CA
Enacted eff 2025-01-01
The Department of Technology must develop and adopt regulations creating an ADS procurement standard that includes (1) a detailed risk assessment procedure covering governance, purpose, misuse potential, data legality and provenance, robustness, and explainability; (2) risk control methods; (3) adverse incident monitoring procedures; (4) prohibited use case identification; (5) a detailed equity assessment; (6) a human oversight assessment; and (7) data minimization standards prohibiting vendors from using agency data for proprietary training. The Department must consider specified AI risk management publications, collaborate with stakeholders, consult with the CPPA, and solicit public comment.
CA
Enacted eff 2025-01-01
The Department of Technology must, beginning January 1, 2026, and annually thereafter, review and update both the ADS procurement standard and its implementing regulations.
CA
Enacted eff 2025-01-01
State agencies must not procure an ADS, enter into a contract for an ADS, or contract for any service utilizing an ADS until the Department of Technology has adopted the ADS procurement standard regulations.
CA
Enacted eff 2025-01-01
State agencies must include in every ADS contract clauses that (1) provide a completed risk assessment analyzing governance, purpose, misuse potential, data legality and provenance, robustness, and explainability; (2) require adherence to appropriate procurement standards; (3) provide adverse incident monitoring procedures; (4) require agency authorization before deployment of ADS upgrades and enhancements; and (5) provide a termination right for significant vendor breaches.
CT
Enacted eff 2023-07-01
State contracting agencies must include a provision in every contract entered on or after October 1, 2023 requiring the contracting business to comply with the Connecticut Data Privacy Act (Conn. Gen. Stat. §§ 42-515 to 42-525).
CT
Enacted eff 2026-07-01
State agencies must not use AI in public-assistance delivery or rights-impacting functions unless compliant with OPM/DAS policies, must comply with OPM/DAS policies for AI procurement, and must complete and publicly post an AI impact assessment at least 60 days before deploying any procured AI technology.
IN
Enacted eff 2025-07-01
The Indiana Department of Education must establish guidelines for creating school AI policies and publish a model school AI policy, covering disclosure requirements for students, proper and improper use examples, privacy policies, and recommendations on restricting AI platform use.
MD
Enacted eff 2024-07-01
Beginning July 1, 2025, units of State government may not deploy any new AI system unless it complies with the policies and procedures adopted by the Department under § 3.5–804.
MD
Enacted eff 2024-07-01
Units of State government seeking to test new technology (including AI) through a proof-of-concept pilot must obtain approval from the Secretary of Information Technology, enter into a memorandum of understanding with DoIT, and comply with competitive solicitation requirements. The Department of General Services must adopt policies and procedures for competitive proof of concept procurements.
UT
Enacted eff 2027-01-01
The state chief information officer must establish by rule provenance standards for digital content on public-facing state agency webpages used for transactions or services, requiring provenance records identifying the software or tool used, creation date, content identifier, and prior content identifiers.
CA
Engrossed eff 2026-01-01
State agencies must not award a contract for a high-risk automated decision system to any person who has violated the Unruh Civil Rights Act, the California Fair Employment and Housing Act, or the Automated Decision Systems chapter (Bus. & Prof. Code § 22756 et seq.).
VA
Engrossed eff 2026-07-01
Public bodies must not implement any high-risk AI system unless they have fulfilled all requirements of Chapter 55.6 and complied with the CIO's high-risk AI policies and procedures.
VA
Engrossed eff 2026-07-01
Public bodies must include a CIO-developed high-risk AI system compliance clause in all procurement contracts for high-risk AI systems for which negotiation or renegotiation begins on or after July 1, 2026.
CT
Introduced eff 2025-10-01
State agencies must not procure, purchase, or acquire any high-risk AI system utilizing automated decision systems except where specifically authorized by law.
CT
Introduced eff 2026-10-01
State agencies and entities acting on their behalf must not use AI technology in any function related to public assistance delivery or materially impacting individuals' rights, civil liberties, safety, or welfare unless specifically authorized by law. State agencies must not procure, purchase, or acquire AI technology unless specifically authorized by law.
LA
Introduced
The state and its political subdivisions must not enter into, modify, renew, or extend an AI technology contract unless the contracting entity provides a sworn affidavit attesting it is not owned by, controlled by, or organized under the laws of a foreign country of concern.
MA
Introduced
The Department of State Police may perform facial recognition searches only for four authorized purposes: executing a felony warrant, responding to an emergency involving imminent danger of death or serious physical injury, identifying a deceased person, or acting on behalf of another agency that has obtained a warrant or documented an emergency or deceased-identification basis.
