PS-01
Public Sector AI
Government AI Accountability
Government agencies that develop, procure, or deploy AI systems must maintain inventories of those systems, conduct impact assessments before deploying AI in consequential public-facing roles, meet defined procurement standards, and disclose AI use to affected individuals. Vendors selling AI to government agencies must be able to demonstrate standards compliance.
Sub-obligations4
Bills84
Jurisdictions28
Enacted10
Show
Sort bills within section

4 sub-obligations of PS-01

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
PS-01.1 AI system inventory and registry
Government agencies must maintain and annually publish an inventory or registry of AI systems in use, including each system's name, vendor, capability description, purpose, decision-making role, the categories of decisions it informs, the populations affected, and whether a pre-implementation impact assessment was performed. Inventory must be published in an open, machine-readable data format on a publicly accessible government website.
13Enacted 15Live 29Failed 57Total Jump →
PS-01.2 Algorithmic impact assessment before deployment
Before deploying an AI system in a consequential public-facing role, the agency must conduct and publish a formal impact assessment covering system purpose, affected populations, discriminatory impact analysis, mitigation measures, and oversight mechanisms.
5Enacted 6Live 15Failed 26Total Jump →
PS-01.3 Public disclosure of registry and assessments
Registry entries and impact assessments must be publicly accessible, enabling citizens, journalists, and researchers to understand what AI systems government agencies use and for what purposes.
5Enacted 15Live 18Failed 38Total Jump →
PS-01.4 Procurement standards compliance
AI systems intended for government procurement must meet defined performance, safety, transparency, and documentation standards. Vendors must be able to produce documentation demonstrating compliance as part of the procurement process.
10Enacted 20Live 41Failed 71Total Jump →
Bills That Map This Requirement 216 mappings
PS-01.1
AI system inventory and registry
Government agencies must maintain and annually publish an inventory or registry of AI systems in use, including each system's name, vendor, capability description, purpose, decision-making role, the categories of decisions it informs, the populations affected, and whether a pre-implementation impact assessment was performed. Inventory must be published in an open, machine-readable data format on a publicly accessible government website.
Enacted
13
Live
15
Failed
29
Total
57
CA
CA AB 302 (Government AI Inventory) § Gov. Code § 11546.45.5(b)
Enacted eff 2024-01-01
The Department of Technology must conduct a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency, on or before September 1, 2024.
CA
CA AB 302 (Government AI Inventory) § Gov. Code § 11546.45.5(c)
Enacted eff 2024-01-01
The Department of Technology must include in the comprehensive inventory a description of each system's decision-making capabilities and intended benefits, alternatives considered, efficacy research results, categories of data and personal information used, and risk mitigation measures in place (including accuracy metrics, cybersecurity and privacy controls, risk assessments, and contestation processes).
CT
Enacted eff 2023-07-01
The Department of Administrative Services must conduct an annual inventory of all AI systems in use by state agencies — including system name, vendor, capabilities, decision-making role, and impact assessment status — and publish the inventory on the state's open data portal.
CT
Enacted eff 2023-07-01
The Judicial Department must conduct an annual inventory of its AI systems — including system name, vendor, capabilities, decision-making role, and impact assessment status — and publish the inventory on the department's website.
CT
Enacted eff 2026-07-01
The Department of Administrative Services must annually inventory all AI systems in use by state agencies — including system name, vendor, capabilities, decision-making role, impact assessment status, PII access, and known risks — and publish the inventory on the state's open data portal.
