIDS that considers information relevant to the potential for unlawful bias in connection with the system's intended end use.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must maintain impact assessment documentation for a reasonable time period covering: system purpose and use cases, consistency with developer's intended uses, potential for discriminatory impact on protected characteristics, data inputs and outputs, retraining data, performance metrics, transparency measures including notice to individuals, and post-deployment monitoring and user safeguards.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must maintain documentation for a reasonable time period covering the CAIDS's purpose and intended end uses, potential for discriminatory impact on protected characteristics and mitigation steps, known limitations, training data overview and collection methods, and pre-sale performance evaluation metrics.
US
Failed
Covered entities must perform ongoing testing and evaluation of system performance, including documenting performance metrics and success criteria, comparing test and deployed conditions, evaluating differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status, describing proxy data methods used, and identifying and documenting mitigation steps for material negative impacts including the rationale for any impacts left unmitigated.
US
Failed
Covered entities must perform ongoing testing and evaluation of automated decision system performance, including evaluating differential performance across consumers' race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status, documenting methodology and any use of proxy data.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact across protected characteristics, and (4) compliance with the NIST AI Risk Management Framework.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) system efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact based on race, color, religion, sex, national origin, age, disability, and genetic information, and (4) compliance with the NIST AI Risk Management Framework or successor.
US
Failed
Covered entities must perform ongoing testing and evaluation of automated decision system performance, including documenting success metrics, test vs. deployed performance, and differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, veteran status, and any other FTC-designated characteristics, including methodology and proxy-data methods used.
US
Failed
Covered entities must perform ongoing testing and evaluation of system performance using benchmarking datasets and historical data, including documenting performance metrics, test and deployed condition results, and evaluation of differential performance across protected characteristics (race, color, sex, gender, age, disability, religion, family status, socioeconomic status, veteran status) using documented methodology including proxy data methods.
H-02.3
Algorithmic impact assessment
A formal written assessment of the AI system's potential discriminatory impact must be completed before deployment, identifying risks and mitigation measures. Must be retained and available to regulators on request.
Enacted
5
Live
78
Failed
77
Total
160
CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must cover purpose, algorithmic discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. Deployers must retain all impact assessments and records for at least three years after final deployment, and must conduct at least annual reviews to verify each system is not causing algorithmic discrimination.
CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment and at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must include: (1) a statement of purpose, intended use cases, deployment context, and benefits; (2) an analysis of algorithmic discrimination risks with mitigation steps; (3) categories of input data and outputs; (4) data used to customize the system if applicable; (5) performance metrics and known limitations; (6) transparency measures including consumer disclosure of AI use; and (7) post-deployment monitoring and user safeguards. After a substantial modification, the assessment must also disclose the extent to which actual use was consistent with the developer's intended uses. A single assessment may cover a comparable set of systems. An assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect. Deployers must retain the most recent impact assessment, all associated records, and all prior assessments for at least three years following final deployment. In addition, deployers must review deployment of each high-risk AI system at least annually to ensure it is not causing algorithmic discrimination.
VA
Enacted eff 2026-07-01
Developers must exercise a reasonable duty of care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of each high-risk AI system. Compliance with all requirements of § 59.1-608 creates a rebuttable presumption that the developer has satisfied this duty.
VA
Enacted eff 2026-07-01
Deployers must exercise a reasonable duty of care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with all requirements of § 59.1-609 creates a rebuttable presumption that the deployer has satisfied this duty.
VA
Enacted eff 2026-07-01
Deployers must complete a detailed impact assessment for each high-risk AI system before initial deployment and before each significant update. The impact assessment must include at minimum: purpose and use case disclosure, algorithmic discrimination risk identification and mitigation steps, data input and output categories, customization data categories, performance metrics and limitations, transparency measures, post-deployment monitoring descriptions, and validity and reliability analysis. A single assessment may cover comparable systems. Impact assessments completed for other applicable laws are accepted if reasonably similar in scope. Assessments and all records must be retained for three years.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must conduct performance evaluations of each covered ADS — covering purpose, developer-approved uses, expected accuracy and reliability, intended disparate treatment (with necessity and alternatives analysis), reasonably foreseeable disparate impacts (with necessity, alternatives, and mitigation analysis), and effects of fine-tuning — before initial deployment (for systems first available on or after January 1, 2026; by January 1, 2027 for pre-existing systems), after each substantial modification or material fine-tuning, and at least annually.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed eff 2026-01-01
Developers must perform a formal impact assessment on each high-risk automated decision system before making it publicly available for use (for systems available on or after January 1, 2026). For systems first made publicly available before January 1, 2026, developers must perform an impact assessment upon making a substantial modification to the system.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed eff 2026-01-01
Deployers must perform an impact assessment on each high-risk automated decision system within two years of deploying the system (for systems first deployed after January 1, 2026). A state-agency deployer may opt out of this requirement if it uses the system only for its intended use as determined by the developer, makes no substantial modification, the developer complies with the Public Contract Code procurement and confidential-submission requirements, the state agency has no reasonable basis to believe deployment is likely to result in algorithmic discrimination, and the state agency maintains a governance program under § 22756.3.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed eff 2026-01-01
Developers must make the statements from their impact assessment available to deployers and potential deployers. The impact assessment must include: (1) a statement of purpose, intended benefits, intended uses, and intended deployment contexts; (2) a description of intended outputs; (3) a summary of data types used as inputs and recommended processing; (4) a summary of reasonably foreseeable disproportionate or unjustified impacts on protected classifications; (5) a description of safeguards to mitigate known algorithmic discrimination risks; (6) a description of how deployers can monitor for algorithmic discrimination; (7) a statement of the extent to which the deployer's use varies from the developer's intended use; (8) a description of deployer-side safeguards against discrimination; and (9) a description of how the system has been and will be monitored and evaluated.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.5
Engrossed eff 2026-01-01
Developers and deployers must not deploy or make available for deployment a high-risk automated decision system if its impact assessment determines the system is likely to result in algorithmic discrimination — unless the entity implements safeguards to mitigate the known risks of algorithmic discrimination and performs an updated impact assessment verifying that the discrimination has been mitigated and is not reasonably likely to occur.
NY
Engrossed
Developers and deployers must take reasonable care to prevent foreseeable risk of algorithmic discrimination arising from the use, sale, or sharing of a high-risk AI system or a product featuring a high-risk AI system.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must complete an impact assessment before initially deploying a high-risk AI system and within 90 days of each significant update, covering purpose, discrimination risks, data categories, customization data, performance metrics, transparency measures, and post-deployment monitoring. Impact assessments and all related records must be retained for five years. A single assessment may cover a comparable set of systems, and assessments completed under other applicable laws may satisfy this requirement if reasonably similar in scope.
CT
Introduced eff 2025-10-01
Employers must contract with an impartial third party to complete an impact assessment of any high-risk AI system no later than one year before deployment. The assessment must cover the system's purpose, use cases, deployment context, performance metrics, known limitations, error rates, algorithmic discrimination risk, accessibility, employee-rights impacts, and effects on job quality or well-being. For systems deployed before October 1, 2025, the assessment must be completed by October 1, 2026.
CT
Introduced eff 2026-10-01
Deployers must not deploy or continue deploying an automated employment-related decision process if the most recent bias audit identified disparate impact, unless the deployer can demonstrate: (1) business necessity, (2) implementation of corrective actions approved by the Labor Commissioner, and (3) either that no less discriminatory alternative is available or that a less discriminatory alternative has been implemented.
GA
Introduced
Deployers (or a contracted third party) must complete a formal impact assessment for each automated decision system before deployment and at least annually thereafter, and within 90 days after any intentional and substantial modification. The assessment must include, at minimum: (1) a statement of purpose, use cases, deployment context, and benefits; (2) analysis of risks of algorithmic discrimination, accessibility limitations, labor-law violations, and privacy intrusions; (3) description of data inputs and outputs; (4) overview of customization data; (5) validity and reliability analysis per contemporary social science standards with performance metrics; (6) description of transparency measures; (7) description of post-deployment monitoring and user safeguards; and (8) for post-modification assessments, a statement on whether the system was used consistently with or varying from the developer's intended uses. Subject to small-deployer exemption in § 10-16-6.
GA
Introduced
Deployers must not deploy an automated decision system if the impact assessment reveals a risk of algorithmic discrimination until the developer or deployer takes reasonable steps to search for and implement less discriminatory alternative decision methods.
HI
Introduced
Deployers must complete an internal impact assessment at least annually, and upon any intentional and substantial modification of a high-risk AI system, evaluating intended use, data categories and limitations, foreseeable risks of consumer harm, discrimination mitigation steps, and monitoring results.
IA
Introduced
Developers must use reasonable care to protect individuals from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of their high-risk AI systems. Compliance with the statute's enumerated requirements and attorney general rules creates a rebuttable presumption of reasonable care.
IA
Introduced
Deployers must use reasonable care to protect individuals from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with the statute's risk management, impact assessment, and annual review requirements and any attorney general rules creates a rebuttable presumption of reasonable care.
IA
Introduced
Deployers (or their contracted third parties) must complete an impact assessment for each high-risk AI system within 90 days of deployment or intentional and substantial modification, covering: purpose, context, and benefits; discrimination risk analysis and mitigation steps; data input categories and outputs; performance metrics and limitations; transparency measures; post-deployment monitoring and safeguards; and, for modifications, consistency with the developer's intended uses.
IL
Introduced
Employers must conduct an initial impact assessment at least 30 days before implementing any automated decision-making system. The assessment must bear the signature of (1) one or more individuals responsible for meaningful human review of the system, and (2) an independent auditor. An independent auditor is disqualified if, at any point in the 5 years preceding the assessment, that person was involved in developing or deploying the system under review, had an employment relationship with the developer or deployer, or had a direct or material indirect financial interest in the developer or deployer.
IL
Introduced
Employers must conduct additional impact assessments at least once every 2 years and before any material changes to the automated decision-making system. Each assessment must include, in plain language: (1) a description of the system's objectives; (2) an evaluation of the system's ability to achieve those objectives; (3) a description and evaluation of algorithms, computational models, and AI tools used, including a summary of underlying algorithms and a description of the design and training; (4) testing for: (A) disparate impact or discrimination based on protected characteristics (race, color, religious creed, national origin, sex, disability, gender identity, sexual orientation, genetic information, pregnancy, ancestry, veteran status) and mitigation actions; (B) accessibility limitations for persons with disabilities; (C) privacy and job quality impacts including wages, hours, conditions, and safeguards; (D) cybersecurity vulnerabilities and safeguards; (E) public health or safety risks; (F) foreseeable misuse and safeguards; and (G) use, storage, and control of sensitive or personal data; and (5) a notification mechanism for employees impacted by the system.
IL
Introduced
Auto insurers must demonstrate to the Department of Insurance that their marketing, underwriting, rating, claims handling, fraud investigations, and any algorithm or model used for those practices do not disparately impact customers on the basis of race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression.
IN
Introduced eff 2026-07-01
Employers must ensure that any automated decision system used to generate output for employment-related decisions has undergone predeployment testing and validation covering: (i) efficacy of the system; (ii) compliance with enumerated federal employment discrimination statutes (Title VII, ADEA, ADA Title I, GINA Title II, Equal Pay Act, Rehabilitation Act Sections 501/505, Pregnant Workers Fairness Act); (iii) absence of discriminatory impact based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, and genetic information (including family medical history); and (iv) compliance with the NIST AI Risk Management Framework (January 26, 2023) or a successor framework.
LA
Introduced
Covered insurers must conduct an annual disparate impact audit of each ADS, performed by a qualified independent actuary (FCAS/FSA/FAAA) or data scientist with algorithmic-fairness expertise, analyzing outcomes disaggregated by protected class and geographic area, assessing each variable's contribution, evaluating less discriminatory alternatives, and documenting methodology, findings, and corrective actions.
MA
Introduced
Controllers must conduct and document a data protection assessment before engaging in targeted advertising, data sales, profiling with foreseeable consumer harm risks, sensitive data processing, or processing data from products predominantly used by minors. Assessments must identify data categories, processing purposes, weigh benefits against consumer risks, and account for de-identification and consumer expectations.
MA
Introduced
Employers must not use electronic monitoring (alone or with an ADS) unless the monitoring has been the subject of an impact assessment conducted within one year by an independent, impartial auditor evaluating data protection/security practices, allowable purposes, potential legal violations, and impact on employee privacy and job quality.
MA
Introduced
Employers must not use an automated employment decision tool unless it has undergone an independent impact assessment within the prior year evaluating scientific validity of attributes, protected-class proxy risk, training data disparities, output disparate impact, disability accessibility, post-deployment discrimination risks, and privacy/job quality impacts. Results must be submitted to the Department of Labor Standards within 60 days for inclusion in a public registry and distributed to affected employees.
MA
Introduced
Employers must cease using an automated employment decision tool if an impact assessment finds disparate impact or disability accessibility limitations, until the employer (1) takes reasonable remediation steps and describes them in writing to employees, the auditor, and the department, and (2) if disputing the finding, demonstrates in writing that the tool is the least discriminatory method available.
MA
Introduced
Deployers must complete an annual impact assessment for each high-risk AI system covering: (i) the purpose and intended use, (ii) data categories used and outputs generated, and (iii) potential risks of discrimination and mitigation measures. Impact assessments must be updated after any substantial modification to the system.
MA
Introduced
Deployers must complete an impact assessment for each deployed high-risk AI system at the time of initial deployment, at least annually thereafter, and within 90 days after any intentional and substantial modification. The impact assessment must include, at a minimum: (1) purpose, intended use cases, deployment context, and benefits; (2) analysis of known or reasonably foreseeable risks of algorithmic discrimination and mitigation steps; (3) categories of input data and system outputs; (4) categories of data used to customize the system, if applicable; (5) performance metrics and known limitations; (6) transparency measures, including consumer disclosure; and (7) post-deployment monitoring and user safeguards. Assessments following an intentional and substantial modification must also disclose the extent to which the system was used consistently with or varied from the developer's intended uses. A single impact assessment may cover a comparable set of high-risk AI systems. An impact assessment completed for another applicable law satisfies this requirement if reasonably similar in scope and effect.
MA
Introduced
Employers must not use electronic monitoring, alone or with an automated employment decision system, unless the monitoring has been the subject of an impact assessment. The assessment must: (1) be conducted no more than one year before use (or within six months of the effective date for pre-existing monitoring); (2) be conducted by an independent and impartial party with no financial or legal conflicts of interest; (3) evaluate whether data protection and security practices are consistent with applicable law and cybersecurity best practices; (4) identify the allowable purpose(s); (5) consider and describe any other ways the monitoring could violate applicable law and steps to prevent such violations; and (6) consider and describe whether the monitoring may negatively impact employees' privacy and job quality, including wages, hours, and working conditions.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MA
Introduced
If an impact assessment finds that any data set, feature, or application of an automated employment decision tool results in a disparate impact based on protected characteristics or unlawfully limits accessibility for persons with disabilities, the employer must refrain from using the tool until it: (1) takes reasonable and appropriate steps to remedy the disparate impact or accessibility limitation and describes those steps in writing to employees, the auditor, and the department; and (2) if the employer believes the finding is erroneous or that remedial steps sufficiently address the findings, describes in writing how the feature at issue is the least discriminatory method of assessing performance or ability to perform essential job functions.
MI
Introduced
Before using any automated decisions tool or electronic monitoring tool, employers must commission an impact assessment by an independent and impartial third party with no financial or legal conflicts of interest. The assessment must be conducted one year before implementation (or within 6 months of the act's effective date for tools already in use) and must: (a) evaluate the tool's objectives, algorithms, data, cybersecurity vulnerabilities, and potential biases including discriminatory outcomes based on race, gender, or disability; (b) identify the attributes and modeling techniques the tool uses; (c) evaluate whether those attributes are scientifically valid means of evaluating performance and whether they may function as proxies for protected classes under the Elliott-Larsen Civil Rights Act; (d) identify disparate-impact risks in training data and outputs and describe remedial actions; (e) evaluate disability accessibility limitations and describe remedies; (f) describe potential sources of post-implementation adverse impact; (g) assess whether any feature causing disparate impact is the least discriminatory method available; (h) identify other potential legal violations and steps to prevent them; and (i) describe potential negative effects on privacy, wages, hours, and working conditions.
MI
Introduced
Before using an automated decisions or electronic monitoring tool, employers must commission an independent, conflict-free third-party impact assessment evaluating the tool's objectives, algorithms, data, cybersecurity, biases, proxy variables, disparate impact, accessibility limits, and privacy and job-quality effects, with remediation steps.
NJ
Introduced
Employers, public entities, and vendors must not deploy an AEDS or EMT until an independent auditor (or, for public employees, the Department of Labor) has conducted an impact assessment confirming the system serves only enumerated allowable purposes, uses the least invasive means, complies with anti-discrimination requirements (including disparate-impact analysis of training data), and implements effective human-oversight procedures. Vendors must provide the auditor full access to design documentation, training data sources, accuracy analyses, and economic-impact estimates. Assessments must be completed within one year before deployment, updated upon any substantial change, and the system may not operate until a compliant assessment is in place. Legacy systems must be assessed within six months of the effective date.
NJ
Introduced
Public entities and vendors must not deploy an ABSDS until the Department of Labor has conducted an impact assessment confirming compliance with anti-discrimination, proportionality, and human-oversight requirements, including effective procedures to prevent incorrect benefit denials based on mistaken fraud claims. Vendors must provide full documentation including design, training data, accuracy analysis, and economic-impact estimates. Assessments must be completed within one year before deployment, updated upon substantial changes, and the system may not operate until the assessment is complete. Legacy ABSDS systems must be assessed within one year of the effective date.
NJ
Introduced
High-risk AI systems implemented in New Jersey must undergo algorithmic impact assessments prior to deployment. The Office of Information Technology in the Department of the Treasury will perform the impact assessments, in a manner to be determined by OIT.
NJ
Introduced
Employers, public entities, and vendors must, before deploying an AEDS or EMT, have an independent auditor (or the Department of Labor for public-employee systems) conduct and affirm an impact assessment confirming Section 2 compliance, disparate-impact analysis, and human-oversight procedures, updated within one year before deployment and re-run on any substantial change.