MA
Introduced
The Department of State Police must centralize all facial recognition search functions within a single facial recognition operations group and must use only facial recognition technology from the RMV, the FBI, or technology approved by the Executive Office of Technology Services and Security following a public hearing.
MA
Introduced
The Department of State Police must limit facial recognition searches to the five enumerated purposes: Registrar identity verification, warrant-based felony identification, emergencies involving imminent danger of death or serious physical injury, deceased-person identification, and searches on behalf of other agencies that have obtained a warrant or documented emergency grounds.
MA
Introduced
The Department of State Police must designate a single facial recognition operations group to receive, evaluate, and perform all facial recognition search requests, and must use only facial recognition technology currently used by the Registrar or FBI — or technology approved by the Executive Office of Technology Services and Security following a public hearing.
MA
Introduced
No executive office, department, division, agency, or commission of the commonwealth may procure, purchase, or acquire any service or system utilizing automated decision systems unless the use is specifically authorized by law.
MA
Introduced
No executive office, department, division, agency, or commission of the commonwealth may procure, purchase, or acquire any service or system utilizing or relying on automated decision systems unless the use of such system is specifically authorized by law.
NJ
Introduced
The Office of Information Technology must establish minimum requirements for AI safety tests applicable to all AI technology sold, developed, deployed, used, or offered for sale in New Jersey. The requirements must include at minimum: (1) an analysis of potential cybersecurity threats and vulnerabilities; (2) an analysis of the AI technology's data sources and potential sources of bias, inaccurate information, or violations of state or federal criminal, copyright, patent, or trade secret laws; and (3) descriptions of possible remedies or defensive measures to address identified threats, biases, inaccuracies, or potential legal violations.
NJ
Introduced
The Office of Information Technology must establish minimum requirements for AI safety tests — including cybersecurity threat analysis, data source and bias analysis, and remediation descriptions — and must review each annual safety test report submitted by AI companies.
NY
Introduced
State units must purchase algorithmic decision system products or services only if they adhere to responsible AI standards, including (1) harm avoidance (minimizing risks of physical or mental injury, unjustified information disclosure, and unwarranted damage to property, reputation, or environment), (2) transparency (full disclosure of system capabilities, limitations, and potential problems), (3) fairness (eliminating discrimination, embedding equality and justice as system goals, and providing feedback avenues to redress harms), and (4) comprehensive impact and risk evaluation.
OK
Introduced eff 2026-11-01
State governmental entities must not enter into, extend, or renew AI contracts unless the vendor provides a sworn affidavit attesting it is not owned by, controlled by, or organized under the laws of a foreign adversary.
US
Introduced
NIST must develop standards, guidelines, and minimum requirements for federal agency use, risk management, and procurement of AI systems (excluding national security systems), including standards for authenticating, tracking provenance, and labeling agency-generated synthetic content, and standards for testing, evaluation, verification, and validation of AI acquisitions.
US
Introduced
Each executive agency head must, within 90 days of enactment, review all AI provided by a covered foreign adversary entity on the Section 2(a) list and consider it for exclusion and removal from agency procurement and use.
US
Introduced
Each executive agency head must use at minimum the supply chain risk management authorities in 41 U.S.C. § 4713 to consider exclusion and removal of listed foreign adversary AI.
VA
Introduced
The Department of Criminal Justice Services must establish and publicly post on its website a model policy governing the use of covered AI systems by state and local law-enforcement agencies and sheriff's departments, covering authorized uses, a default prohibition on unauthorized uses, data practices, anti-discrimination protections, criminal-investigation disclosure requirements, and disciplinary consequences for violations.
AK
Failed
State agencies may contract for AI systems used in consequential decisions only if the vendor has implemented multi-factor authentication to secure the system and its stored data.
AK
Failed
State agencies may contract for AI systems used in consequential decisions only if the vendor has implemented security and privacy controls meeting NIST SP 800-53 Rev. 5 or a successor publication designated by department regulation.
FL
Failed eff 2026-07-01
Government entities must not extend, renew, or enter into contracts for AI technology, software, or products with entities owned by, controlled by, or organized under the laws of a foreign country of concern.
FL
Failed eff 2026-07-01
Government entities must not accept bids or enter into AI contracts unless the vendor provides a sworn affidavit attesting that the entity is not owned by, controlled by, or organized under the laws of a foreign country of concern.
FL
Failed eff 2026-07-01
Governmental entities must, beginning July 1, 2026, obtain a sworn affidavit from any vendor providing AI technology, software, or products (or any vendor whose contract includes AI as an optional component) attesting that the vendor is not owned by, controlled by, or organized in a foreign country of concern, before accepting a bid or entering into a contract.