IN
Enacted eff 2025-07-01
The Indiana Department of Education must establish and annually update a publicly titled inventory of at least twenty AI platforms, classifying each as supported or discouraged for school use, and must create a submission process allowing teachers and school administrators to nominate AI platforms for inclusion.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-508
Enacted eff 2024-10-01
Law enforcement agencies contracting for a non-government FRT system must disclose on their public website the name of the system and the names and descriptions of the databases searched.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Enacted eff 2024-07-01
Each unit of State government must conduct a regular inventory of systems employing high-risk AI — including system name, vendor, capabilities, purpose, pre-deployment impact assessment status, decision-making role, and most recent impact assessment summary — and submit it to the Department in the prescribed format, beginning December 1, 2025.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Enacted eff 2024-07-01
The Department must publish an aggregated statewide AI inventory on its website, withholding only information whose publication would compromise system security or integrity, and must provide withheld information to the Governor, General Assembly members, and law enforcement upon request.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–303(a)(12)
Enacted eff 2024-07-01
The Secretary of Information Technology must conduct inventories and ongoing assessments of AI systems used by units of State government as required under § 3.5–803.
TX
TX HB 149 (Responsible AI Governance) § Gov't Code § 325.011
Enacted eff 2026-01-01
The Sunset Advisory Commission must, as part of its review criteria for each state agency, assess the agency's use of AI systems in its operations, its oversight of AI use by persons under its jurisdiction, and any related impact on the agency's ability to achieve its mission, goals, and objectives.
TX
TX HB 149 (Responsible AI Governance) § Gov't Code § 2054.068
Enacted eff 2026-01-01
State agencies must provide to the Department of Information Resources an evaluation of the agency's use or considered use of artificial intelligence systems, as part of the department's information technology infrastructure data collection.
TX
TX HB 149 (Responsible AI Governance) § Gov't Code § 2054.0965
Enacted eff 2026-01-01
State agencies must include an inventory of their artificial intelligence systems as part of their periodic information resources reviews submitted to the Department of Information Resources.
CA
CA AB 1405 (AI Auditor Enrollment) § Gov. Code § 11549.82
Engrossed
The Government Operations Agency must, by January 1, 2027, establish on its website (1) a mechanism for AI auditors to enroll, (2) enrollment fees not exceeding reasonable administrative costs, and (3) a mechanism for natural persons to report misconduct by enrolled AI auditors.
CA
CA AB 1405 (AI Auditor Enrollment) § Gov. Code § 11549.82
Engrossed
The Government Operations Agency must, beginning January 1, 2027, (1) publish all enrolled AI auditor information in a publicly accessible format on its website, (2) retain misconduct reports for as long as the auditor remains enrolled plus 10 years, and (3) share misconduct reports with other state agencies as necessary for enforcement purposes.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5522
Engrossed eff 2026-07-01
Public bodies must annually report on initial and ongoing high-risk AI system assessments and provide an inventory of all such systems to the General Assembly (legislative branch), the Executive Secretary of the Supreme Court (judicial branch), or the CIO (executive branch and others).
CT
CT SB 1249 (AI Innovations) § Conn. Gen. Stat. § 4-67p (as amended by Sec. 1)
Introduced eff 2025-07-01
The Chief Data Officer and agency data officers must, by January 1, 2026, review state agency data inventories to identify and publish data useful for AI and machine learning, develop data quality and anti-discrimination governance policies for such data, apply necessary privacy protections, and establish publication procedures through the state open data repository.
MO
Introduced
The state board of education must create and maintain a statewide master list of all software used by students in Missouri public schools as a public transparency tool. Software may only be listed after the contracting entity has executed the statewide digital privacy agreement and obtained academic-effectiveness verification, and these requirements must be met before student use.
MO
Introduced
Contracting entities must execute the statewide digital privacy agreement, obtain academic-effectiveness verification, and submit all documentation to the state board of education for listing for each software product adopted. Local educational agencies must also maintain their local software inventory. The state board must publish and update the statewide master list on an ongoing basis and conduct compliance audits.
NY
Introduced
State agencies must publish on their website a list of all automated employment decision-making tools they use, including a description of each tool, the date use began, and a summary of purpose and use, initially by December 30 following the effective date and annually thereafter.
NY
Introduced
The Office of Information Technology Services must maintain and annually publish on the New York State Open Data website a statewide inventory of all state agency artificial intelligence systems, including the purpose and uses of each system. State agencies must submit required inventory data to the office at least 60 days before each annual publication date.