NJ
Introduced
Public entities and vendors must not deploy an ABSDS unless the Department of Labor conducts and affirms an impact assessment confirming Section 2 compliance, analyzing training-data disparities and disparate adverse impact on beneficiaries, and requiring human-oversight procedures to prevent harmful outcomes including erroneous fraud-based benefit denials; re-run on any substantial change.
NJ
Introduced
State entities must cooperate with biannual Office audits of their high-risk algorithmic systems assessing intended purpose, data inputs, potential bias or disparate impact, and risk mitigation, and must develop and implement a corrective action plan within the director's timeframe if the Office identifies bias or discrimination risk. Audit summaries must be suitable for public disclosure.
NJ
Introduced
Covered entities must conduct an algorithmic impact assessment at least every two years evaluating whether the automated decision system results in a disparate impact on a protected class, in a form prescribed by the Director of the Division on Civil Rights.
NJ
Introduced
High-risk AI systems implemented in New Jersey must undergo algorithmic impact assessments prior to deployment. The assessments are performed by the Office of Information Technology in a manner to be determined by that office.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Designers, developers, and deployers of automated systems must take proactive and continuous measures to protect against algorithmic discrimination, including: (1) proactive equity assessments as part of system design, (2) use of representative data, (3) protection against proxies for demographic features, and (4) assurance of accessibility for persons with disabilities in design and development.
NY
Introduced
Employers with 100 or more employees must not use an AEDT for any employment decision unless the tool has been subjected to a disparate-impact assessment, conducted within the prior year by an impartial auditor with no financial or legal conflicts of interest. The assessment must identify modeling techniques, evaluate disparate impact on protected classes, assess whether the tool uses the least discriminatory method, and be submitted to the Department of Labor for a public registry within 60 days of completion and distributed to affected employees.
NY
Introduced
Employers must cease using an AEDT if an impact assessment finds disparate impact on a protected class, and may not resume use until the employer (1) takes reasonable and appropriate steps to remedy the disparate impact and (2) where the employer disputes the finding or believes remediation is sufficient, submits to the Commissioner a demonstration that the tool is the least discriminatory method available for assessing employee performance or ability to perform essential job functions.
NY
NY AB 5429 (Workforce Stabilization Act) § Labor Law § 201-j(1)
Introduced
Employers must conduct an impact assessment before utilizing or applying any artificial intelligence. The assessment must be repeated at least every two years and prior to any material change to the AI system that may change its outcome or effect. The impact assessment must include: (1) a description of the AI system's objectives; (2) an evaluation of the system's ability to achieve its stated objectives; (3) a description and evaluation of the system's development, including a summary of the underlying algorithms, computational modes, and tools, and the design and training data used; (4) the extent to which the system requires input of sensitive and personal data, how that data is used and stored, and any user control over their data; (5) an estimate of the number of employees already displaced due to AI; and (6) an estimate of the number of employees expected to be displaced or otherwise affected due to increased AI use in the workplace.
NY
Introduced
Deployers (or their contracted third parties) must complete an impact assessment for each high-risk AI decision system before initial deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification. Each impact assessment must include: (1) a statement of the system's purpose, intended use cases, deployment context, and benefits; (2) analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (3) descriptions of data input categories, system outputs, customization data categories, performance metrics and known limitations; (4) a description of transparency measures including consumer disclosure; and (5) a description of post-deployment monitoring and user safeguards. Post-modification assessments must also disclose actual-vs-intended use. A single assessment may cover a comparable set of systems, and an assessment completed under another law is deemed sufficient if reasonably similar in scope and effect. Deployers must retain the most recent assessment, all records, and all prior assessments for at least three years following final deployment.
NY
Introduced
Covered entities must conduct an impact assessment of each automated lending decision-making tool at least annually and prior to any material change, signed by an individual responsible for meaningful human review. The assessment must include bias and discrimination testing across enumerated protected characteristics, algorithm and training data descriptions, cybersecurity and privacy risk evaluation, misuse scenario analysis, and sensitive data handling practices. A summary report must be posted on the covered entity's website before initial deployment and updated after each subsequent assessment.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 111
Introduced
Covered deployers must file staggered reports with the Department of Financial Services that include an impact assessment evaluating whether the high-risk AI system poses a risk of algorithmic discrimination, the steps taken to address it, monetization, and a consumer cost-benefit analysis.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Developers and deployers must, prior to deploying, licensing, or offering a covered algorithm for a consequential action (including material changes), conduct a preliminary evaluation of the plausibility that any expected or intended use may result in a harm. If harm is not plausible, the developer or deployer must record a finding of no plausible harm — including a description of expected/intended use, how the evaluation was conducted, and an explanation — and submit it to the Division of Consumer Protection. If harm is plausible, a full pre-deployment evaluation by an independent auditor is required. Material changes to previously-deployed algorithms trigger re-evaluation, which may be scoped to the change.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Developers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: the algorithm's design and methodology (inputs and outputs); creation, training, and testing details (performance metrics, benchmarks, demographic representation, testing outputs, stakeholder consultation, protected-characteristic testing methodology); precursor algorithms; data sources, types, legal authorization, and representativeness; training process details; potential for harm or disparate impact; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the developer.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: how the algorithm makes or contributes to a consequential action and its deployment purpose; necessity and proportionality relative to the baseline process being replaced; data inputs (type, collection, inference, processing, legal authorization, representativeness); expected and actual testing outputs; additional testing or training conducted by the deployer; stakeholder consultation; potential for harm or disparate impact in the deployment context; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the deployer.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must cease using an automated employment decision tool upon a finding of disparate impact until the employer has (1) taken reasonable steps to remedy the disparate impact, and (2) if the employer believes the finding is erroneous or remediated, submitted to the Commissioner a demonstration that the tool is the least discriminatory method of assessing employee performance or ability.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
If an impact assessment finds disparate impact or unlawful accessibility limitations, the employer must immediately cease using the tool until it (1) takes reasonable remedial steps and describes those steps in writing to employees, the auditor, and the Department, and (2) demonstrates in writing that the flagged feature is the least discriminatory method available, if the employer believes the finding is erroneous or that remedial steps are sufficient.
NY
NY SB 1854 (Workforce Stabilization Act) § Labor Law § 201-j(1)
Introduced
Employers must conduct an impact assessment before utilizing or applying any artificial intelligence. The assessment must be repeated at least every two years, and a new assessment must be conducted prior to any material change to the AI that may change its outcome or effect. Each impact assessment must include: (a) a description of the AI's objectives; (b) an evaluation of the AI's ability to achieve those objectives; (c) a description of the underlying algorithms, computational modes, tools, and training data used to develop the AI; (d) the extent to which the AI requires sensitive and personal data input, how that data is used and stored, and any user controls over their data; (e) an estimate of the number of employees already displaced due to AI; and (f) an estimate of the number of employees expected to be displaced or otherwise affected by increased AI use.
NY
Introduced
Deployers must complete an impact assessment for each high-risk AI decision system before deployment, at least annually thereafter, and within 90 days after any intentional and substantial modification. Each impact assessment must include, to the extent reasonably known: (A) a statement of purpose, intended use cases, deployment context, and benefits; (B) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (C) descriptions of input data categories and system outputs; (D) if applicable, categories of data used for customization; (E) performance metrics and known limitations; (F) transparency measures including consumer notification; and (G) post-deployment monitoring and user safeguards. Impact assessments following intentional and substantial modifications must also disclose whether the system was used consistently with the developer's intended uses. A single assessment may cover comparable systems. An impact assessment completed under another law satisfying substantially similar requirements is deemed compliant. Deployers must retain the most recently completed impact assessment, all records, and all prior assessments for at least three years following final deployment.
NY
Introduced
Deployers must conduct an annual impact assessment for each AEDT in use, covering: the tool's purpose, benefits, and deployment context; how its output is the controlling factor; data types collected from individuals; consistency with the developer's intended-use statement; foreseeable discrimination risk and mitigation safeguards; monitoring practices; and validity or relevance evaluation.
NY
Introduced
Developers must conduct an annual impact assessment for each AEDT made available for sale or licensing, covering: intended purpose, benefits, and deployment contexts; intended output and controlling-factor role; intended data collection from individuals; foreseeable discrimination risk and mitigation safeguards; and deployer monitoring guidance.
NY
Introduced
Covered entities must conduct at least annual impact assessments of each automated lending decision-making tool — signed by a responsible human reviewer — covering accuracy, fairness, bias, discrimination across protected characteristics, cybersecurity, privacy, safety, misuse risks, data practices, and notification mechanisms, and must publish a summary report on their website before deployment and after each subsequent assessment. An additional assessment is required before any material change to the tool.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not use electronic monitoring, alone or in conjunction with an automated decision system, unless the proposed use has been the subject of an impact assessment. The impact assessment must: (1) be conducted no more than one year before use begins (or within six months of the effective date for pre-existing monitoring), (2) be conducted by an independent and impartial party with no financial or legal conflicts of interest, (3) evaluate whether data protection and security practices are consistent with applicable law and cybersecurity best practices, (4) identify the allowable purposes as defined in the chapter, (5) consider and describe any other ways the monitoring could result in a law violation and necessary steps to prevent it, (6) consider and describe whether the monitoring may negatively impact employees' privacy and job quality including wages, hours, and working conditions, and (7) be disclosed in full, in plain language, to all affected workers and their authorized representatives within 30 days of the employer's receipt. Workers and their authorized representatives have the right to comment on, challenge, and bargain over the proposed monitoring based on the assessment's findings.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must complete an impact assessment of each high-risk AI system before deployment and at least annually thereafter (and within 90 days of any intentional and substantial modification), covering purpose, discrimination risk analysis, data categories, customization data, performance metrics, transparency measures, and post-deployment monitoring.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-20
Introduced
Developers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the system. A rebuttable presumption of reasonable care applies if the developer complies with all requirements of Section 37-31-20 and any rules adopted by the Attorney General.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers of high-risk AI systems must use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination. A rebuttable presumption of reasonable care applies if the deployer complies with all requirements of Section 37-31-30 and any rules adopted by the Attorney General.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers, or third parties contracted by deployers, must complete an impact assessment for each deployed high-risk AI system before or at deployment, and at least annually thereafter and within 90 days after any intentional and substantial modification. The impact assessment must include, at minimum: (1) a statement of the system's purpose, intended uses, deployment context, and benefits; (2) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (3) a description of data inputs and outputs; (4) an overview of data used to customize the system, if applicable; (5) performance metrics and known limitations; (6) transparency measures including consumer disclosure; and (7) post-deployment monitoring and user safeguards. Post-modification assessments must also disclose whether the system was used consistently with or varied from the developer's intended uses. A single impact assessment may cover comparable systems. An impact assessment completed for another applicable law or regulation satisfies this requirement if reasonably similar in scope and effect. Small deployers with fewer than 50 employees are exempt if other conditions in subsection (F) are met.
US
Introduced
Covered entities must perform impact assessments of each covered algorithm both before and after deployment, and maintain documentation of those assessments for three years beyond the duration of deployment.
US
Introduced
Covered entities must identify and measure any likely material negative impact of the covered algorithm on consumers, document steps taken to eliminate or mitigate each identified impact, document any impacts left unmitigated with justification (including a non-discriminatory compelling interest analysis), and maintain standard protocols for identifying, measuring, and mitigating negative impacts.
US
Introduced
Developers and deployers must conduct a preliminary evaluation of the plausibility that any expected or intended use of a covered algorithm for a consequential action may result in harm before deploying, licensing, or offering it. If harm is not plausible, a finding must be recorded and submitted to the FTC. If harm is plausible, a full pre-deployment evaluation must be conducted.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering the algorithm's design, methodology, training data, testing across demographic groups, potential for disparate impact, and mitigation recommendations, and receive a written report from the auditor.
US
Introduced
Covered entities must perform impact assessments of any deployed automated decision system intended for use in an augmented critical decision process and of any augmented critical decision process, both before and after deployment.
US
Introduced
Covered entities must, for any new augmented critical decision process, evaluate the previously existing decision-making process it replaces, including the baseline process description, known harms or negative impacts, and the intended benefits and purpose of the new process.
US
Introduced
Covered entities must identify and measure any likely material negative impact of each automated decision system or augmented critical decision process on consumers, document steps taken to eliminate or mitigate those impacts, document which impacts were left unmitigated with justification (including the compelling non-discriminatory interest and why alternatives are insufficient), and maintain standard protocols for identifying, measuring, and mitigating negative impacts with associated staff training.
US
Introduced
Developers and deployers must conduct a preliminary evaluation of whether any expected or intended use of a covered algorithm may plausibly result in harm before deployment, licensing, or offering. If no harm is plausible, a documented finding must be recorded and submitted to the FTC. If harm is plausible, a full pre-deployment evaluation by an independent auditor is required.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering design, methodology, training data, testing across protected characteristics, stakeholder consultation, potential for disparate impact, and mitigation recommendations. The auditor must submit a report with findings and recommendations.
VT
Introduced eff 2025-07-01
Employers must create a written impact assessment before utilizing any automated decision system. The assessment must include at minimum: (1) a detailed description of the ADS and its purpose; (2) a description of data used; (3) outputs produced and the types of employment decisions those outputs may inform; (4) an assessment of necessity including reasons for supplementing nonautomated decision-making; (5) a validity and reliability assessment per contemporary social science standards, including performance metrics and known limitations; (6) a detailed risk assessment covering discrimination across protected classes, chilling effects on legal rights, harms to health/safety/dignity/autonomy, privacy risks including data breaches, and negative economic/material impacts to employees; (7) a summary of risk mitigation measures; and (8) a description of the assessment methodology.
WA
Introduced eff 2026-07-01
Employers must create a written impact assessment before utilizing any automated decision system, covering the system's description, data used, outputs, rationale, risks (including errors, discrimination across enumerated protected classes, chilling effects on legal rights, physical and mental health harms, privacy risks, and negative economic impacts), mitigation measures, and methodology. The assessment must be updated upon any significant change to the system.
WA
Introduced eff 2027-01-01
Deployers must complete an impact assessment for each high-risk AI system before initial deployment and before any significant update is used for consequential decisions. The impact assessment must include at minimum: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) whether deployment poses known or reasonably foreseeable algorithmic discrimination risks, the nature of such discrimination, and mitigation steps taken; (3) for post-deployment assessments, whether actual use cases were consistent with or varied from the developer's intended uses; (4) categories of input data and system outputs; (5) categories of data used to customize the system, if applicable; (6) performance metrics and known limitations; (7) transparency measures taken, including consumer-facing AI disclosure; (8) post-deployment monitoring and user safeguards, including oversight processes; and (9) an analysis of the system's validity and reliability per standard industry practices. An impact assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect. A single impact assessment may address a comparable set of high-risk AI systems.
WA
Introduced eff 2026-07-01
Deployers must complete an impact assessment for each high-risk AI system before deployment on or after July 1, 2027, and within 90 days after any intentional and substantial modification. Each assessment must include, to the extent reasonably known: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (3) categories of input data, system outputs, performance metrics and limitations, transparency measures taken, and post-deployment monitoring and user safeguards. Assessments following a substantial modification must also disclose the extent to which the system was used consistently with or in variance from the developer's intended uses. A single assessment may cover comparable systems, and an assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect.
WA
Introduced eff 2027-01-01
Deployers must complete an impact assessment for each high-risk AI system before initial deployment and before any significant update is used to make a consequential decision. The impact assessment must include, at minimum: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) whether the deployment poses any known or reasonably foreseeable risk of algorithmic discrimination, the nature of such discrimination, and mitigation steps taken; (3) for postdeployment assessments, whether updated use cases are consistent with the developer's intended uses; (4) categories of data inputs and outputs; (5) categories of data used by the deployer to customize the system; (6) performance metrics and known limitations; (7) transparency measures taken, including consumer disclosures; (8) postdeployment monitoring and user safeguards, including any oversight process; and (9) an analysis of the system's validity and reliability in accordance with standard industry practices.
WA
Introduced
Deployers must complete an impact assessment for each high-risk AI system before or at the time of deployment, and within 90 days after any intentional and substantial modification. Each impact assessment must include, at a minimum: (1) the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of known or reasonably foreseeable risks of algorithmic discrimination and mitigation steps taken; (3) a description of input data categories, outputs, performance metrics and known limitations, transparency measures, and post-deployment monitoring and user safeguards. Impact assessments following a substantial modification must also disclose the extent to which the system was used consistently with or varied from the developer's intended uses. A single impact assessment may cover a comparable set of high-risk AI systems, and an impact assessment completed under another applicable law satisfies these requirements if reasonably similar in scope and effect.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Deployers must perform a documented impact assessment on each automated decision tool before first using it and annually thereafter, covering the tool's purpose, outputs, data categories collected (mapped to CCPA categories), consistency with the developer's intended-use statement, adverse-impact analysis across protected classes, safeguards against algorithmic discrimination, human oversight description, and validity evaluation. For tools already in use before January 1, 2025, the initial assessment must be completed before January 1, 2026.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Developers must perform a documented impact assessment on each automated decision tool before making it available to potential deployers and annually thereafter, covering the tool's purpose, outputs, data categories collected, adverse-impact analysis across protected classes, mitigation measures against algorithmic discrimination, and human oversight capabilities. For tools first made available before January 1, 2025, the initial assessment must be completed before January 1, 2026.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Deployers must perform an annual impact assessment for each automated decision tool, covering purpose, outputs, data types, consistency with the developer's intended-use statement, adverse impacts on the basis of sex, race, or ethnicity, discrimination safeguards, human oversight, and validity evaluation.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Developers must complete and document an annual assessment for each automated decision tool they design, code, or produce, covering purpose, outputs, data types, adverse impacts on the basis of sex, race, or ethnicity, discrimination mitigation measures, and human oversight capabilities.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible for any significant update to an automated decision tool.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within ninety days after any intentional and substantial modification. Post-modification assessments must disclose the extent to which the system's actual use was consistent with or varied from the developer's intended uses.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification, including a statement on whether actual use deviated from the developer's intended uses.
CO
Failed eff 2025-05-05
Deployers must complete an impact assessment for each high-risk AI system prior to first deployment (or January 1, 2027, whichever is later) and annually thereafter, covering risks of algorithmic discrimination, accessibility limitations, unfair trade practices, labor law violations, and Colorado Privacy Act violations, along with data categories, sources, outputs, and performance metrics. This obligation applies only to systems that are the principal basis of consequential decisions.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within ninety days of any intentional and substantial modification. Effective June 30, 2026.