FL
Failed eff 2026-07-01
Governmental entities must not knowingly enter into a contract with any entity for AI technology, software, or products if the entity is owned by, controlled by, or organized in a foreign country of concern.
FL
Failed
Government entities must not enter into, extend, or renew contracts for AI technology, software, or products with entities that are owned by, have a controlling interest held by, or are organized under the laws of or have their principal place of business in a foreign country of concern.
FL
Failed
Government entities must require AI technology vendors to provide a sworn affidavit, signed under penalty of perjury, attesting that the vendor is not owned by, controlled by, or organized under the laws of a foreign country of concern before accepting bids, proposals, or entering contracts for AI technology, software, or products.
FL
Failed
The Department of Management Services must, by January 1, 2025 and in consultation with the Advisory Council, prescribe by rule the form, contents, and manner of submission of the automated decision systems inventory report.
GA
Failed
Law enforcement agencies must use only facial recognition software formally approved in writing by the agency. Use of software obtained through pilot programs, demonstration programs, personal accounts, or trial periods in any investigation is prohibited.
GA
Failed
The Commission must develop and propose recommendations for minimum technology standards, data governance policies, individual appeal and human review procedures, bias prevention, pre-deployment risk evaluation, data provenance, cybersecurity, prohibitions on secret profiling and unitary scoring, public transparency, and the creation of a permanent oversight body for government automated decision systems.
HI
Failed
The Office of Enterprise Technology Services must develop, maintain, and periodically update procurement guidelines for state AI technology — building on the NIST AI RMF and the White House Blueprint for an AI Bill of Rights — addressing safety, algorithmic discrimination, data privacy, high-risk uses, and AI-generated content disclosure, in consultation with employee organizations, trust and safety experts, and academic researchers.
HI
Failed
Before adopting any automated decision system, a state agency must ensure the system has received appropriate consultation, testing, risk identification, and risk mitigation consistent with this chapter, and must obtain approval from the Chief Information Officer.
MA
Failed
The Department of State Police may perform facial recognition searches only for four enumerated purposes: executing a felony warrant, responding to an emergency involving immediate danger of death or serious injury, identifying a deceased person, or on behalf of another agency with appropriate warrant or documented emergency/deceased-person justification.
MA
Failed
The Department of State Police must centralize all facial recognition search operations in a single designated operations group and must use only facial recognition technology currently used by the RMV or FBI, or technology approved by the Executive Office of Technology Services and Security following a public hearing.
MA
Failed
The Department of State Police must designate a single facial recognition operations group to receive, evaluate, and execute all law enforcement facial recognition search requests, and must use only RMV, FBI, or Executive Office of Technology Services and Security-approved facial recognition technology, with new software requiring a public hearing before approval.
MD
Failed
Beginning July 1, 2025, units of State government must not deploy any new AI system unless it complies with the Department's AI policies and procedures.
MD
Failed
The State Police, in consultation with other relevant state agencies, must adopt and publish a model statewide policy regarding the use of facial recognition technology.
MD
Failed
Law enforcement agencies must not use or contract for facial recognition technology unless the use conforms to the model statewide policy adopted and published by the State Police.
MD
Failed
The Department of Public Safety and Correctional Services must (1) adopt and publish a model statewide policy for facial recognition use, (2) develop and administer training and proficiency testing including cultural diversity and implicit bias components, (3) review and approve a single facial recognition technology for statewide law enforcement use, and (4) publish on its public website the name, version, and vendor of the currently and previously approved technologies.
MD
Failed
Law enforcement agencies must not use or contract for facial recognition technology unless the use conforms to the model statewide policy and the technology is currently approved by the Department of Public Safety and Correctional Services.
MN
Failed eff 2023-01-01
The Commissioner of Public Safety must use facial recognition technology on every driver's license and Minnesota identification card application and renewal to prevent duplicate issuance, identification fraud, and to expedite processing.
MN
Failed eff 2023-01-01
The Commissioner must incorporate facial recognition software that uses mathematical algorithms to compare applicant facial features against photographs and data in the Department of Public Safety's records, relevant FBI records, and any other relevant law enforcement or criminal history databases.
MT
Failed
Law enforcement agencies must limit facial recognition technology use to investigating serious crimes (with probable cause), locating missing/endangered persons, or identifying deceased persons; must obtain a warrant or court order before performing a search (with a 24-hour emergency exception); must not use sketches or manually produced images as inputs; and must not substantively manipulate images inconsistent with the provider's intended use.