NY
Introduced
The Commissioner of Labor must maintain a database of AI/automation-related WARN reports and must prepare and publish quarterly summaries analyzing the number, sector, and location of workforce reductions identified as resulting from AI or automation. Reports must be made publicly available on the Department of Labor's website and shared with the Department of Economic Development for use in workforce innovation planning and retraining programs.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(I)
Introduced eff 2026-11-01
The State Department of Education must create and maintain a publicly accessible Data Transparency Portal that (1) lists all data elements collected, (2) identifies which elements are mandatory versus optional, (3) publishes copies of all active vendor contracts and data-sharing agreements, (4) reports all data breaches or unauthorized disclosures within thirty days, and (5) posts annual privacy and security compliance audits.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(F)
Introduced
School entities must maintain publicly accessible information identifying all approved AI tools and their intended uses.
US
Introduced
The Federal Acquisition Security Council must develop a list of all artificial intelligence produced or developed by a foreign adversary within 60 days of enactment.
US
Introduced
The Federal Acquisition Security Council must update the foreign adversary AI list at least every 180 days.
VA
VA HB 1295 (Law Enforcement AI Inventory) § Va. Code § 9.1-116.11(B)
Introduced
Law-enforcement agencies must conduct an annual inventory of all covered AI systems used by the agency and make the inventory publicly available by November 1 of each year, including each system's name and vendor, capabilities and limitations, data inputs and outputs, and authorized and unauthorized uses.
VT
Introduced eff 2026-07-01
State agencies must publish and maintain on their website a list of all automated employment decision-making tools they use, including a description of each tool, the date the agency began using it, a summary of its purpose and use, and any other relevant information.
AK
Failed
The Department of Administration must conduct a biennial inventory of all AI systems used by state agencies for consequential decisions — including each system's name, vendor, capabilities, and pre-implementation impact assessment status — and publish the completed inventory on the department's website.
AK
Failed
The Department of Administration must conduct a biennial inventory of all state agency systems that employ generative AI for consequential decisions — including each system's name, vendor, capabilities, and impact assessment status — and publish the inventory on the department's website.
CT
Failed
The Commissioner of Administrative Services must annually inventory all AI systems used by state agencies (including vendor, capabilities, decision-making role, and impact-assessment status), publish the inventory on the state open data portal, perform ongoing discrimination assessments, and beginning July 1, 2026, provide annual employee trainings on generative AI use and bias mitigation.
FL
Failed
Each state agency must prepare and submit by July 1, 2025 an inventory report of all automated decision systems being developed, used, or procured, covering system name and vendor, general capabilities, foreseeable out-of-scope capabilities, independent decision-making capacity, data inputs and outputs, bias testing status, purpose and use classification, data security practices, and fiscal impacts. Reports must be submitted to the Department of Management Services, the Advisory Council, and applicable legislative standing committees.
GA
Failed
The Commission must conduct a comprehensive survey of all automated decision systems used by Georgia state agencies and subdivisions, covering developer identity, contract terms, inputs, purposes, validation policies, data maintenance and deletion policies, and potential harms — and must publicly disclose the systems surveyed and their developers.
HI
Failed
Each state agency, department, and branch of government must prepare, maintain, and make accessible to the Office of Enterprise Technology Services an inventory of all current high-risk uses of generative AI within the entity.