CO
Failed
Deployers must include in any post-modification impact assessment a statement disclosing the extent to which the high-risk AI system was used consistently with or varied from the developer's intended uses. Effective June 30, 2026.
CT
Failed
Deployers must complete an impact assessment of each high-risk AI system at deployment, at least annually thereafter, and within 90 days of an intentional and substantial modification, covering purpose, discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. Impact assessments and all associated records must be retained for at least three years after final deployment.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information availability determination practices to (1) determine whether practices discriminate in violation of § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a per-determination audit trail recording the determination type, data and sources, algorithm methodology, training data, subgroup performance testing results, methodology, and ultimate decision, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with relevant third parties including service providers, and (6) identify and implement reasonable measures to remediate identified disparate-impact risks, including risks from service-provider determinations.
HI
Failed
The Office of Enterprise Technology Services must develop, maintain, and periodically update guidelines for state agencies to assess the impact of adopting generative AI tools on vulnerable communities, including criteria for evaluating equitable outcomes in high-risk uses, in consultation with employee organizations, trust and safety experts, and academic researchers.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate under § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a detailed audit trail recording determination type, data, sources, methodology, algorithm, training data, subgroup testing results, and ultimate decision for each determination, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable mitigation measures for disparate-impact risks.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate on the basis of protected characteristics, (2) analyze disparate-impact risks, (3) create and retain for at least five years a detailed audit trail for each determination (recording type, data, sources, methodology, training data, subgroup testing results, algorithm, and decision), (4) conduct annual impact assessments of existing systems and pre-implementation impact assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable measures to mitigate identified disparate-impact risks.
IL
Failed
Deployers must perform an annual impact assessment for each automated decision tool, covering the tool's purpose, outputs, data types, potential adverse impacts across protected characteristics, discrimination safeguards, human oversight components, and validation methodology. The first assessment is due by January 1, 2026.
IL
Failed
Deployers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
IL
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering tool purpose, outputs, data types, consistency with the developer's intended-use statement, algorithmic discrimination risks, ethical AI safeguards, human oversight mechanisms, and validation methodology.
IL
Failed
Developers must complete and document an annual impact assessment for each automated decision tool they design, code, or produce, covering tool purpose, outputs, data types, algorithmic discrimination risks from intended use and foreseeable misuse, ethical AI mitigation measures, and intended human oversight mechanisms.
IL
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
IL
Failed
Deployers must perform an impact assessment for each automated decision tool by January 1, 2027, and annually thereafter. The assessment must include: (1) a statement of the tool's purpose, intended benefits, uses, and deployment contexts; (2) a description of the tool's outputs and how they inform consequential decisions; (3) a summary of data types collected from individuals and processed by the tool; (4) an analysis of potential adverse impacts across protected characteristics (sex, race, color, ethnicity, religion, age, national origin, limited English proficiency, disability, veteran status, genetic information); (5) a description of safeguards implemented or planned to address reasonably foreseeable algorithmic discrimination risks; (6) a description of human use or monitoring of the tool in consequential decision-making; and (7) a description of how the tool has been or will be evaluated for validity or relevance. This obligation does not apply to deployers with fewer than 25 employees unless the tool impacted more than 999 people in the prior calendar year.
IL
Failed
Deployers must perform an additional impact assessment as soon as feasible with respect to any significant update to an automated decision tool. A significant update is a new version, new release, or other update that changes the tool's use case, key functionality, or expected outcomes.
MA
MA HB 4029 (Algorithmic Accountability) § G.L. c. 93, § 115(b)
Failed
Covered entities must comply with all regulations promulgated by the Office under subsection (c) and must not knowingly provide substantial assistance to any entity that violates those regulations, regardless of any contractual arrangement with consumers.
MA
MA HB 4029 (Algorithmic Accountability) § G.L. c. 93, § 115(c)
Failed
Covered entities must conduct automated decision system impact assessments for all existing and new high-risk automated decision systems — with new systems assessed prior to implementation — and data protection impact assessments for all existing and new high-risk information systems, at frequencies determined by the Office.
MA
MA HB 4029 (Algorithmic Accountability) § G.L. c. 93, § 115(c)
Failed
Covered entities must reasonably address in a timely manner the results of all automated decision system and data protection impact assessments.
MD
MD HB 1255 (Automated Employment Decision Tools) § Md. Code, Lab. & Empl. § 3-718(B)–(C)
Failed
Employers must not use an automated employment decision tool unless the tool has undergone an impact assessment within the year preceding first use and annually thereafter, and each assessment determines the tool's use would not involve a high-risk action (likely unlawful discrimination or disparate impact).
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must complete an impact assessment for any deployed high-risk AI system and retain all impact assessments and related records for at least 3 years after the end of deployment.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5006
Failed
Deployers must complete an impact assessment at least annually and within 90 days of any intentional and substantial modification, covering system purpose, deployment context, algorithmic discrimination risk analysis, mitigation steps, inputs and outputs, customization data, performance metrics, known limitations, transparency measures, oversight processes, and (for subsequent assessments) consistency with intended uses.
MD
MD SB 957 (Automated Employment Decision Tools) § Md. Code, Lab. & Empl. § 3–718(B)–(C)
Failed
Employers must not use an automated employment decision tool to screen applicants or determine employment terms unless the tool (1) was subject to an impact assessment in the year before first use, (2) undergoes an annual impact assessment each year of use, and (3) each assessment determines the tool would not involve a high-risk action likely to result in unlawful discrimination or disparate impact.
NE
Failed
Deployers must complete an impact assessment for each high-risk AI system deployed on or after February 1, 2026, and within 90 days after any intentional and substantial modification. The impact assessment must include, to the extent reasonably known: (1) a statement disclosing the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of whether deployment poses known risks of algorithmic discrimination and the mitigation steps taken; (3) a high-level summary of input data categories and outputs; (4) if the deployer used data to customize the system, an overview of the customization data categories; (5) any performance evaluation metrics and known limitations; (6) a description of transparency measures including consumer disclosure of AI use; and (7) a description of post-deployment monitoring and user safeguards. Impact assessments following substantial modifications must also disclose whether the system was used consistently with the developer's intended use. A single impact assessment may address a comparable set of systems. Deployers must maintain: the most recent impact assessment for each system, all records concerning the assessment, and for at least three years following final deployment, each prior impact assessment and associated records.
NM
Failed
Deployers must conduct an impact assessment for each deployed high-risk AI system (1) annually and (2) within 90 days of an intentional and substantial modification, covering intended uses, discrimination risks and mitigation, data categories, performance metrics including demographic test data breakdowns, transparency measures, and post-deployment monitoring. A single assessment may cover comparable systems. An exempt small deployer (fewer than 50 employees, no own-data training, intended-use-only deployment, consumer-accessible developer assessment) is excused.
NY
Failed
Employers must conduct at least annually a disparate impact analysis — conforming to the EEOC Uniform Guidelines on Employee Selection Procedures — assessing the actual impact of any automated employment decision tool used to select candidates for jobs within the state, differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must conduct at least an annual disparate impact analysis assessing the actual impact of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers must take proactive and continuous measures to prevent algorithmic discrimination, including proactive equity assessments during system design, use of representative data, protection against proxies for demographic features, and accessibility assurance for persons with disabilities.
NY
Failed
Employers must conduct at least annual disparate impact analyses of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must not use any AEDT unless it has been the subject of an impact assessment conducted by an independent auditor within the past year (or within six months of the effective date for pre-existing tools). The assessment must evaluate the tool's attributes and modeling techniques for scientific validity, proxy-variable risk across protected classes, training-data disparities, output-level disparate impact, disability accessibility, post-deployment discrimination risk, and least-discriminatory-method analysis. The completed assessment or an accessible summary must be submitted to the Department of Labor for inclusion in a public registry within 60 days and distributed to affected employees.
NY
Failed
Employers must immediately cease using any AEDT found by an impact assessment to cause disparate impact on a protected class or unlawfully limit disability accessibility, and may not resume use until (1) the employer takes reasonable steps to remedy the disparate impact or accessibility limitation and describes those steps in writing to employees, the auditor, and the Department, and (2) if the employer contests the finding, it describes in writing how the tool is the least discriminatory method of assessing the relevant performance criteria.
NY
Failed
Deployers must perform an impact assessment for each automated employment decision tool in use within one year of the effective date and annually thereafter, covering at minimum the tool's purpose, output, data types collected, consistency with the developer's intended-use statement, foreseeable discrimination risks and mitigation safeguards, monitoring practices, and validity evaluation.
NY
Failed
Developers must perform an impact assessment for each automated employment decision tool made available for sale or licensing within one year of the effective date and annually thereafter, covering at minimum the tool's intended purpose, intended output, intended data collection, foreseeable discrimination risks and mitigation safeguards, and deployer monitoring capabilities.
NY
Failed
When a bias audit finds disparate impact or accessibility limitations, employers must (1) take reasonable steps to reduce or remedy the impact and describe those steps in writing to employees, the auditor, and the department; (2) if the employer disputes the finding or believes remediation suffices, describe in writing why the tool is the least discriminatory method; or (3) if the finding results from a lawful affirmative action plan, describe the plan in writing to employees, the auditor, and the department.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers must conduct proactive equity assessments during system design, use representative data, implement protections against demographic-proxy variables, ensure accessibility for persons with disabilities, and conduct both pre-deployment and ongoing disparity testing and mitigation under clear organizational oversight.
NY
Failed
Employers must conduct an impact assessment before utilizing or applying any artificial intelligence, covering the AI's objectives, effectiveness, underlying algorithms and training data, sensitive-data use, and both current and projected employee displacement. Reassessments must be conducted at least every two years and before any material change to the AI system.
OK
Failed
Deployers must conduct assessments of AI systems to identify potential biases in training data, risks to safety, civil liberties, and fundamental rights, and mitigation strategies for identified risks.
OK
OK HB 3835 (Ethical AI Act) § 75A O.S. § 1002
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering the tool's purpose, outputs, data types collected, consistency with developer statements, algorithmic discrimination risks, ethical AI safeguards, human oversight mechanisms, and validation evaluations.
OK
OK HB 3835 (Ethical AI Act) § 75A O.S. § 1002
Failed
Developers must complete and document an annual impact assessment for each automated decision tool they design, code, or produce, covering the tool's purpose, outputs, data types collected, algorithmic discrimination risks, ethical AI measures, and intended human use patterns.
OK
OK HB 3835 (Ethical AI Act) § 75A O.S. § 1002
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-2
Failed
Deployers must perform an annual impact assessment for each automated decision tool they use, covering purpose, outputs, data types, consistency with developer's intended-use statement, adverse-impact analysis across protected characteristics, discrimination safeguards, human oversight mechanisms, and validity evaluation.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-2
Failed
Developers must complete and document an annual assessment of each automated decision tool they design, code, or produce, covering purpose, outputs, data types, adverse-impact analysis across protected characteristics, discrimination mitigation measures, and human oversight capabilities.
RI
RI HB 7521 (Automated Decision Tools) § R.I. Gen. Laws § 42-166-2
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible following any significant update to an automated decision tool.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must perform an impact assessment before deploying any CAIDS, repeat the assessment annually, and conduct a new assessment whenever material changes are made to the system's purpose or data inputs.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must maintain impact assessment documentation for a reasonable time period covering the CAIDS's purpose, consistency with developer's intended uses, discriminatory impact potential across protected characteristics and mitigation steps, data inputs and outputs, retraining data, performance metrics and limitations, transparency measures, and post-deployment monitoring and safeguards.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must maintain design evaluation documentation for a reasonable time period covering the CAIDS's purpose and intended uses, discriminatory impact potential across protected characteristics and mitigation steps, known limitations, training data collection and processing overview, and pre-sale performance metrics.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must perform an impact assessment prior to deploying a CAIDS and annually thereafter, with a new assessment required upon material changes to the system's purpose or the type of data it receives.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must maintain impact assessment documentation for a reasonable time period covering: system purpose and use cases, consistency with developer's intended uses, potential for discriminatory impact on protected characteristics, data inputs and outputs, retraining data, performance metrics, transparency measures including notice to individuals, and post-deployment monitoring and user safeguards.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must conduct a design evaluation for each CAIDS that considers information relevant to the potential for unlawful bias in connection with the system's intended end use.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.006
Failed
Deployers must complete a written impact assessment for each high-risk AI system, annually and within 90 days of any substantial modification, covering purpose, discrimination risk analysis, data categories, performance metrics, transparency measures, post-deployment monitoring, and cybersecurity threat modeling. Following a modification, the deployer must disclose whether the system was used consistently with the developer's intended uses.
US
Failed
Covered entities must perform impact assessments of all deployed automated decision systems used or expected to be used in augmented critical decision processes, both before and after deployment.
US
Failed
Covered entities must perform ongoing testing and evaluation of system performance, including documenting performance metrics and success criteria, comparing test and deployed conditions, evaluating differential performance across race, color, sex, gender, age, disability, religion, family status, socioeconomic status, and veteran status, describing proxy data methods used, and identifying and documenting mitigation steps for material negative impacts including the rationale for any impacts left unmitigated.
US
Failed
Covered entities must perform impact assessments of all deployed automated decision systems and augmented critical decision processes, both before and after deployment, evaluating the system's impact on consumers.
US
Failed
Covered entities must attempt to eliminate or mitigate, in a timely manner, any augmented critical decision process that demonstrates a likely material negative impact with legal or similarly significant effects on a consumer's life.
US
Failed
Covered entities must identify and document any likely material negative impact of the automated decision system or augmented critical decision process on consumers, document steps taken to eliminate or mitigate such impacts, document unmitigated impacts with justifying rationale, and document standard protocols for impact identification and staff training.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact across protected characteristics, and (4) compliance with the NIST AI Risk Management Framework.
US
Failed
Employers must ensure that any automated decision system whose output is used in employment-related decisions has undergone pre-deployment testing and validation for (1) system efficacy, (2) compliance with federal employment discrimination laws, (3) absence of discriminatory impact based on race, color, religion, sex, national origin, age, disability, and genetic information, and (4) compliance with the NIST AI Risk Management Framework or successor.
US
Failed
Covered entities must perform impact assessments of each deployed automated decision system and each augmented critical decision process, both prior to and after deployment.
US
Failed
Covered entities must perform impact assessments of all deployed automated decision systems developed for use in augmented critical decision processes, and of all augmented critical decision processes, both prior to and after deployment.
US
Failed
Covered entities must identify and measure all likely material negative impacts of the system on consumers, document steps taken to eliminate or mitigate them, document unmitigated impacts with compelling justification, and document standard protocols for identifying, measuring, mitigating, and eliminating negative impacts including staff training.
US
Failed
Developers and deployers must conduct a preliminary evaluation of the plausibility that any expected or intended use of a covered algorithm may result in harm before deploying, licensing, or offering the algorithm for a consequential action. If no harm is plausible, they must record and submit the finding to the FTC; if harm is plausible, they must proceed to a full pre-deployment evaluation.
US
Failed
Developers and deployers must engage an independent auditor to conduct a full pre-deployment evaluation when harm is plausible, covering the algorithm's design, methodology, training and testing data, demographic representation, testing across protected characteristics, potential for disparate impact, and mitigation recommendations. The independent auditor must submit a report to the developer or deployer.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-605
Failed
Deployers must complete an impact assessment before initial deployment and within 90 days of each significant update. Each assessment must include, at minimum: (1) purpose, use cases, deployment context, benefits, and any reasonably foreseeable algorithmic discrimination risks with mitigation steps; (2) for post-deployment assessments, whether updated use cases varied from the developer's intended uses; (3) categories of input data and outputs; (4) if applicable, data used to customize the system; (5) transparency measures taken; and (6) post-deployment monitoring and user safeguards. Assessments and all associated records must be maintained for a reasonable period. A cross-compliance safe harbor applies for assessments completed under other applicable laws of reasonably similar scope.
VT
Failed
Employers must create a written impact assessment before using any automated decision system, covering system description, data used, outputs, necessity justification, detailed risk assessment (errors, discrimination across protected characteristics, legal-rights chilling, employee health/dignity/privacy/economic impacts), mitigation measures, and methodology. The assessment must be updated upon any significant change to the system.
VT
Failed
Developers must provide deployers with the technical capability to access all information and documentation reasonably required for the deployer to complete an impact assessment under § 1003(c).
VT
Failed
Deployers must complete an impact assessment for each high-risk AI system (1) before initial deployment, (2) annually within 45 days of each calendar year-end, and (3) within 45 days of each significant update. Each assessment must cover purpose, discrimination risks, mitigation steps, data inputs and outputs, retraining data, performance metrics, transparency measures, and post-deployment monitoring. Assessments and all related records must be maintained for at least three years.
VT
Failed
Developers must complete an impact assessment for each generative AI system before offering it in Vermont. The assessment must evaluate intended purpose, extent of use, prior harms, potential harm intensity and breadth, user dependency, vulnerable-population exposure, and outcome reversibility. Assessments and all related records must be retained for at least three years.
WA
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering the tool's purpose, outputs, data types, consistency with the developer's intended-use statement, foreseeable algorithmic discrimination risks, safeguards aligned with ethical AI principles, human oversight mechanisms, and validation methodology. Deployers with fewer than 50 employees are exempt.
WA
Failed
Developers must complete and document an annual impact assessment for each automated decision tool they design, code, or produce, covering the tool's purpose, outputs, data types, foreseeable algorithmic discrimination risks from intended use or foreseeable misuse, ethical AI safeguards, and intended human oversight mechanisms.
WA
Failed
Deployers and developers must perform an additional impact assessment as soon as feasible for any significant update to an automated decision tool.
H-02.4
Regulator submission of assessment
Proactive submission of the impact assessment to a regulatory authority on a defined schedule or upon request.
Enacted
0
Live
18
Failed
6
Total
24
CT
Introduced eff 2026-10-01
Deployers must, within thirty days of completing a bias audit, (1) file the bias audit report and a plain-language summary with the Labor Commissioner in the prescribed form, and (2) publish the plain-language summary on the deployer's website in a conspicuous place accessible to applicants and employees. The summary must include the audit methodology, key findings and identified risks, and any corrective actions taken.
IL
Introduced
Auto insurers must demonstrate to the Department of Insurance that their marketing, underwriting, rating, claims handling, fraud investigations, and any algorithm or model used for those practices do not disparately impact customers on the basis of race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression.