NC
Failed
Prime contractors must certify at contract execution and each annual renewal whether an AEDT was or will be used to select contract employees, provide the bias audit summary to the contracting agency before such use, and acknowledge that material noncompliance constitutes a breach of contract entitling the State to withhold payment or terminate for cause.
NC
Failed
The State Treasurer and the Executive Administrator of the State Health Plan must review all State Health Plan practices and all third-party utilization review contracts to ensure compliance with the AI utilization review prohibition in G.S. 58-50-61(s).
NM
Failed
Procurement contracts for AI products or services subject to the Act must include a vendor transparency requirement obligating the vendor to disclose the system's methodology, data types and sources, data collection and weighting methods, and error-correction processes.
NY
Failed
State units must purchase algorithmic decision systems only if the product or service adheres to responsible AI standards covering (1) harm avoidance (minimizing risks of physical/mental injury, unjustified data disclosure, and property/reputation/environmental damage), (2) transparency (full disclosure of system capabilities, limitations, and potential problems), (3) fairness (eliminating discrimination, providing feedback avenues for redress), and (4) comprehensive impact and risk evaluation.
US
Failed
Federal law enforcement agencies and crime laboratories serving them must use only computational forensic software tested under NIST's Computational Forensic Algorithm Testing Program, must conduct and publicly publish an internal validation under the Computational Forensic Algorithm Testing Standards, and must update the validation upon any material software change.
US
Failed
The Administrator of Federal Procurement Policy must provide draft contract language for agency procurement that requires AI suppliers to adhere to framework-consistent actions and to provide access to data, models, and parameters sufficient for testing, evaluation, verification, and validation.
US
Failed
The Federal Acquisition Regulatory Council must promulgate regulations establishing requirements for AI acquisitions with risk-based framework compliance, and solicitation provisions and contract clauses referencing those requirements, within one year after OMB issues guidance under subsection (b)(1).
US
Failed
Federal law enforcement agencies and crime laboratories providing services to federal law enforcement must (1) use only computational forensic software tested under the NIST Computational Forensic Algorithm Testing Program, (2) conduct an internal validation per the Computational Forensic Algorithm Testing Standards and make results publicly available, and (3) update the internal validation whenever a material software change triggers retesting.
US
Failed
Each agency head must ensure that procurement contracts for federal AI systems are consistent with the subchapter's requirements and OMB guidance.
US
Failed
The FAR must be revised within six months of OMB guidance issuance to require contractors and subcontractors building, providing, operating, or maintaining federal AI systems to supply the information agencies need for AI governance charters and compliance reporting.
US
Failed
Covered agencies (DoD, intelligence community, FBI) must establish criteria for when AI systems warrant accredited privacy, civil rights, and civil liberties testing, adopt those criteria, and submit each qualifying AI system to a NIST-accredited organization for evaluation before procuring, fielding, or using the system.
US
Failed
The Director of OMB must, within one year of enactment and in consultation with the AI Hygiene Working Group, implement procurement-contract requirements ensuring that AI acquisitions align with OMB AI guidance, address privacy, civil rights, civil liberties, data ownership and security, and include requirements for securing training data, algorithms, and AI system components against misuse, unauthorized alteration, degradation, or inoperability. These requirements must be updated at least every two years.
WA
Failed
The Washington State CIO must adopt rules by January 1, 2022 governing the development, procurement, and use of automated decision systems by public agencies, incorporating the minimum standards set forth in Sections 4 and 5, after consulting with representatives of disproportionately impacted communities.
WA
Failed
Public agencies must ensure that procurement contracts for automated decision systems preserve all minimum standards in this section without impairment, require the vendor to waive any legal claims that would impair these standards, and must not contain nondisclosure or other provisions that prohibit or impair the minimum standards.
WA
Failed
The Office of the State CIO must, in consultation with the Office of Equity and impacted community representatives, adopt guidance for agencies on the development, procurement, and use of automated decision systems, incorporating the minimum standards set forth in the act.
WA
Failed
Agencies must ensure that for newly acquired systems (and to the maximum extent practicable for existing ones), the system and its training data are made freely available by the vendor before, during, and after deployment for agency or independent third-party testing, auditing, or research, subject to trade-secret protections that limit disclosure to outcomes only.
WA
Failed
Procurement contracts for automated decision systems entered into after the effective date must ensure the minimum standards can be effectuated without impairment, require the vendor to waive legal claims that would impair those standards, and may not contain nondisclosure or other provisions that would prohibit or impair the minimum standards.