LA
Introduced
Covered insurers must file a Disparate Impact Audit Certification with the Commissioner annually by June 30, signed by the senior AI governance officer, including a summary of each system audited, whether disparate impact was found, corrective actions or actuarial-necessity justification, and a compliance certification.
MA
Introduced
Controllers must submit data protection assessment reports to the attorney general within 30 days of completion, make a summary publicly available in an easily accessible location, and produce full assessments to the AG upon request during investigations. Trade secrets may be redacted; attorney-client privilege is preserved.
MA
Introduced
Employers must not use an automated employment decision tool unless it has undergone an independent impact assessment within the prior year evaluating scientific validity of attributes, protected-class proxy risk, training data disparities, output disparate impact, disability accessibility, post-deployment discrimination risks, and privacy/job quality impacts. Results must be submitted to the Department of Labor Standards within 60 days for inclusion in a public registry and distributed to affected employees.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must procure quarterly harmful bias audits by an independent third-party organization covering error rates and bias assessments, submit each quarterly audit to the Commissioner within 30 days of completion, and submit annual reports summarizing the quarterly results and algorithmic performance.
MI
Introduced
Within 60 days of completing an impact assessment, employers must (a) submit the assessment in its entirety or in an accessible summary form to the Department of Labor and Economic Opportunity for inclusion in a public registry of impact assessments, and (b) distribute the assessment to all covered individuals who may be subject to the tool.
MI
Introduced
Within 60 days of completing an impact assessment, employers must submit it (in full or accessible summary) to the department for a public registry and distribute it to workers who may be subject to the tool.
NJ
Introduced
The impact assessment report, including all underlying data, must be submitted in its entirety with an accessible summary to the Department of Labor within 60 days of completion for inclusion in a public registry. The vendor must provide the report to any employer or public entity seeking to implement the AEDS or EMT. Registry entries must be made available to affected employees, applicants, and their authorized representatives; proprietary information may only be publicly disclosed in aggregated form.
NJ
Introduced
Public entities and vendors must not deploy an ABSDS until the Department of Labor has conducted an impact assessment confirming compliance with anti-discrimination, proportionality, and human-oversight requirements, including effective procedures to prevent incorrect benefit denials based on mistaken fraud claims. Vendors must provide full documentation including design, training data, accuracy analysis, and economic-impact estimates. Assessments must be completed within one year before deployment, updated upon substantial changes, and the system may not operate until the assessment is complete. Legacy ABSDS systems must be assessed within one year of the effective date.
NJ
Introduced
The ABSDS impact assessment report, with all underlying data and an accessible summary, must be submitted to the Department of Labor within 60 days of completion for inclusion in a public registry. The vendor must provide the report to any public entity seeking to deploy the ABSDS. Registry entries must be available to affected service recipients, entities, applicants, and their authorized representatives.
NY
Introduced
Employers must cease using an AEDT if an impact assessment finds disparate impact on a protected class, and may not resume use until the employer (1) takes reasonable and appropriate steps to remedy the disparate impact and (2) where the employer disputes the finding or believes remediation is sufficient, submits to the Commissioner a demonstration that the tool is the least discriminatory method available for assessing employee performance or ability to perform essential job functions.
NY
Introduced
Banks must annually (1) have an independent auditor conduct a disparate impact analysis assessing each automated decision tool used for lending decisions, differentiating between approved and non-approved applicants across protected classes, and (2) submit a summary of the most recent analysis and the tool's distribution date to the Attorney General's office.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 111
Introduced
Covered deployers must file staggered reports with the Department of Financial Services that include an impact assessment evaluating whether the high-risk AI system poses a risk of algorithmic discrimination, the steps taken to address it, monetization, and a consumer cost-benefit analysis.
NY
Introduced
Real estate brokers using virtual agents and online housing platforms using virtual agents or AI tools must have an independent disparate impact analysis conducted at least annually. The analysis must test whether the automated tool produces adverse impacts across protected classes (sex, race, ethnicity, and other classes under the Human Rights Law), whether any differentiation serves a substantial, legitimate, nondiscriminatory interest, and whether a less discriminatory alternative exists. Covered entities must submit a summary of the most recent disparate impact analysis to the attorney general's office.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
IL
Failed
Proprietors of diagnostic algorithms must regularly evaluate their algorithms for biases and discrimination against protected categories under the Illinois Human Rights Act and report findings annually to the Department of Public Health and the Department of Innovation and Technology.
IL
IL HB 5115 (Diagnostic Algorithm) § 210 ILCS 85/6.35
Failed
Proprietors of diagnostic algorithms must regularly evaluate their algorithms for biases and discrimination against protected categories under the Illinois Human Rights Act and report findings annually to the Department of Public Health and the Department of Innovation and Technology.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must procure quarterly harmful bias audits by an independent third-party organization covering error rates and harmful bias assessments, and must submit each quarterly audit to the Commissioner within 30 days of completion and annual summary reports of quarterly audit results and algorithmic performance.
NY
Failed
Employers must not use any AEDT unless it has been the subject of an impact assessment conducted by an independent auditor within the past year (or within six months of the effective date for pre-existing tools). The assessment must evaluate the tool's attributes and modeling techniques for scientific validity, proxy-variable risk across protected classes, training-data disparities, output-level disparate impact, disability accessibility, post-deployment discrimination risk, and least-discriminatory-method analysis. The completed assessment or an accessible summary must be submitted to the Department of Labor for inclusion in a public registry within 60 days and distributed to affected employees.
NY
Failed
Vendors must conduct a disparate impact report at least one year before selling or offering for sale an automated employment decision tool, and must file annual public disclosure reports with the Department of Labor that include the most recent disparate impact results and the vendor's disability accommodation policy.
NY
Failed
Employers must not use an automated employment decision tool unless it has been subjected to an independent bias audit conducted no more than one year prior to use (or within six months for tools in use at enactment). The audit must be conducted by an independent party with no conflicts of interest and must: identify modeling techniques and attributes; evaluate scientific validity and proxy-for-protected-class risk; analyze training data and output disparities across protected classes; evaluate disability accessibility impacts; assess all residual discrimination risks; and for any disparate impact finding, evaluate whether the feature at issue is the least discriminatory method. The audit must be submitted to the Department of Labor within sixty days and distributed to affected employees.
H-02.5
Public disclosure of assessment
Deployers must make the algorithmic impact assessment, in summary or full, publicly available so affected individuals, advocates, and researchers can review the system's discriminatory risks and mitigations; permitted redactions for trade secrets, security, or privilege must be described in the published version.
Enacted
0
Live
28
Failed
12
Total
40
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.3
Engrossed
After completing an impact assessment, the auditor must provide results to the contracting deployer and make a high-level summary publicly available at no cost on the auditor's website. The auditor may not publicly disclose personal information of decision subjects without express consent. Documentation must be in English and any other regularly used language and clearly presented.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2105
Introduced eff 2026-01-01
Healthcare insurers must publicly publish, on their website or another publicly available website, statistics on automated decision-making systems' approval, denial, and appeal rates in a readily accessible format, with enrollee population demographics to contextualize the equity implications of automated decisions.
CT
Introduced eff 2026-10-01
Deployers must, within thirty days of completing a bias audit, (1) file the bias audit report and a plain-language summary with the Labor Commissioner in the prescribed form, and (2) publish the plain-language summary on the deployer's website in a conspicuous place accessible to applicants and employees. The summary must include the audit methodology, key findings and identified risks, and any corrective actions taken.
GA
Introduced
Deployers must publish on their public websites all impact assessments completed within the preceding three years, in a form and manner prescribed by the Attorney General.
IL
Introduced
Employers must notify affected employees and any exclusive bargaining representative of the results of each impact assessment. A copy of the impact assessment must be provided upon request.
IL
Introduced
Employers must publish each impact assessment on the employer's website, subject to the redaction limitations in Section 20.
MA
Introduced
Controllers must submit data protection assessment reports to the attorney general within 30 days of completion, make a summary publicly available in an easily accessible location, and produce full assessments to the AG upon request during investigations. Trade secrets may be redacted; attorney-client privilege is preserved.
MA
Introduced
Employers must not use an automated employment decision tool unless it has undergone an independent impact assessment within the prior year evaluating scientific validity of attributes, protected-class proxy risk, training data disparities, output disparate impact, disability accessibility, post-deployment discrimination risks, and privacy/job quality impacts. Results must be submitted to the Department of Labor Standards within 60 days for inclusion in a public registry and distributed to affected employees.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MI
Introduced
Within 60 days of completing an impact assessment, employers must (a) submit the assessment in its entirety or in an accessible summary form to the Department of Labor and Economic Opportunity for inclusion in a public registry of impact assessments, and (b) distribute the assessment to all covered individuals who may be subject to the tool.
MI
Introduced
Within 60 days of completing an impact assessment, employers must submit it (in full or accessible summary) to the department for a public registry and distribute it to workers who may be subject to the tool.
NJ
Introduced
Employers must publish a summary of the most recent bias audit for any automated employment decision tool used to screen covered individuals on the employer's website.
NJ
Introduced
Employers must, before using an automated employment decision tool, publicly post on the employment section of their website in accessible, machine-readable, and downloadable format (plus hard copy on request): (1) the date and summary results of the most recent bias audit, including the data source, count of individuals in an unknown category, the number of applicants or candidates, selection rates or scoring rates, and impact ratios for all categories; and (2) the tool's date of operation. The summary must remain posted for at least 10 years after the tool's last use, and the employer must issue a press release when the report is made publicly available.
NJ
Introduced
The impact assessment report, including all underlying data, must be submitted in its entirety with an accessible summary to the Department of Labor within 60 days of completion for inclusion in a public registry. The vendor must provide the report to any employer or public entity seeking to implement the AEDS or EMT. Registry entries must be made available to affected employees, applicants, and their authorized representatives; proprietary information may only be publicly disclosed in aggregated form.
NJ
Introduced
The ABSDS impact assessment report, with all underlying data and an accessible summary, must be submitted to the Department of Labor within 60 days of completion for inclusion in a public registry. The vendor must provide the report to any public entity seeking to deploy the ABSDS. Registry entries must be available to affected service recipients, entities, applicants, and their authorized representatives.
NJ
Introduced
The full impact assessment report and an accessible summary must be filed with the Department within 60 days of completion for inclusion in a public registry available to affected employees, applicants, and their representatives, with proprietary information disclosed only when essential and only in aggregated form.
NJ
Introduced
The full ABSDS impact assessment report and an accessible summary must be filed with the Department within 60 days of completion for inclusion in a public registry available to affected beneficiaries, applicants, and their representatives.
NJ
Introduced
State entities must cooperate with biannual Office audits of their high-risk algorithmic systems assessing intended purpose, data inputs, potential bias or disparate impact, and risk mitigation, and must develop and implement a corrective action plan within the director's timeframe if the Office identifies bias or discrimination risk. Audit summaries must be suitable for public disclosure.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Independent evaluations and plain language reporting in the form of an algorithmic impact assessment — including disparity testing results and mitigation information — must be conducted for all automated systems. New York residents must have the right to view such evaluations and reports.
NY
Introduced
Employers must make publicly available on their website a summary of the most recent disparate impact analysis and the distribution date of the tool prior to implementing or using the automated employment decision tool.
NY
Introduced
Landlords must publish a summary of the most recent disparate impact analysis and the distribution date of the tool on their website and through any digital housing listing prior to using the automated decision tool to screen applicants.
NY
Introduced
Covered entities must conduct an impact assessment of each automated lending decision-making tool at least annually and prior to any material change, signed by an individual responsible for meaningful human review. The assessment must include bias and discrimination testing across enumerated protected characteristics, algorithm and training data descriptions, cybersecurity and privacy risk evaluation, misuse scenario analysis, and sensitive data handling practices. A summary report must be posted on the covered entity's website before initial deployment and updated after each subsequent assessment.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Introduced
Landlords must publicly post a summary of the most recent disparate impact analysis and the distribution date of the tool on their website before implementing or using the tool, and must also make the summary accessible through any digital housing listing where the tool will be used to screen applicants.
NY
Introduced
Covered entities must conduct at least annual impact assessments of each automated lending decision-making tool — signed by a responsible human reviewer — covering accuracy, fairness, bias, discrimination across protected characteristics, cybersecurity, privacy, safety, misuse risks, data practices, and notification mechanisms, and must publish a summary report on their website before deployment and after each subsequent assessment. An additional assessment is required before any material change to the tool.
VT
Introduced eff 2025-07-01
Employers must provide a copy of the impact assessment to any employee upon request. Employers must update the assessment any time a significant change or update is made to the automated decision system. A single impact assessment may address a comparable set of ADS deployed by the employer.
WA
Introduced eff 2026-07-01
Employers must provide a copy of the automated decision system impact assessment to any employee upon request.
NY
Failed
Employers must make publicly available on their website a summary of the most recent disparate impact analysis and the distribution date of the tool prior to implementing or using the automated employment decision tool.
NY
Failed
Employers must make publicly available on their website a summary of the most recent disparate impact analysis and the distribution date of the tool prior to implementing or using the automated employment decision tool.
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must publish a summary of the most recent disparate impact analysis and the distribution date of the tool on the landlord's website before implementing or using the tool, and must also make that summary accessible through any digital housing listing where the landlord intends to use the tool to screen applicants.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 405
Failed
Independent evaluations and plain-language algorithmic impact assessments — including disparity testing results and mitigation information — must be conducted for all automated systems. New York residents must have the right to view such evaluations and reports.
NY
Failed
Employers must not use an automated employment decision tool unless the tool has been the subject of a bias audit conducted within the past year by an independent, impartial auditor with no financial or legal conflicts of interest. The audit must (1) identify modeling techniques and attributes, (2) evaluate scientific validity and proxy-variable risk for protected classes, (3) assess training data and output disparities and recommend remedial actions, (4) evaluate disability accessibility limitations, (5) determine whether features causing disparate impact are the least discriminatory method available, and (6) be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Failed
Employers must publish a summary of the most recent disparate impact analysis, including the distribution date of the tool, on the employer's or employment agency's website prior to implementing or using the automated employment decision tool.
NY
Failed
Employers must not use any AEDT unless it has been the subject of an impact assessment conducted by an independent auditor within the past year (or within six months of the effective date for pre-existing tools). The assessment must evaluate the tool's attributes and modeling techniques for scientific validity, proxy-variable risk across protected classes, training-data disparities, output-level disparate impact, disability accessibility, post-deployment discrimination risk, and least-discriminatory-method analysis. The completed assessment or an accessible summary must be submitted to the Department of Labor for inclusion in a public registry within 60 days and distributed to affected employees.
NY
Failed
Vendors must include a copy of the most recent public disclosure report at no additional cost with every sale of an automated employment decision tool.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must publish a summary of the most recent disparate impact analysis and the distribution date of the tool on the landlord's website and through any digital housing listing platform before implementing or using the automated decision tool to screen applicants.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 405
Failed
Independent evaluations in the form of algorithmic impact assessments — including disparity testing results and mitigation information — must be conducted for all automated systems and reported in plain language. Residents must have the right to view these evaluations and reports.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-605
Failed
Deployers must make publicly available, in a clear and readily accessible manner, a statement summarizing how the deployer manages any reasonably foreseeable risk of algorithmic discrimination arising from deployment or use of a high-risk AI system.
VT
Failed
Employers must provide a copy of the automated decision system impact assessment to any employee upon request.
H-02.6
Independent third-party audit
A qualified independent auditor with no material relationship to the developer or deployer must evaluate the system for bias and disparate impact. Currently required primarily for automated employment decision tools.
Enacted
0
Live
53
Failed
20
Total
73
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must contract with an independent third-party auditor to assess compliance with performance evaluation requirements, provide the auditor with reasonably necessary information (with limited trade-secret redactions), consider and incorporate auditor feedback into subsequent versions, and publish a high-level summary of the auditor's feedback on the developer's website at no cost. A developer may not deploy or make the covered ADS available if the audit deadline lapses before completion.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers who use a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a three-year period must contract with an independent third-party auditor to conduct an impact assessment before January 1, 2030, and every three years thereafter. The deployer must provide the auditor with reasonably necessary information (with limited trade-secret redactions). The deployer must cease using the covered ADS if the audit deadline passes before completion. The deployer is not required to collect additional personal information beyond what is gathered in the ordinary course of business.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.3
Engrossed
Third-party auditors conducting impact assessments on deployed covered ADS must request reasonably necessary information from the deployer, and for each developer-approved use must document observed accuracy and reliability, whether observed performance materially differed from expected performance, whether any disparate impacts resulted and whether they were anticipated, whether the deployer used the system outside approved uses, and whether the deployer assumed developer responsibilities.
NY
Engrossed
Developers and deployers must have completed an independent audit under section 87 confirming reasonable care to prevent foreseeable algorithmic discrimination before using, selling, or sharing any high-risk AI system. The audit is a prerequisite to lawful operation.
CT
Introduced eff 2025-10-01
Employers must contract with an impartial third party to complete an impact assessment of any high-risk AI system no later than one year before deployment. The assessment must cover the system's purpose, use cases, deployment context, performance metrics, known limitations, error rates, algorithmic discrimination risk, accessibility, employee-rights impacts, and effects on job quality or well-being. For systems deployed before October 1, 2025, the assessment must be completed by October 1, 2026.
CT
Introduced eff 2026-10-01
Deployers must, before deploying an automated employment-related decision process and annually thereafter, contract with a Labor Commissioner-approved independent auditor to complete a bias audit. The audit must: (A) evaluate performance and error rates across relevant subgroups, (B) assess disparate impact against protected classes, (C) examine data sources and output quality, (D) evaluate threshold, scoring, and ranking criteria effects, and (E) test for less discriminatory alternatives. The auditor must have no financial or operational interest in the deployer or developer and must be approved by the Labor Commissioner.
IL
Introduced
Employers must conduct an initial impact assessment at least 30 days before implementing any automated decision-making system. The assessment must bear the signature of (1) one or more individuals responsible for meaningful human review of the system, and (2) an independent auditor. An independent auditor is disqualified if, at any point in the 5 years preceding the assessment, that person was involved in developing or deploying the system under review, had an employment relationship with the developer or deployer, or had a direct or material indirect financial interest in the developer or deployer.
IN
Introduced eff 2026-07-01
Employers must ensure that each automated decision system used for employment-related decisions is independently tested at least annually for discriminatory impact (based on race, color, religion, sex, national origin, age, disability, and genetic information) or potential biases, and the results of each test must be made publicly available.
LA
Introduced
Covered insurers must conduct an annual disparate impact audit of each ADS, performed by a qualified independent actuary (FCAS/FSA/FAAA) or data scientist with algorithmic-fairness expertise, analyzing outcomes disaggregated by protected class and geographic area, assessing each variable's contribution, evaluating less discriminatory alternatives, and documenting methodology, findings, and corrective actions.
MA
Introduced
Employers must not use electronic monitoring (alone or with an ADS) unless the monitoring has been the subject of an impact assessment conducted within one year by an independent, impartial auditor evaluating data protection/security practices, allowable purposes, potential legal violations, and impact on employee privacy and job quality.
MA
Introduced
Employers must not use an automated employment decision tool unless it has undergone an independent impact assessment within the prior year evaluating scientific validity of attributes, protected-class proxy risk, training data disparities, output disparate impact, disability accessibility, post-deployment discrimination risks, and privacy/job quality impacts. Results must be submitted to the Department of Labor Standards within 60 days for inclusion in a public registry and distributed to affected employees.
MA
Introduced
Employers must not use electronic monitoring, alone or with an automated employment decision system, unless the monitoring has been the subject of an impact assessment. The assessment must: (1) be conducted no more than one year before use (or within six months of the effective date for pre-existing monitoring); (2) be conducted by an independent and impartial party with no financial or legal conflicts of interest; (3) evaluate whether data protection and security practices are consistent with applicable law and cybersecurity best practices; (4) identify the allowable purpose(s); (5) consider and describe any other ways the monitoring could violate applicable law and steps to prevent such violations; and (6) consider and describe whether the monitoring may negatively impact employees' privacy and job quality, including wages, hours, and working conditions.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must procure quarterly harmful bias audits by an independent third-party organization covering error rates and bias assessments, submit each quarterly audit to the Commissioner within 30 days of completion, and submit annual reports summarizing the quarterly results and algorithmic performance.
MI
Introduced
Before using any automated decisions tool or electronic monitoring tool, employers must commission an impact assessment by an independent and impartial third party with no financial or legal conflicts of interest. The assessment must be conducted one year before implementation (or within 6 months of the act's effective date for tools already in use) and must: (a) evaluate the tool's objectives, algorithms, data, cybersecurity vulnerabilities, and potential biases including discriminatory outcomes based on race, gender, or disability; (b) identify the attributes and modeling techniques the tool uses; (c) evaluate whether those attributes are scientifically valid means of evaluating performance and whether they may function as proxies for protected classes under the Elliott-Larsen Civil Rights Act; (d) identify disparate-impact risks in training data and outputs and describe remedial actions; (e) evaluate disability accessibility limitations and describe remedies; (f) describe potential sources of post-implementation adverse impact; (g) assess whether any feature causing disparate impact is the least discriminatory method available; (h) identify other potential legal violations and steps to prevent them; and (i) describe potential negative effects on privacy, wages, hours, and working conditions.
MI
Introduced
Before using an automated decisions or electronic monitoring tool, employers must commission an independent, conflict-free third-party impact assessment evaluating the tool's objectives, algorithms, data, cybersecurity, biases, proxy variables, disparate impact, accessibility limits, and privacy and job-quality effects, with remediation steps.
NJ
Introduced
Developers must not sell, deploy, or offer for sale an automated employment decision tool in New Jersey unless (1) the tool has been the subject of an independent bias audit within the past year, (2) the sale includes at no additional cost an annual bias audit service with results provided to the purchaser and a written plan to monitor implementation of audit recommendations, (3) the tool is accompanied by a notice stating it is subject to this act, and (4) the developer has implemented the most recent bias audit's recommendations and issued a press release announcing how those recommendations were implemented.
NJ
Introduced
Employers and employment agencies must not use or continue to use an automated employment decision tool unless it has been subject to an independent bias audit within the preceding one year.
NJ
Introduced
Each bias audit must calculate selection rates or scoring rates and impact ratios for each protected category — including sex, race/color/national origin/ethnicity, age, marital/familial status, disability, religion, sexual orientation, gender identity, income source, and intersectional categories of sex, ethnicity, and race — and must indicate the number of individuals excluded from calculations because they fall within an unknown category. Categories representing less than two percent of the audit data may be excluded from impact-ratio calculations if justified and disclosed.
NJ
Introduced
Employers, public entities, and vendors must not deploy an AEDS or EMT until an independent auditor (or, for public employees, the Department of Labor) has conducted an impact assessment confirming the system serves only enumerated allowable purposes, uses the least invasive means, complies with anti-discrimination requirements (including disparate-impact analysis of training data), and implements effective human-oversight procedures. Vendors must provide the auditor full access to design documentation, training data sources, accuracy analyses, and economic-impact estimates. Assessments must be completed within one year before deployment, updated upon any substantial change, and the system may not operate until a compliant assessment is in place. Legacy systems must be assessed within six months of the effective date.
NJ
Introduced
Employers and employment agencies must not use or continue to use an AEDT unless an independent bias audit of the AEDT has been completed within the preceding one year.
NJ
Introduced
Bias audits must calculate selection rates, scoring rates, and impact ratios for each EEO-1 category, separately analyzed across sex, race/ethnicity, and intersectional categories, and must report the number of individuals in unknown categories. Categories representing less than two percent of the data may be excluded if the auditor provides justification and reports the excluded category's applicant count and rate.
NJ
Introduced
Employers, public entities, and vendors must, before deploying an AEDS or EMT, have an independent auditor (or the Department of Labor for public-employee systems) conduct and affirm an impact assessment confirming Section 2 compliance, disparate-impact analysis, and human-oversight procedures, updated within one year before deployment and re-run on any substantial change.
NJ
Introduced
Public entities and vendors must not deploy an ABSDS unless the Department of Labor conducts and affirms an impact assessment confirming Section 2 compliance, analyzing training-data disparities and disparate adverse impact on beneficiaries, and requiring human-oversight procedures to prevent harmful outcomes including erroneous fraud-based benefit denials; re-run on any substantial change.
NY
NY AB 3125 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Introduced
Landlords must ensure that an independent auditor conducts a disparate impact analysis of each automated housing decision making tool at least annually. The analysis must assess the tool's actual impact on applicants by sex, race, ethnicity, and other protected classes, and must differentiate between applicants who were selected and applicants who were not selected. The completed analysis must be provided to the landlord.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Independent evaluations and plain language reporting in the form of an algorithmic impact assessment — including disparity testing results and mitigation information — must be conducted for all automated systems. New York residents must have the right to view such evaluations and reports.
NY
Introduced
Employers with 100 or more employees must not use an AEDT for any employment decision unless the tool has been subjected to a disparate-impact assessment, conducted within the prior year by an impartial auditor with no financial or legal conflicts of interest. The assessment must identify modeling techniques, evaluate disparate impact on protected classes, assess whether the tool uses the least discriminatory method, and be submitted to the Department of Labor for a public registry within 60 days of completion and distributed to affected employees.
NY
Introduced
Landlords must have an independent auditor conduct an annual disparate impact analysis assessing the actual impact of each automated decision tool used to screen housing applicants, including testing for adverse impact on the basis of sex, race, ethnicity, or other protected class.
NY
Introduced
Banks must annually (1) have an independent auditor conduct a disparate impact analysis assessing each automated decision tool used for lending decisions, differentiating between approved and non-approved applicants across protected classes, and (2) submit a summary of the most recent analysis and the tool's distribution date to the Attorney General's office.
NY
Introduced
Developers of high-risk AI decision systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses. A rebuttable presumption of reasonable care applies if the developer complies with all requirements of this section and retains an independent third-party auditor — from a list the attorney general publishes at least annually — to complete bias and governance audits for the system.
NY
Introduced
Deployers of high-risk AI decision systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A rebuttable presumption of reasonable care applies if the deployer complies with all requirements of § 1552 and retains an AG-identified independent third-party auditor to complete bias and governance audits for the system.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 110
Introduced
Covered developers must commission an independent third-party audit of each high-risk AI system within six months of completing development and offering it, and annually thereafter, evaluating whether reasonable care was taken to prevent algorithmic discrimination and whether the risk management program conforms to statute.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 110
Introduced
Covered deployers must commission an independent third-party audit of each high-risk AI system within six months of deployment, again at one year, and every two years thereafter, evaluating reasonable care against algorithmic discrimination, system accuracy and reliability, and risk-management-program conformity.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 110
Introduced
Covered developers and deployers must use auditors that are independent — barred from prior or concurrent service relationships in the past twelve months, from competing AI development for five years, and from contingent or success-based fees — except they may use an internal auditor only when an independent audit would cost more than one percent of their fair market value.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 110
Introduced
Covered developers and deployers must give the auditor complete and unredacted copies of all prior reports filed with DFS, and must not let an AI system complete an audit in full or draft it without meaningful human review and oversight.
NY
Introduced
Real estate brokers using virtual agents and online housing platforms using virtual agents or AI tools must have an independent disparate impact analysis conducted at least annually. The analysis must test whether the automated tool produces adverse impacts across protected classes (sex, race, ethnicity, and other classes under the Human Rights Law), whether any differentiation serves a substantial, legitimate, nondiscriminatory interest, and whether a less discriminatory alternative exists. Covered entities must submit a summary of the most recent disparate impact analysis to the attorney general's office.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Developers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: the algorithm's design and methodology (inputs and outputs); creation, training, and testing details (performance metrics, benchmarks, demographic representation, testing outputs, stakeholder consultation, protected-characteristic testing methodology); precursor algorithms; data sources, types, legal authorization, and representativeness; training process details; potential for harm or disparate impact; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the developer.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 103
Introduced
Deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering: how the algorithm makes or contributes to a consequential action and its deployment purpose; necessity and proportionality relative to the baseline process being replaced; data inputs (type, collection, inference, processing, legal authorization, representativeness); expected and actual testing outputs; additional testing or training conducted by the deployer; stakeholder consultation; potential for harm or disparate impact in the deployment context; alternative mitigation practices and monitoring recommendations; and any additional information prescribed by the Division. The independent auditor must submit a report with findings and recommendations to the deployer.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 104
Introduced
Deployers must, when harm is identified during the annual preliminary assessment, engage an independent auditor to conduct a full impact assessment covering: actual harms produced or likely produced; the extent of disparate impact and methodology; data types input during the reporting period (including field descriptions and whether data was used for retraining); whether the algorithm produced expected outputs; how the algorithm was used in consequential actions; mitigation actions taken and staff training; and any additional Division-prescribed information. The auditor must submit findings and recommendations to the deployer. Within 30 days of receiving the auditor's report, the deployer must submit a summary to the developer, subject to trade secret and privacy protections.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Developers of high-risk AI decision systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses. A rebuttable presumption of reasonable care attaches if the developer (1) complied with the article's provisions and (2) retained an independent third-party auditor from the attorney general's published list to complete bias and governance audits for the system. The attorney general must identify qualified independent auditors and publish their list on the AG's website by January 1, 2026, and update the list at least annually.
NY
Introduced
Deployers of high-risk AI decision systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A rebuttable presumption of reasonable care attaches if the deployer (1) complied with the article's provisions and (2) retained an independent third-party auditor from the attorney general's published list to complete bias and governance audits for the system.
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Introduced
Landlords must obtain at least annually a disparate impact analysis conducted by an independent auditor assessing the actual impact of any automated housing decision making tool used to screen applicants for housing, testing for adverse impact across sex, race, ethnicity, and other protected classes.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not use electronic monitoring, alone or in conjunction with an automated decision system, unless the proposed use has been the subject of an impact assessment. The impact assessment must: (1) be conducted no more than one year before use begins (or within six months of the effective date for pre-existing monitoring), (2) be conducted by an independent and impartial party with no financial or legal conflicts of interest, (3) evaluate whether data protection and security practices are consistent with applicable law and cybersecurity best practices, (4) identify the allowable purposes as defined in the chapter, (5) consider and describe any other ways the monitoring could result in a law violation and necessary steps to prevent it, (6) consider and describe whether the monitoring may negatively impact employees' privacy and job quality including wages, hours, and working conditions, and (7) be disclosed in full, in plain language, to all affected workers and their authorized representatives within 30 days of the employer's receipt. Workers and their authorized representatives have the right to comment on, challenge, and bargain over the proposed monitoring based on the assessment's findings.
TX
TX HB 5282 (AI Assessment Scoring) § Educ. Code § 39.023(q)–(r)
Introduced eff 2025-09-01
Before the agency may permit an AI scoring method for constructed responses, the method must (1) have been trained on representative samples including responses from educationally disadvantaged, emergent bilingual, and special-education-eligible students, (2) demonstrate validity and reliability consistent with industry-accepted standards including NAEP standards, and (3) be evaluated and certified by a qualified independent entity — unaffiliated with TEA or the scoring method developer — as valid, reliable, free of measurable bias against disadvantaged students, and compliant with applicable psychometric standards.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering the algorithm's design, methodology, training data, testing across demographic groups, potential for disparate impact, and mitigation recommendations, and receive a written report from the auditor.
US
Introduced
Deployers must conduct annual post-deployment impact assessments to identify any harm caused by the covered algorithm during the reporting period. If harm is identified, the deployer must engage an independent auditor to conduct a full impact assessment and share a summary with the developer within 30 days.
US
Introduced
Employers must ensure that any automated decision system used to generate outputs for employment-related decisions has undergone pre-deployment testing and validation for efficacy, compliance with seven enumerated federal employment discrimination laws, absence of discriminatory impact across protected characteristics, and compliance with the NIST AI RMF. The system must also be independently tested at least annually for discriminatory impact and bias, with results made publicly available.
US
Introduced
Developers and deployers must, when harm is plausible, engage an independent auditor to conduct a full pre-deployment evaluation covering design, methodology, training data, testing across protected characteristics, stakeholder consultation, potential for disparate impact, and mitigation recommendations. The auditor must submit a report with findings and recommendations.
US
Introduced
Deployers must conduct annual post-deployment impact assessments to identify any harm from the covered algorithm. If harm occurred, the deployer must engage an independent auditor for a full assessment covering actual harm, disparate impact analysis, data inputs, outputs, mitigation actions, and recommendations. Assessment summaries must be shared with the developer within 30 days.
VT
Introduced eff 2025-07-01
Developers must not use, sell, or share an automated decision system for use in a consequential decision unless the system has passed an independent audit in accordance with § 4193e. If an independent audit finds the system produces algorithmic discrimination, the developer must not use, sell, or share the system until the discrimination has been rectified and confirmed by a post-adjustment audit.
VT
Introduced eff 2025-07-01
Developers and deployers are jointly responsible for ensuring an independent audit is conducted prior to deployment, six months after deployment, and at least every 18 months thereafter. The audit must include: (1) analysis of data management policies and data security compliance; (2) analysis of system validity and reliability by use case; (3) comparative performance analysis across demographic groups with a determination of whether algorithmic discrimination is produced; (4) analysis of compliance with applicable labor, civil rights, consumer protection, privacy, and data privacy laws; and (5) evaluation of the risk management program. Auditors must be fully independent — no prior commercial, employment, or financial relationship with the developer or deployer within 12 months, fees must not be contingent on results, and no incentives for positive outcomes. Audits must be completed entirely without the assistance of an automated decision system. Auditors must receive complete and unredacted copies of all prior reports. All completed audits must be delivered to the Attorney General regardless of findings. Absent a contractual allocation of responsibility, the developer and deployer are jointly and severally liable.
MA
MA HB 4029 (Algorithmic Accountability) § G.L. c. 93, § 115(c)
Failed
Covered entities must conduct impact assessments in consultation with external third parties, including independent auditors and independent technology experts, where reasonably possible.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must procure quarterly harmful bias audits by an independent third-party organization covering error rates and harmful bias assessments, and must submit each quarterly audit to the Commissioner within 30 days of completion and annual summary reports of quarterly audit results and algorithmic performance.
NC
Failed
Deployers must not use an AEDT to make a covered employment decision unless the AEDT has undergone an independent bias audit within the preceding 12 months, the audit results are publicly accessible, and advance notice has been provided to the affected individual. The deployer may rely on a vendor-commissioned audit if the auditor meets independence requirements.
NC
Failed
Prime contractors must comply with the bias audit, disclosure, and advance notice requirements of the Fair AI Hiring Act for any AEDT used to select contract employees under a covered contract (personal service contracts exceeding $25,000).
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must ensure that a qualified independent auditor conducts a disparate impact analysis of any automated decision tool used to screen housing applicants at least annually, assessing actual adverse impact across sex, race, ethnicity, and other protected classes and differentiating between selected and non-selected applicants.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 405
Failed
Independent evaluations and plain-language algorithmic impact assessments — including disparity testing results and mitigation information — must be conducted for all automated systems. New York residents must have the right to view such evaluations and reports.
NY
Failed
Employers must not use an automated employment decision tool unless the tool has been the subject of a bias audit conducted within the past year by an independent, impartial auditor with no financial or legal conflicts of interest. The audit must (1) identify modeling techniques and attributes, (2) evaluate scientific validity and proxy-variable risk for protected classes, (3) assess training data and output disparities and recommend remedial actions, (4) evaluate disability accessibility limitations, (5) determine whether features causing disparate impact are the least discriminatory method available, and (6) be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Failed
Employers must not use any AEDT unless it has been the subject of an impact assessment conducted by an independent auditor within the past year (or within six months of the effective date for pre-existing tools). The assessment must evaluate the tool's attributes and modeling techniques for scientific validity, proxy-variable risk across protected classes, training-data disparities, output-level disparate impact, disability accessibility, post-deployment discrimination risk, and least-discriminatory-method analysis. The completed assessment or an accessible summary must be submitted to the Department of Labor for inclusion in a public registry within 60 days and distributed to affected employees.
NY
Failed
Employers must not use an automated employment decision tool unless it has been subjected to an independent bias audit conducted no more than one year prior to use (or within six months for tools in use at enactment). The audit must be conducted by an independent party with no conflicts of interest and must: identify modeling techniques and attributes; evaluate scientific validity and proxy-for-protected-class risk; analyze training data and output disparities across protected classes; evaluate disability accessibility impacts; assess all residual discrimination risks; and for any disparate impact finding, evaluate whether the feature at issue is the least discriminatory method. The audit must be submitted to the Department of Labor within sixty days and distributed to affected employees.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must obtain at least annually a disparate impact analysis conducted by an independent auditor assessing the actual impact of the automated decision tool across protected classes (sex, race, ethnicity, and other protected classes), differentiating between selected and non-selected applicants.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 405
Failed
Independent evaluations in the form of algorithmic impact assessments — including disparity testing results and mitigation information — must be conducted for all automated systems and reported in plain language. Residents must have the right to view these evaluations and reports.
PA
Failed
Employers and employment agencies must not use an automated employment decision tool unless it has undergone an independent bias audit within the prior year and a summary of the most recent bias audit results has been published on the employer's or agency's publicly accessible website.
US
Failed
Law enforcement agencies must not use any facial recognition system unless it has been annually submitted to NIST's benchmark test for law enforcement and has achieved a sufficiently high level of accuracy, including non-discriminatory variance by race, ethnicity, gender, and age, as determined by NIST.
US
Failed
Law enforcement agencies must annually submit their facial recognition systems to operational testing by an independent entity, using NIST's protocol, to determine system accuracy, impact of human reviewers on accuracy, and whether accuracy varies by race, ethnicity, gender, orage.
US
Failed
Employers must ensure the automated decision system is independently tested at least annually for discriminatory impact and potential biases, with results made publicly available.
US
Failed
Employers must ensure the automated decision system is independently tested at least annually for discriminatory impact and potential biases, and the results of such testing must be made publicly available.
US
Failed
Developers and deployers must engage an independent auditor to conduct a full pre-deployment evaluation when harm is plausible, covering the algorithm's design, methodology, training and testing data, demographic representation, testing across protected characteristics, potential for disparate impact, and mitigation recommendations. The independent auditor must submit a report to the developer or deployer.
US
Failed
Deployers must conduct annual post-deployment impact assessments of each covered algorithm, beginning with a preliminary assessment; if harm is identified, they must engage an independent auditor to conduct a full impact assessment covering resulting harms, disparate impact, data inputs, output accuracy, and mitigation actions. The independent auditor must submit a report to the deployer, who must forward a summary to the developer within 30 days.
WA
Failed
Public agencies must ensure the automated decision system and its training data are made freely available by the vendor before, during, and after deployment for agency or independent third-party testing, auditing, or research to understand its impacts, including potential bias, inaccuracy, or disparate impacts.
WA
Failed
The Algorithmic Accountability Review Board must conduct selective audits of algorithmic accountability reports for pre-2026 systems, evaluating whether each system meets minimum standards for bias and accuracy, considering the number of affected persons, likelihood of discriminatory results, and severity of effects. The Office must establish audit volume guidelines by January 1, 2024.
H-02.7
Public disclosure of audit results
Audit results, including selection rates and impact ratios across protected categories, must be published prior to or contemporaneous with deployment.
Enacted
0
Live
20
Failed
13
Total
33
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed
Developers must contract with an independent third-party auditor to assess compliance with performance evaluation requirements, provide the auditor with reasonably necessary information (with limited trade-secret redactions), consider and incorporate auditor feedback into subsequent versions, and publish a high-level summary of the auditor's feedback on the developer's website at no cost. A developer may not deploy or make the covered ADS available if the audit deadline lapses before completion.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.3
Engrossed
After completing an impact assessment, the auditor must provide results to the contracting deployer and make a high-level summary publicly available at no cost on the auditor's website. The auditor may not publicly disclose personal information of decision subjects without express consent. Documentation must be in English and any other regularly used language and clearly presented.
CT
Introduced eff 2026-10-01
Deployers must, within thirty days of completing a bias audit, (1) file the bias audit report and a plain-language summary with the Labor Commissioner in the prescribed form, and (2) publish the plain-language summary on the deployer's website in a conspicuous place accessible to applicants and employees. The summary must include the audit methodology, key findings and identified risks, and any corrective actions taken.
IN
Introduced eff 2026-07-01
Employers must ensure that each automated decision system used for employment-related decisions is independently tested at least annually for discriminatory impact (based on race, color, religion, sex, national origin, age, disability, and genetic information) or potential biases, and the results of each test must be made publicly available.
MA
Introduced
Employers must not use an automated employment decision tool unless the tool has been the subject of an independent impact assessment conducted no more than one year before use (or within six months of the effective date for tools already in use). The assessment must be conducted by an independent, impartial party with no financial or legal conflicts of interest and must: identify the tool's attributes and modeling techniques; evaluate scientific validity and proxy-variable risk for protected classes; identify training data disparities and their potential disparate impact; identify output disparate impacts; evaluate disability accessibility limitations; consider post-deployment adverse impact sources; assess all other discrimination risks arising during the assessment; evaluate whether any feature causing disparate impact is the least discriminatory method available; consider other potential legal violations and prevention steps; consider privacy and job-quality impacts; and be submitted in its entirety or accessible summary form to the Department of Labor Standards for a public registry within sixty days of completion and distributed to employees subject to the tool.
MI
Introduced
Within 60 days of completing an impact assessment, employers must (a) submit the assessment in its entirety or in an accessible summary form to the Department of Labor and Economic Opportunity for inclusion in a public registry of impact assessments, and (b) distribute the assessment to all covered individuals who may be subject to the tool.
NJ
Introduced
Developers must not sell, deploy, or offer for sale an automated employment decision tool in New Jersey unless (1) the tool has been the subject of an independent bias audit within the past year, (2) the sale includes at no additional cost an annual bias audit service with results provided to the purchaser and a written plan to monitor implementation of audit recommendations, (3) the tool is accompanied by a notice stating it is subject to this act, and (4) the developer has implemented the most recent bias audit's recommendations and issued a press release announcing how those recommendations were implemented.
NJ
Introduced
Employers must, before using an automated employment decision tool, publicly post on the employment section of their website in accessible, machine-readable, and downloadable format (plus hard copy on request): (1) the date and summary results of the most recent bias audit, including the data source, count of individuals in an unknown category, the number of applicants or candidates, selection rates or scoring rates, and impact ratios for all categories; and (2) the tool's date of operation. The summary must remain posted for at least 10 years after the tool's last use, and the employer must issue a press release when the report is made publicly available.
NJ
Introduced
Employers and employment agencies must publicly post on the employment section of their website, before using the AEDT, a summary of the most recent bias audit results — including the audit date, data source and explanation, unknown-category counts, applicant numbers, selection or scoring rates, impact ratios for all categories, and the AEDT distribution date. The posting must remain available for at least six months after the employer's latest use of the AEDT.
NY
NY AB 3125 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Introduced
Landlords must publicly post a summary of the most recent disparate impact analysis, including the distribution date of the tool version analyzed, on the landlord's website before implementing or using the tool. The summary must also be accessible through any housing listing on a digital platform for which the landlord intends to use the automated housing decision making tool to screen applicants.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Independent evaluations and plain language reporting in the form of an algorithmic impact assessment — including disparity testing results and mitigation information — must be conducted for all automated systems. New York residents must have the right to view such evaluations and reports.
NY
Introduced
Employers with 100 or more employees must not use an AEDT for any employment decision unless the tool has been subjected to a disparate-impact assessment, conducted within the prior year by an impartial auditor with no financial or legal conflicts of interest. The assessment must identify modeling techniques, evaluate disparate impact on protected classes, assess whether the tool uses the least discriminatory method, and be submitted to the Department of Labor for a public registry within 60 days of completion and distributed to affected employees.
NY
Introduced
Landlords must publish a summary of the most recent disparate impact analysis and the distribution date of the tool on their website and through any digital housing listing prior to using the automated decision tool to screen applicants.
NY
Introduced
Employers with 100 or more employees must obtain an independent impact assessment by an impartial auditor before using any automated employment decision tool. The assessment must evaluate disparate impact across protected classes, describe attributes and modeling techniques, identify remediation actions, evaluate least-discriminatory alternatives, and be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Employers must not use an AEDT for any employment decision unless it has been subject to an independent impact assessment conducted within the prior year (or within six months of the effective date for pre-existing tools). The assessment must be conducted by an independent auditor, and must evaluate the tool's scientific validity, identify disparate impacts on protected classes in both training data and outputs, assess disability accessibility, evaluate proxy-variable risk, identify potential post-deployment adverse impacts, and determine whether each flagged feature is the least discriminatory method available. The completed assessment or an accessible summary must be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Introduced
Developers of high-risk AI decision systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses. A rebuttable presumption of reasonable care attaches if the developer (1) complied with the article's provisions and (2) retained an independent third-party auditor from the attorney general's published list to complete bias and governance audits for the system. The attorney general must identify qualified independent auditors and publish their list on the AG's website by January 1, 2026, and update the list at least annually.
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Introduced
Landlords must publicly post a summary of the most recent disparate impact analysis and the distribution date of the tool on their website before implementing or using the tool, and must also make the summary accessible through any digital housing listing where the tool will be used to screen applicants.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not use electronic monitoring, alone or in conjunction with an automated decision system, unless the proposed use has been the subject of an impact assessment. The impact assessment must: (1) be conducted no more than one year before use begins (or within six months of the effective date for pre-existing monitoring), (2) be conducted by an independent and impartial party with no financial or legal conflicts of interest, (3) evaluate whether data protection and security practices are consistent with applicable law and cybersecurity best practices, (4) identify the allowable purposes as defined in the chapter, (5) consider and describe any other ways the monitoring could result in a law violation and necessary steps to prevent it, (6) consider and describe whether the monitoring may negatively impact employees' privacy and job quality including wages, hours, and working conditions, and (7) be disclosed in full, in plain language, to all affected workers and their authorized representatives within 30 days of the employer's receipt. Workers and their authorized representatives have the right to comment on, challenge, and bargain over the proposed monitoring based on the assessment's findings.
US
Introduced
Employers must ensure that any automated decision system used to generate outputs for employment-related decisions has undergone pre-deployment testing and validation for efficacy, compliance with seven enumerated federal employment discrimination laws, absence of discriminatory impact across protected characteristics, and compliance with the NIST AI RMF. The system must also be independently tested at least annually for discriminatory impact and bias, with results made publicly available.
VT
Introduced eff 2025-07-01
Developers and deployers are jointly responsible for ensuring an independent audit is conducted prior to deployment, six months after deployment, and at least every 18 months thereafter. The audit must include: (1) analysis of data management policies and data security compliance; (2) analysis of system validity and reliability by use case; (3) comparative performance analysis across demographic groups with a determination of whether algorithmic discrimination is produced; (4) analysis of compliance with applicable labor, civil rights, consumer protection, privacy, and data privacy laws; and (5) evaluation of the risk management program. Auditors must be fully independent — no prior commercial, employment, or financial relationship with the developer or deployer within 12 months, fees must not be contingent on results, and no incentives for positive outcomes. Audits must be completed entirely without the assistance of an automated decision system. Auditors must receive complete and unredacted copies of all prior reports. All completed audits must be delivered to the Attorney General regardless of findings. Absent a contractual allocation of responsibility, the developer and deployer are jointly and severally liable.
NC
Failed
Deployers must not use an AEDT to make a covered employment decision unless the AEDT has undergone an independent bias audit within the preceding 12 months, the audit results are publicly accessible, and advance notice has been provided to the affected individual. The deployer may rely on a vendor-commissioned audit if the auditor meets independence requirements.
NC
Failed
Deployers must publish on the employment section of their public website a bias audit summary — including the audit date, auditor name, AEDT description, data source and scope, demographic selection/scoring rates and impact ratios, and adverse-impact findings — within 30 days of audit completion and before any AEDT use. Summaries must remain publicly accessible for at least three years.
NC
Failed
Public employers must incorporate the AEDT audit, disclosure, and notice requirements of this Chapter into their recruitment, selection, and promotion policies, and must post bias audit summaries on the relevant agency's public website.
NC
Failed
Prime contractors must comply with the bias audit, disclosure, and advance notice requirements of the Fair AI Hiring Act for any AEDT used to select contract employees under a covered contract (personal service contracts exceeding $25,000).
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must publish a summary of the most recent disparate impact analysis and the distribution date of the tool on the landlord's website before implementing or using the tool, and must also make that summary accessible through any digital housing listing where the landlord intends to use the tool to screen applicants.
NY
Failed
Employers must not use an automated employment decision tool unless the tool has been the subject of a bias audit conducted within the past year by an independent, impartial auditor with no financial or legal conflicts of interest. The audit must (1) identify modeling techniques and attributes, (2) evaluate scientific validity and proxy-variable risk for protected classes, (3) assess training data and output disparities and recommend remedial actions, (4) evaluate disability accessibility limitations, (5) determine whether features causing disparate impact are the least discriminatory method available, and (6) be submitted to the Department of Labor for a public registry within 60 days and distributed to affected employees.
NY
Failed
Vendors must conduct a disparate impact report at least one year before selling or offering for sale an automated employment decision tool, and must file annual public disclosure reports with the Department of Labor that include the most recent disparate impact results and the vendor's disability accommodation policy.
NY
Failed
Employers must not use an automated employment decision tool unless it has been subjected to an independent bias audit conducted no more than one year prior to use (or within six months for tools in use at enactment). The audit must be conducted by an independent party with no conflicts of interest and must: identify modeling techniques and attributes; evaluate scientific validity and proxy-for-protected-class risk; analyze training data and output disparities across protected classes; evaluate disability accessibility impacts; assess all residual discrimination risks; and for any disparate impact finding, evaluate whether the feature at issue is the least discriminatory method. The audit must be submitted to the Department of Labor within sixty days and distributed to affected employees.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must publish a summary of the most recent disparate impact analysis and the distribution date of the tool on the landlord's website and through any digital housing listing platform before implementing or using the automated decision tool to screen applicants.
PA
Failed
Employers and employment agencies must not use an automated employment decision tool unless it has undergone an independent bias audit within the prior year and a summary of the most recent bias audit results has been published on the employer's or agency's publicly accessible website.
US
Failed
Summaries of all benchmark and operational test findings must be submitted to the Director of the Administrative Office of the United States Courts and posted on its public website.
US
Failed
Employers must ensure the automated decision system is independently tested at least annually for discriminatory impact and potential biases, with results made publicly available.
US
Failed
Employers must ensure the automated decision system is independently tested at least annually for discriminatory impact and potential biases, and the results of such testing must be made publicly available.
H-02.8
Periodic Post-Deployment Discrimination Review
Deployers must conduct periodic (at least annual) reviews of each deployed high-risk AI system to affirmatively verify the system is not causing algorithmic discrimination, separate from pre-deployment bias assessments. Reviews may be conducted internally or by a contracted third party.
Enacted
3
Live
46
Failed
41
Total
90
CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must cover purpose, algorithmic discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. Deployers must retain all impact assessments and records for at least three years after final deployment, and must conduct at least annual reviews to verify each system is not causing algorithmic discrimination.
CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment and at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must include: (1) a statement of purpose, intended use cases, deployment context, and benefits; (2) an analysis of algorithmic discrimination risks with mitigation steps; (3) categories of input data and outputs; (4) data used to customize the system if applicable; (5) performance metrics and known limitations; (6) transparency measures including consumer disclosure of AI use; and (7) post-deployment monitoring and user safeguards. After a substantial modification, the assessment must also disclose the extent to which actual use was consistent with the developer's intended uses. A single assessment may cover a comparable set of systems. An assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect. Deployers must retain the most recent impact assessment, all associated records, and all prior assessments for at least three years following final deployment. In addition, deployers must review deployment of each high-risk AI system at least annually to ensure it is not causing algorithmic discrimination.
CT
Enacted eff 2023-07-01
The Department of Administrative Services must perform ongoing assessments of AI systems in use by state agencies to ensure no system results in unlawful discrimination or disparate impact, following the policies established by the Office of Policy and Management.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers who use a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a three-year period must contract with an independent third-party auditor to conduct an impact assessment before January 1, 2030, and every three years thereafter. The deployer must provide the auditor with reasonably necessary information (with limited trade-secret redactions). The deployer must cease using the covered ADS if the audit deadline passes before completion. The deployer is not required to collect additional personal information beyond what is gathered in the ordinary course of business.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2105
Introduced eff 2026-01-01
Healthcare insurers using automated decision-making systems must conduct regular system audits to verify the system is not increasing overall or disparate claims denials, coverage limitations, or otherwise decreasing access to care.
AZ
Introduced
AI businesses must conduct quarterly audits of each high-risk AI system to identify and correct instances of discrimination, harmful outputs, or unsafe behavior.
GA
Introduced
Deployers (or a contracted third party) must review the deployment of each automated decision system at least annually to ensure that the system is not causing algorithmic discrimination.
HI
Introduced
Deployers must complete an internal impact assessment at least annually, and upon any intentional and substantial modification of a high-risk AI system, evaluating intended use, data categories and limitations, foreseeable risks of consumer harm, discrimination mitigation steps, and monitoring results.
IA
Introduced
Deployers must review, at least annually, the deployment of each high-risk AI system to ensure the system is not causing algorithmic discrimination.
IL
Introduced
Employers must conduct additional impact assessments at least once every 2 years and before any material changes to the automated decision-making system. Each assessment must include, in plain language: (1) a description of the system's objectives; (2) an evaluation of the system's ability to achieve those objectives; (3) a description and evaluation of algorithms, computational models, and AI tools used, including a summary of underlying algorithms and a description of the design and training; (4) testing for: (A) disparate impact or discrimination based on protected characteristics (race, color, religious creed, national origin, sex, disability, gender identity, sexual orientation, genetic information, pregnancy, ancestry, veteran status) and mitigation actions; (B) accessibility limitations for persons with disabilities; (C) privacy and job quality impacts including wages, hours, conditions, and safeguards; (D) cybersecurity vulnerabilities and safeguards; (E) public health or safety risks; (F) foreseeable misuse and safeguards; and (G) use, storage, and control of sensitive or personal data; and (5) a notification mechanism for employees impacted by the system.
IN
Introduced eff 2026-07-01
Employers must ensure that each automated decision system used for employment-related decisions is independently tested at least annually for discriminatory impact (based on race, color, religion, sex, national origin, age, disability, and genetic information) or potential biases, and the results of each test must be made publicly available.
LA
Introduced
Covered insurers must conduct an annual disparate impact audit of each ADS, performed by a qualified independent actuary (FCAS/FSA/FAAA) or data scientist with algorithmic-fairness expertise, analyzing outcomes disaggregated by protected class and geographic area, assessing each variable's contribution, evaluating less discriminatory alternatives, and documenting methodology, findings, and corrective actions.
MA
Introduced
Controllers must review and update data protection assessments throughout the processing lifecycle as appropriate given the type, amount, and sensitivity of data and risk level, to monitor for harm and adjust safeguards.
MA
Introduced
Employers must conduct or commission subsequent impact assessments annually for each year the automated employment decision tool is in use, meeting all initial assessment requirements and additionally assessing any change in the tool's validity or disparate impact.
MA
Introduced
Deployers must complete an annual impact assessment for each high-risk AI system covering: (i) the purpose and intended use, (ii) data categories used and outputs generated, and (iii) potential risks of discrimination and mitigation measures. Impact assessments must be updated after any substantial modification to the system.
MA
Introduced
Deployers must, at least annually, review the deployment of each high-risk AI system to ensure that the system is not causing algorithmic discrimination. The review may be conducted by the deployer or a third party contracted by the deployer.
MA
Introduced
Employers must conduct or commission subsequent impact assessments annually for each year the automated employment decision tool remains in use. Subsequent assessments must meet all requirements of the initial assessment and must additionally assess and describe any change in the tool's validity or disparate impact since the prior assessment.
MI
Introduced
Employers must conduct or commission subsequent impact assessments annually for each year in which an electronic monitoring tool or automated decisions tool is in use. Annual assessments must meet the same requirements as the initial assessment and must assess and describe any change in the tool's validity or disparate impact.
MI
Introduced
Employers must conduct or commission an updated impact assessment each year a monitoring or automated decisions tool remains in use, reassessing the tool's validity and any change in disparate impact.
NJ
Introduced
Employers and employment agencies must not use or continue to use an automated employment decision tool unless it has been subject to an independent bias audit within the preceding one year.
NJ
Introduced
Employers and employment agencies must not use or continue to use an AEDT unless an independent bias audit of the AEDT has been completed within the preceding one year.
NJ
Introduced
Covered entities must conduct an algorithmic impact assessment at least every two years evaluating whether the automated decision system results in a disparate impact on a protected class, in a form prescribed by the Director of the Division on Civil Rights.
NY
NY AB 3125 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Introduced
Landlords must ensure that an independent auditor conducts a disparate impact analysis of each automated housing decision making tool at least annually. The analysis must assess the tool's actual impact on applicants by sex, race, ethnicity, and other protected classes, and must differentiate between applicants who were selected and applicants who were not selected. The completed analysis must be provided to the landlord.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 505
Introduced
Persons developing and deploying automated systems must conduct pre-deployment and ongoing disparity testing and mitigation under clear organizational oversight.
NY
Introduced
Employers must conduct or commission subsequent impact assessments annually for each year an AEDT remains in use, meeting the same requirements as the initial assessment and additionally describing any change in the tool's validity or disparate impact.
NY
Introduced
Employers must conduct, no less than annually, a disparate impact analysis — conforming to the EEOC Uniform Guidelines on Employee Selection Procedures — assessing the actual impact of any automated employment decision tool used to select candidates for jobs within the state. The analysis must differentiate between selected and non-selected candidates across sex, race, ethnicity, and other protected classes. The full analysis must be provided to the employer but is not publicly filed and is subject to all applicable privileges.
NY
Introduced
Landlords must have an independent auditor conduct an annual disparate impact analysis assessing the actual impact of each automated decision tool used to screen housing applicants, including testing for adverse impact on the basis of sex, race, ethnicity, or other protected class.
NY
Introduced
Banks must annually (1) have an independent auditor conduct a disparate impact analysis assessing each automated decision tool used for lending decisions, differentiating between approved and non-approved applicants across protected classes, and (2) submit a summary of the most recent analysis and the tool's distribution date to the Attorney General's office.
NY
Introduced
Deployers (or their contracted third parties) must review the deployment of each high-risk AI decision system at least annually to ensure the system is not causing algorithmic discrimination. This is a periodic operating review obligation distinct from the impact assessment requirement.
NY
Introduced
Covered entities must conduct an impact assessment of each automated lending decision-making tool at least annually and prior to any material change, signed by an individual responsible for meaningful human review. The assessment must include bias and discrimination testing across enumerated protected characteristics, algorithm and training data descriptions, cybersecurity and privacy risk evaluation, misuse scenario analysis, and sensitive data handling practices. A summary report must be posted on the covered entity's website before initial deployment and updated after each subsequent assessment.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 110
Introduced
Covered deployers must commission an independent third-party audit of each high-risk AI system within six months of deployment, again at one year, and every two years thereafter, evaluating reasonable care against algorithmic discrimination, system accuracy and reliability, and risk-management-program conformity.
NY
Introduced
Real estate brokers and online housing platforms using virtual agents or AI tools must proactively identify discriminatory algorithmic results and modify their virtual agents or AI tools to adopt less discriminatory alternatives. This includes assessing the data used to train such systems and verifying that use of such data does not predict discriminatory outcomes.
NY
Introduced
Real estate brokers and online housing platforms must conduct regular end-to-end testing of their advertising, captioning, and chatbot systems to ensure that discriminatory outcomes are detected. Testing must include comparing the delivery of advertisements across different demographic audiences.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 104
Introduced
Deployers must, on an annual basis after deployment, conduct a preliminary impact assessment to identify any harm that resulted from the covered algorithm during the reporting period. If no harm is identified, the deployer must record a finding of no harm — including a description of intended use, methodology, and explanation — and submit it to the Division. If harm is identified, the deployer must conduct a full impact assessment as described in subdivision 2.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 104
Introduced
Deployers must, when harm is identified during the annual preliminary assessment, engage an independent auditor to conduct a full impact assessment covering: actual harms produced or likely produced; the extent of disparate impact and methodology; data types input during the reporting period (including field descriptions and whether data was used for retraining); whether the algorithm produced expected outputs; how the algorithm was used in consequential actions; mitigation actions taken and staff training; and any additional Division-prescribed information. The auditor must submit findings and recommendations to the deployer. Within 30 days of receiving the auditor's report, the deployer must submit a summary to the developer, subject to trade secret and privacy protections.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 104
Introduced
Developers must annually review each deployer-submitted impact assessment summary to: assess how the deployer is using the algorithm; assess data inputs and outputs; assess deployer contractual compliance and whether remedial action is needed; compare real-world performance against pre-deployment testing; assess whether the algorithm is causing or is reasonably likely to cause harm; assess disparate impact risk and identify affected protected characteristics; determine whether modifications are needed; determine whether other actions are appropriate to ensure the algorithm remains safe and effective; and undertake any additional assessment or action prescribed by the Division.
NY
Introduced
Employers must conduct or commission subsequent annual impact assessments for each year an automated employment decision tool remains in use, assessing and describing any change in the validity or disparate impact of the tool.
NY
Introduced
Employers must conduct or commission subsequent impact assessments annually for each year the AEDT remains in use, meeting all initial assessment requirements and assessing any changes in validity or disparate impact since the prior assessment.
NY
Introduced
Deployers must complete an impact assessment for each high-risk AI decision system before deployment, at least annually thereafter, and within 90 days after any intentional and substantial modification. Each impact assessment must include, to the extent reasonably known: (A) a statement of purpose, intended use cases, deployment context, and benefits; (B) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (C) descriptions of input data categories and system outputs; (D) if applicable, categories of data used for customization; (E) performance metrics and known limitations; (F) transparency measures including consumer notification; and (G) post-deployment monitoring and user safeguards. Impact assessments following intentional and substantial modifications must also disclose whether the system was used consistently with the developer's intended uses. A single assessment may cover comparable systems. An impact assessment completed under another law satisfying substantially similar requirements is deemed compliant. Deployers must retain the most recently completed impact assessment, all records, and all prior assessments for at least three years following final deployment.
NY
Introduced
Deployers must conduct, no later than January 1, 2027, and at least annually thereafter, a review of each deployed high-risk AI decision system to verify that the system is not causing algorithmic discrimination. Reviews may be conducted by the deployer or a contracted third party.
NY
NY SB 6471 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Introduced
Landlords must obtain at least annually a disparate impact analysis conducted by an independent auditor assessing the actual impact of any automated housing decision making tool used to screen applicants for housing, testing for adverse impact across sex, race, ethnicity, and other protected classes.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must review the deployment of each high-risk AI system at least annually to ensure it is not causing algorithmic discrimination.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
At least annually, deployers or third parties contracted by deployers must review the deployment of each high-risk AI system to ensure the system is not causing algorithmic discrimination.
US
Introduced
Deployers must conduct annual post-deployment impact assessments to identify any harm caused by the covered algorithm during the reporting period. If harm is identified, the deployer must engage an independent auditor to conduct a full impact assessment and share a summary with the developer within 30 days.
US
Introduced
Developers must annually review each deployer impact assessment summary to assess deployer usage, data inputs, contractual compliance, real-world performance versus testing, whether harm or disparate impact is occurring, and whether the algorithm needs modification.
US
Introduced
Deployers must conduct annual post-deployment impact assessments to identify any harm from the covered algorithm. If harm occurred, the deployer must engage an independent auditor for a full assessment covering actual harm, disparate impact analysis, data inputs, outputs, mitigation actions, and recommendations. Assessment summaries must be shared with the developer within 30 days.
US
Introduced
Developers must annually review each deployer impact assessment summary to assess deployer usage, data inputs/outputs, contractual compliance, real-world performance versus testing, whether harm or disparate impact is occurring, and whether the algorithm needs modification.
WA
Introduced eff 2026-07-01
Deployers must conduct at least annual reviews — either internally or through a contracted third party — of each deployed high-risk AI system to verify the system is not causing algorithmic discrimination. If a deployer discovers that the system has caused algorithmic discrimination, the deployer must notify the attorney general within 90 days of discovery, in the form and manner prescribed by the attorney general.
WA
Introduced
Deployers must conduct at least annual reviews of each deployed high-risk AI system to verify the system is not causing algorithmic discrimination. If a deployer discovers that a system has caused algorithmic discrimination, the deployer must notify the attorney general within 90 days of discovery, in a form and manner prescribed by the attorney general.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Deployers must perform an annual impact assessment for each automated decision tool, covering purpose, outputs, data types, consistency with the developer's intended-use statement, adverse impacts on the basis of sex, race, or ethnicity, discrimination safeguards, human oversight, and validity evaluation.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.1
Failed
Developers must complete and document an annual assessment for each automated decision tool they design, code, or produce, covering purpose, outputs, data types, adverse impacts on the basis of sex, race, or ethnicity, discrimination mitigation measures, and human oversight capabilities.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within ninety days after any intentional and substantial modification. Post-modification assessments must disclose the extent to which the system's actual use was consistent with or varied from the developer's intended uses.
CO
Failed
Deployers must, on or before October 1, 2026, and at least annually thereafter, review the deployment of each high-risk AI system to ensure it is not causing algorithmic discrimination.
CO
Failed
Deployers must conduct at least annual reviews of each deployed high-risk AI system to verify it is not causing algorithmic discrimination.
CO
Failed eff 2025-05-05
Deployers must complete an impact assessment for each high-risk AI system prior to first deployment (or January 1, 2027, whichever is later) and annually thereafter, covering risks of algorithmic discrimination, accessibility limitations, unfair trade practices, labor law violations, and Colorado Privacy Act violations, along with data categories, sources, outputs, and performance metrics. This obligation applies only to systems that are the principal basis of consequential decisions.
CO
Failed eff 2025-05-05
Deployers must conduct an annual review of each deployed high-risk AI system to verify it is not causing algorithmic discrimination.
CO
Failed
Deployers must review each deployed high-risk AI system at least annually to ensure it is not causing algorithmic discrimination. Initial review required by June 30, 2026.
CT
Failed
Deployers must review the deployment of each high-risk AI system at least annually to verify it is not causing algorithmic discrimination.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information availability determination practices to (1) determine whether practices discriminate in violation of § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a per-determination audit trail recording the determination type, data and sources, algorithm methodology, training data, subgroup performance testing results, methodology, and ultimate decision, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with relevant third parties including service providers, and (6) identify and implement reasonable measures to remediate identified disparate-impact risks, including risks from service-provider determinations.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate under § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a detailed audit trail recording determination type, data, sources, methodology, algorithm, training data, subgroup testing results, and ultimate decision for each determination, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable mitigation measures for disparate-impact risks.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate on the basis of protected characteristics, (2) analyze disparate-impact risks, (3) create and retain for at least five years a detailed audit trail for each determination (recording type, data, sources, methodology, training data, subgroup testing results, algorithm, and decision), (4) conduct annual impact assessments of existing systems and pre-implementation impact assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable measures to mitigate identified disparate-impact risks.
MD
MD HB 1255 (Automated Employment Decision Tools) § Md. Code, Lab. & Empl. § 3-718(B)–(C)
Failed
Employers must not use an automated employment decision tool unless the tool has undergone an impact assessment within the year preceding first use and annually thereafter, and each assessment determines the tool's use would not involve a high-risk action (likely unlawful discrimination or disparate impact).
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must assess at least annually whether each deployed high-risk AI system is causing algorithmic discrimination.
MD
MD SB 957 (Automated Employment Decision Tools) § Md. Code, Lab. & Empl. § 3–718(B)–(C)
Failed
Employers must not use an automated employment decision tool to screen applicants or determine employment terms unless the tool (1) was subject to an impact assessment in the year before first use, (2) undergoes an annual impact assessment each year of use, and (3) each assessment determines the tool would not involve a high-risk action likely to result in unlawful discrimination or disparate impact.
NM
Failed
Deployers must conduct an impact assessment for each deployed high-risk AI system (1) annually and (2) within 90 days of an intentional and substantial modification, covering intended uses, discrimination risks and mitigation, data categories, performance metrics including demographic test data breakdowns, transparency measures, and post-deployment monitoring. A single assessment may cover comparable systems. An exempt small deployer (fewer than 50 employees, no own-data training, intended-use-only deployment, consumer-accessible developer assessment) is excused.
NM
Failed
Deployers must review each deployed high-risk AI system by March 1, 2027 to ensure it is not causing algorithmic discrimination.
NY
Failed
Employers must conduct at least annually a disparate impact analysis — conforming to the EEOC Uniform Guidelines on Employee Selection Procedures — assessing the actual impact of any automated employment decision tool used to select candidates for jobs within the state, differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must conduct at least an annual disparate impact analysis assessing the actual impact of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
NY AB 7906 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must ensure that a qualified independent auditor conducts a disparate impact analysis of any automated decision tool used to screen housing applicants at least annually, assessing actual adverse impact across sex, race, ethnicity, and other protected classes and differentiating between selected and non-selected applicants.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers must conduct both pre-deployment and ongoing disparity testing and mitigation for all automated systems, under clear organizational oversight.
NY
Failed
Employers must conduct or commission annual subsequent bias audits for each year the automated employment decision tool is in use, assessing and describing any change in validity or disparate impact.
NY
Failed
Employers must conduct at least annual disparate impact analyses of each automated employment decision tool used to select candidates for jobs within New York, conforming to the EEOC Uniform Guidelines on Employee Selection Procedures and differentiating between selected and non-selected candidates across sex, race, ethnicity, and other protected classes.
NY
Failed
Employers must conduct or commission subsequent impact assessments annually for each year the AEDT remains in use, complying with all requirements of the initial assessment and additionally assessing any change in the tool's validity or disparate impact.
NY
Failed
Deployers must perform an impact assessment for each automated employment decision tool in use within one year of the effective date and annually thereafter, covering at minimum the tool's purpose, output, data types collected, consistency with the developer's intended-use statement, foreseeable discrimination risks and mitigation safeguards, monitoring practices, and validity evaluation.
NY
Failed
Vendors must produce at least annually a disparate impact report assessing the actual impact of each deployed automated employment decision tool used by employers to select candidates in New York, and must provide the report to the employer. The report is not publicly filed and is subject to applicable privileges.
NY
Failed
Employers must conduct or commission subsequent bias audits annually for each year an automated employment decision tool is in use, complying with all initial-audit requirements and additionally assessing and describing any change in the tool's validity or disparate impact.
NY
NY SB 7735 (Automated Housing Decision Tools) § Real Prop. Law § 227-g(2)
Failed
Landlords must obtain at least annually a disparate impact analysis conducted by an independent auditor assessing the actual impact of the automated decision tool across protected classes (sex, race, ethnicity, and other protected classes), differentiating between selected and non-selected applicants.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 405
Failed
Designers, developers, and deployers must conduct proactive equity assessments during system design, use representative data, implement protections against demographic-proxy variables, ensure accessibility for persons with disabilities, and conduct both pre-deployment and ongoing disparity testing and mitigation under clear organizational oversight.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.006
Failed
Deployers must complete a written impact assessment for each high-risk AI system, annually and within 90 days of any substantial modification, covering purpose, discrimination risk analysis, data categories, performance metrics, transparency measures, post-deployment monitoring, and cybersecurity threat modeling. Following a modification, the deployer must disclose whether the system was used consistently with the developer's intended uses.
US
Failed
Employers must ensure the automated decision system is independently tested at least annually for discriminatory impact and potential biases, with results made publicly available.
US
Failed
Employers must ensure the automated decision system is independently tested at least annually for discriminatory impact and potential biases, and the results of such testing must be made publicly available.
US
Failed
Deployers must conduct annual post-deployment impact assessments of each covered algorithm, beginning with a preliminary assessment; if harm is identified, they must engage an independent auditor to conduct a full impact assessment covering resulting harms, disparate impact, data inputs, output accuracy, and mitigation actions. The independent auditor must submit a report to the deployer, who must forward a summary to the developer within 30 days.
US
Failed
Developers must annually review each deployer's impact assessment summary to assess deployer use, data inputs and outputs, contractual compliance, real-world vs. pre-deployment performance, whether harm or disparate impact is occurring, and whether the algorithm needs modification or other remedial action.
VA
Failed
State agencies must annually test the automated decision system for algorithmic discrimination — either directly or through an appropriate contractor — and certify the system's compliance with federal and state law.
VA
Failed
Local government entities must annually test the automated decision system for algorithmic discrimination — either directly or through a contractor — and certify compliance with federal and state law.
VT
Failed
Deployers must complete an impact assessment for each high-risk AI system (1) before initial deployment, (2) annually within 45 days of each calendar year-end, and (3) within 45 days of each significant update. Each assessment must cover purpose, discrimination risks, mitigation steps, data inputs and outputs, retraining data, performance metrics, transparency measures, and post-deployment monitoring. Assessments and all related records must be maintained for at least three years.
WA
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering the tool's purpose, outputs, data types, consistency with the developer's intended-use statement, foreseeable algorithmic discrimination risks, safeguards aligned with ethical AI principles, human oversight mechanisms, and validation methodology. Deployers with fewer than 50 employees are exempt.
WA
Failed
Developers must complete and document an annual impact assessment for each automated decision tool they design, code, or produce, covering the tool's purpose, outputs, data types, foreseeable algorithmic discrimination risks from intended use or foreseeable misuse, ethical AI safeguards, and intended human oversight mechanisms.
WA
Failed
Agencies must perform ongoing monitoring or auditing of automated decision systems that have legal effects on individuals to ensure they do not produce differential effects on subpopulations over time or discriminate on the basis of factors enumerated in RCW 49.60.010.
WA
Failed
Beginning January 1, 2026, agencies must conduct an annual audit on each automated decision system that has legal effects on people to ensure no differential effects on subpopulations over time, and report findings to the Algorithmic Accountability Review Board covering compliance, violations, systematic bias issues, and recommendations.
H-02.9
Impact Assessment Records Retention
Deployers must retain all impact assessments, associated records, and prior impact assessments for a period of time following the final deployment of each high-risk AI system, and make them available to regulators upon request.
Enacted
3
Live
19
Failed
18
Total
40
CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must cover purpose, algorithmic discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. Deployers must retain all impact assessments and records for at least three years after final deployment, and must conduct at least annual reviews to verify each system is not causing algorithmic discrimination.
CO
Enacted eff 2026-02-01
Deployers must complete an impact assessment for each high-risk AI system before deployment and at least annually thereafter, and within 90 days of any intentional and substantial modification. The assessment must include: (1) a statement of purpose, intended use cases, deployment context, and benefits; (2) an analysis of algorithmic discrimination risks with mitigation steps; (3) categories of input data and outputs; (4) data used to customize the system if applicable; (5) performance metrics and known limitations; (6) transparency measures including consumer disclosure of AI use; and (7) post-deployment monitoring and user safeguards. After a substantial modification, the assessment must also disclose the extent to which actual use was consistent with the developer's intended uses. A single assessment may cover a comparable set of systems. An assessment completed under another applicable law satisfies this requirement if reasonably similar in scope and effect. Deployers must retain the most recent impact assessment, all associated records, and all prior assessments for at least three years following final deployment. In addition, deployers must review deployment of each high-risk AI system at least annually to ensure it is not causing algorithmic discrimination.
VA
Enacted eff 2026-07-01
Deployers must retain all impact assessment records — including raw data used to evaluate performance and limitations — throughout the deployment period and for at least three years following final deployment of each high-risk AI system.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5519
Engrossed eff 2026-07-01
Deployers must complete an impact assessment before initially deploying a high-risk AI system and within 90 days of each significant update, covering purpose, discrimination risks, data categories, customization data, performance metrics, transparency measures, and post-deployment monitoring. Impact assessments and all related records must be retained for five years. A single assessment may cover a comparable set of systems, and assessments completed under other applicable laws may satisfy this requirement if reasonably similar in scope.
CT
Introduced eff 2026-10-01
Deployers must maintain all records relating to bias audits for at least five years and make them available to the Labor Commissioner upon request.
GA
Introduced
Deployers must retain the most recently completed impact assessment, all records concerning each impact assessment, and all prior impact assessments throughout the deployment period and for at least three years following the final deployment of the automated decision system.
IA
Introduced
Deployers must retain the most recently completed impact assessment and supporting records for at least three years following the final use of each high-risk AI system.
IL
Introduced
Health care entities deploying AI in direct patient care must maintain validation and bias monitoring records for each AI system and make those records available to the Department of Financial and Professional Regulation upon request.
IL
Introduced
Health care entities must maintain validation and bias monitoring records for each AI system deployed in direct patient care and make those records available to the Department of Financial and Professional Regulation upon request.
MA
Introduced
Deployers must retain the most recently completed impact assessment, all records concerning each impact assessment, and all prior impact assessments for at least three years following the final deployment of the high-risk AI system.
NJ
Introduced
Employers must, before using an automated employment decision tool, publicly post on the employment section of their website in accessible, machine-readable, and downloadable format (plus hard copy on request): (1) the date and summary results of the most recent bias audit, including the data source, count of individuals in an unknown category, the number of applicants or candidates, selection rates or scoring rates, and impact ratios for all categories; and (2) the tool's date of operation. The summary must remain posted for at least 10 years after the tool's last use, and the employer must issue a press release when the report is made publicly available.
NJ
Introduced
Covered entities must maintain records of all algorithmic impact assessments and make them available for inspection by the Division on Civil Rights or the Attorney General upon request.
NY
Introduced
Deployers (or their contracted third parties) must complete an impact assessment for each high-risk AI decision system before initial deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification. Each impact assessment must include: (1) a statement of the system's purpose, intended use cases, deployment context, and benefits; (2) analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (3) descriptions of data input categories, system outputs, customization data categories, performance metrics and known limitations; (4) a description of transparency measures including consumer disclosure; and (5) a description of post-deployment monitoring and user safeguards. Post-modification assessments must also disclose actual-vs-intended use. A single assessment may cover a comparable set of systems, and an assessment completed under another law is deemed sufficient if reasonably similar in scope and effect. Deployers must retain the most recent assessment, all records, and all prior assessments for at least three years following final deployment.
NY
Introduced
Deployers must complete an impact assessment for each high-risk AI decision system before deployment, at least annually thereafter, and within 90 days after any intentional and substantial modification. Each impact assessment must include, to the extent reasonably known: (A) a statement of purpose, intended use cases, deployment context, and benefits; (B) an analysis of known or reasonably foreseeable algorithmic discrimination risks and mitigation steps; (C) descriptions of input data categories and system outputs; (D) if applicable, categories of data used for customization; (E) performance metrics and known limitations; (F) transparency measures including consumer notification; and (G) post-deployment monitoring and user safeguards. Impact assessments following intentional and substantial modifications must also disclose whether the system was used consistently with the developer's intended uses. A single assessment may cover comparable systems. An impact assessment completed under another law satisfying substantially similar requirements is deemed compliant. Deployers must retain the most recently completed impact assessment, all records, and all prior assessments for at least three years following final deployment.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must retain the most recently completed impact assessment, all associated records, and all prior impact assessments for at least three years following the final deployment of the high-risk AI system.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must retain the most recently completed impact assessment, all records concerning each impact assessment, and all prior impact assessments for at least three years following the final deployment of the high-risk AI system.
US
Introduced
Covered entities must perform impact assessments of each covered algorithm both before and after deployment, and maintain documentation of those assessments for three years beyond the duration of deployment.
US
Introduced
Deployers must conduct annual post-deployment impact assessments to identify any harm from the covered algorithm. If harm occurred, the deployer must engage an independent auditor for a full assessment covering actual harm, disparate impact analysis, data inputs, outputs, mitigation actions, and recommendations. Assessment summaries must be shared with the developer within 30 days.
WA
Introduced eff 2027-01-01
Deployers must retain each impact assessment and all records concerning the impact assessment for three years. Throughout the deployment period and for at least three years following final deployment, deployers must retain all records concerning each impact assessment, including all raw data used to evaluate the system's performance and known limitations.
WA
Introduced eff 2026-07-01
Deployers must retain the most recently completed impact assessment, relevant supporting records, and all prior impact assessments for at least three years following the final deployment of each high-risk AI system.
WA
Introduced eff 2027-01-01
Deployers must maintain each impact assessment and all records concerning it for three years. Throughout the deployment period and for at least three years following final deployment of the high-risk AI system, the deployer must retain all records concerning each impact assessment, including all raw data used to evaluate the system's performance and known limitations.
WA
Introduced
Deployers must retain the most recently completed impact assessment, all relevant supporting records, and all prior impact assessments for at least three years following the final deployment of each high-risk AI system.
CO
Failed
Deployers must complete an impact assessment for each high-risk AI system before deployment, at least annually thereafter, and within 90 days of any intentional and substantial modification, including a statement on whether actual use deviated from the developer's intended uses.
CO
Failed eff 2025-05-05
Deployers must complete an impact assessment for each high-risk AI system prior to first deployment (or January 1, 2027, whichever is later) and annually thereafter, covering risks of algorithmic discrimination, accessibility limitations, unfair trade practices, labor law violations, and Colorado Privacy Act violations, along with data categories, sources, outputs, and performance metrics. This obligation applies only to systems that are the principal basis of consequential decisions.
CT
Failed
Deployers must complete an impact assessment of each high-risk AI system at deployment, at least annually thereafter, and within 90 days of an intentional and substantial modification, covering purpose, discrimination risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. Impact assessments and all associated records must be retained for at least three years after final deployment.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information availability determination practices to (1) determine whether practices discriminate in violation of § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a per-determination audit trail recording the determination type, data and sources, algorithm methodology, training data, subgroup performance testing results, methodology, and ultimate decision, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with relevant third parties including service providers, and (6) identify and implement reasonable measures to remediate identified disparate-impact risks, including risks from service-provider determinations.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate under § -2, (2) analyze disparate-impact risks across all protected characteristics, (3) create and retain for at least five years a detailed audit trail recording determination type, data, sources, methodology, algorithm, training data, subgroup testing results, and ultimate decision for each determination, (4) conduct annual impact assessments of existing systems and pre-implementation assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable mitigation measures for disparate-impact risks.
HI
Failed
Covered entities must annually audit their algorithmic eligibility and information-availability determination practices to (1) determine whether practices discriminate on the basis of protected characteristics, (2) analyze disparate-impact risks, (3) create and retain for at least five years a detailed audit trail for each determination (recording type, data, sources, methodology, training data, subgroup testing results, algorithm, and decision), (4) conduct annual impact assessments of existing systems and pre-implementation impact assessments of new systems, (5) conduct audits in consultation with third parties including service providers, and (6) identify and implement reasonable measures to mitigate identified disparate-impact risks.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5004
Failed
Deployers must complete an impact assessment for any deployed high-risk AI system and retain all impact assessments and related records for at least 3 years after the end of deployment.
NE
Failed
Deployers must complete an impact assessment for each high-risk AI system deployed on or after February 1, 2026, and within 90 days after any intentional and substantial modification. The impact assessment must include, to the extent reasonably known: (1) a statement disclosing the system's purpose, intended use cases, deployment context, and benefits; (2) an analysis of whether deployment poses known risks of algorithmic discrimination and the mitigation steps taken; (3) a high-level summary of input data categories and outputs; (4) if the deployer used data to customize the system, an overview of the customization data categories; (5) any performance evaluation metrics and known limitations; (6) a description of transparency measures including consumer disclosure of AI use; and (7) a description of post-deployment monitoring and user safeguards. Impact assessments following substantial modifications must also disclose whether the system was used consistently with the developer's intended use. A single impact assessment may address a comparable set of systems. Deployers must maintain: the most recent impact assessment for each system, all records concerning the assessment, and for at least three years following final deployment, each prior impact assessment and associated records.
NM
Failed
Deployers must retain impact assessment records — including the most recent assessment, all supporting records, and all prior assessments — for at least three years following final deployment of a high-risk AI system.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must maintain impact assessment documentation for a reasonable time period covering the CAIDS's purpose, consistency with developer's intended uses, discriminatory impact potential across protected characteristics and mitigation steps, data inputs and outputs, retraining data, performance metrics and limitations, transparency measures, and post-deployment monitoring and safeguards.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must maintain design evaluation documentation for a reasonable time period covering the CAIDS's purpose and intended uses, discriminatory impact potential across protected characteristics and mitigation steps, known limitations, training data collection and processing overview, and pre-sale performance metrics.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-4
Failed
Deployers must maintain impact assessment documentation for a reasonable time period covering: system purpose and use cases, consistency with developer's intended uses, potential for discriminatory impact on protected characteristics, data inputs and outputs, retraining data, performance metrics, transparency measures including notice to individuals, and post-deployment monitoring and user safeguards.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-5
Failed
Developers must maintain documentation for a reasonable time period covering the CAIDS's purpose and intended end uses, potential for discriminatory impact on protected characteristics and mitigation steps, known limitations, training data overview and collection methods, and pre-sale performance evaluation metrics.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.006
Failed
Deployers must retain all impact assessments, associated records, and prior assessments for at least three years following final deployment of the high-risk AI system.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-605
Failed
Deployers must complete an impact assessment before initial deployment and within 90 days of each significant update. Each assessment must include, at minimum: (1) purpose, use cases, deployment context, benefits, and any reasonably foreseeable algorithmic discrimination risks with mitigation steps; (2) for post-deployment assessments, whether updated use cases varied from the developer's intended uses; (3) categories of input data and outputs; (4) if applicable, data used to customize the system; (5) transparency measures taken; and (6) post-deployment monitoring and user safeguards. Assessments and all associated records must be maintained for a reasonable period. A cross-compliance safe harbor applies for assessments completed under other applicable laws of reasonably similar scope.
VT
Failed
Deployers must complete an impact assessment for each high-risk AI system (1) before initial deployment, (2) annually within 45 days of each calendar year-end, and (3) within 45 days of each significant update. Each assessment must cover purpose, discrimination risks, mitigation steps, data inputs and outputs, retraining data, performance metrics, transparency measures, and post-deployment monitoring. Assessments and all related records must be maintained for at least three years.
VT
Failed
Developers must complete an impact assessment for each generative AI system before offering it in Vermont. The assessment must evaluate intended purpose, extent of use, prior harms, potential harm intensity and breadth, user dependency, vulnerable-population exposure, and outcome reversibility. Assessments and all related records must be retained for at least three years.
WA
Failed
Deployers must complete and document an annual impact assessment for each automated decision tool they use, covering the tool's purpose, outputs, data types, consistency with the developer's intended-use statement, foreseeable algorithmic discrimination risks, safeguards aligned with ethical AI principles, human oversight mechanisms, and validation methodology. Deployers with fewer than 50 employees are exempt.
H-02.10
Substantive algorithmic discrimination prohibition
Deployers must not use AI or algorithmic decision-making systems in a manner that results in discrimination or disparate impact on the basis of protected characteristics in consequential decision-making contexts.
Enacted
3
Live
8
Failed
4
Total
15
CT
Enacted eff 2026-07-01
Employers may not use automated employment-related decision technology as a defense to employment discrimination complaints. Anti-bias testing evidence may be considered by the commission or court but does not create a safe harbor.
CT
Enacted eff 2026-07-01
Employers may not use automated employment-related decision technology as a defense to sexual orientation or civil union status employment discrimination complaints. Anti-bias testing evidence may be considered but does not create a safe harbor.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 552.056
Enacted eff 2026-01-01
No person may develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. Disparate impact alone is not sufficient to demonstrate intent to discriminate. Insurance entities subject to existing unfair-discrimination statutes are exempt. Federally insured financial institutions are deemed in compliance if they comply with all applicable federal and state banking laws.
MI
Introduced
Employers must not use an automated decisions tool to make employment-related decisions, except to screen large volumes of job applications to identify candidates meeting set hiring criteria or to assess candidates on job skills.
NH
Introduced eff 2027-01-01
Any person or state agency subject to this chapter must not develop or deploy an AI system with the intent to unlawfully discriminate against protected classes under state or federal law; disparate impact alone is insufficient to demonstrate intent.
NJ
Introduced
Employers, public entities, and vendors must not use an AEDS, ABSDS, EMT, or surveillance to obtain, infer, or use protected-class characteristics or union membership/advocacy in employment or public-benefit decisions, except information strictly necessary to confirm identity or determine benefit eligibility.
NY
Introduced
Any act that constitutes an unlawful discriminatory practice under the New York Human Rights Law (Executive Law §§ 296, 296-a, 296-c, 296-d) is equally unlawful when performed through an algorithmic decision system. Entities using algorithmic decision systems must ensure those systems do not engage in conduct that would be discriminatory if performed by a human.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 106
Introduced
Developers and deployers must take reasonable care to prevent the foreseeable risk of algorithmic discrimination arising from the use, sale, or sharing of a high-risk AI system used in consequential decisions.
NY
NY A8884 (New York AI Act) § N.Y. Executive Law § 296(23)
Introduced
Developers and deployers must not engage in the algorithmic-discrimination conduct prohibited by Civil Rights Law § 106, which is also an unlawful discriminatory practice under the New York Human Rights Law.
US
Introduced
Developers and deployers must not offer, license, promote, sell, or use a covered algorithm in a manner that causes or contributes to disparate impact, otherwise discriminates, or makes unavailable the equal enjoyment of goods, services, or opportunities related to a consequential action on the basis of a protected characteristic. Exceptions apply for self-testing to mitigate discrimination, diversity expansion, good-faith security research, non-commercial research, and private clubs.
US
Introduced
Developers and deployers must not offer, license, promote, sell, or use a covered algorithm in a manner that causes or contributes to disparate impact, otherwise discriminates, or makes unavailable the equal enjoyment of goods, services, or opportunities related to a consequential action on the basis of a protected characteristic. Exceptions apply for self-testing to mitigate discrimination, diversity expansion, and noncommercial research.
HI
Failed
Covered entities must not make algorithmic eligibility determinations or algorithmic information availability determinations on the basis of actual or perceived race, color, religion, national origin, sex, gender identity or expression, sexual orientation, familial status, source of income, or disability in a manner that discriminates or makes important life opportunities unavailable. Practices with the effect of violating this prohibition constitute unlawful discriminatory practices (disparate-impact liability).
NY
Failed
Any entity using an algorithmic decision system must ensure that the system does not perform acts constituting unlawful discriminatory practices under New York Executive Law Sections 296, 296-a, 296-c, and 296-d (covering employment, housing, public accommodations, credit, and related domains).
US
Failed
Users of online platforms must not utilize algorithmic processes to withhold, deny, or deprive individuals of rights under Title II of the Civil Rights Act of 1964, or to intimidate, threaten, coerce, or punish individuals for exercising those rights.
US
Failed
Users of online platforms must not utilize algorithmic processes to withhold, deny, or deprive individuals of Civil Rights Act Title II rights, or to intimidate, threaten, or coerce individuals to interfere with such rights, or to punish individuals for exercising such rights.