MA
Failed
The commission must conduct a comprehensive ongoing survey and study of all automated decision systems used by Massachusetts state agencies, covering system inventories, procurement policies, training practices, validation and testing methods, transparency and auditability, external review access, due process rights, disparate-impact outcomes, mitigation controls, data governance, and intellectual property barriers.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(h)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year the total number of law enforcement facial recognition searches, disaggregated by requesting agency, by warrant vs. emergency, by alleged offense, and by race and gender of search subjects.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(j)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year the total number of facial recognition searches performed by or at the request of non-law enforcement public agencies, disaggregated by agency and including the race and gender of search subjects.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(h)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year aggregate data on all law enforcement facial recognition searches from the prior calendar year, disaggregated by requesting agency, including warrant vs. emergency counts by offense and the race and gender of search subjects.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(j)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year data on all facial recognition searches performed by or at the request of non-law-enforcement public agencies for the prior calendar year, disaggregated by agency and including the race and gender of search subjects.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Failed
Each unit of State government must conduct a regular inventory of high-risk AI systems beginning December 1, 2025, including the system name, vendor, capabilities, purpose, impact assessment status, decision-making role, and most recent impact assessment summary, and provide the inventory to the Department.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Failed
The Department must publish an aggregated statewide AI inventory on its website. Information that could compromise the security or integrity of a State system may be withheld from public disclosure but must be provided on request to the Governor, General Assembly members, and law enforcement.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-508
Failed
Law enforcement agencies contracting for non-government facial recognition systems must disclose on their public website the name of the system and the names and description of the databases searched.
NC
Failed
The Department must (1) maintain and make publicly available documents describing the AI systems used and their functions in the environmental permitting process, and (2) inform each permit applicant when AI was used to assist in reviewing their application or drafting their permit.
NM
Failed
Each agency must annually submit to the General Services Department an inventory of its AI systems, including each system's name, vendor, general capabilities and uses, whether the system was used for consequential decisions, and the data sources used for assessment.
NM
Failed
The General Services Department must annually compile and provide an aggregate inventory report of all agency AI systems — including assessment results — to the governor, the legislative finance committee, and the appropriate legislative interim committee.
PA
PA HB 49 (AI Registry) § Section 817
Failed
The Department of State must establish and maintain a searchable online registry of businesses operating AI systems in Pennsylvania, coordinate with other state agencies to populate the registry, and create paper and online registration forms collecting business name, IP address, AI code type, software intent, and contact information.
TX
TX HB 1709 (AI Governance) § Gov't Code § 325.011 (as amended)
Failed
The Sunset Advisory Commission must assess each state agency's use of AI systems (including high-risk AI) in operations and oversight, and the impact on the agency's mission, using information from DIR, the AG, or other appropriate agencies.
TX
TX HB 1709 (AI Governance) § Gov't Code § 2054.068(b) (as amended)
Failed
The Department of Information Resources must collect from each state agency an evaluation of its use or considered use of AI systems and high-risk AI systems.
TX
TX HB 1709 (AI Governance) § Gov't Code § 2054.0965(b) (as amended)
Failed
State agencies must include an inventory of their AI systems in the DIR information resources deployment review.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must maintain a publicly available AI governance plan on a centralized agency webpage that describes agency AI policies and procedures, including the AI use case inventory required by the Advancing American AI Act.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3596
Failed
GSA must maintain a single, publicly accessible, machine-readable online Federal AI System Inventory cataloging all agency AI governance charters, and must provide agencies a clear process for timely revisions and updates.
US
US S 3554 (Financial AI Risk Reduction) § Sec. 3 / proposed 12 U.S.C. § 126(a)
Failed
FSOC must direct the Office of Financial Research to conduct research into AI use by financial institutions and their service providers, and must identify threats to financial system stability posed by AI tools and technologies, including deepfake-based market manipulation.
US
Failed
The Secretary of Defense must create and maintain a structured, indexed ledger of all Department of Defense uses of AI-enabled weapon systems, targeting systems, and decision support systems, commencing within one year of enactment and completing within three years.
UT
UT SB 205 (Law Enforcement AI) § Utah Code § 53-25-902
Failed eff 2026-05-06
Law enforcement agencies must publicly disclose each AI technology the agency uses (excluding purely administrative tools), the technology's available transparency, content safeguard, and human oversight settings, whether each setting is required, unused, or employee-disableable, and any other relevant AI technology policies.
WA
Failed
Each algorithmic accountability review office must maintain and publish quarterly on its website a public inventory of all algorithmic accountability reports for automated decision systems proposed, in use, or under development by public agencies. Beginning January 1, 2022, the office must also publish metrics on all approval, conditional approval, or denial decisions with written explanations.
WA
Failed
Agencies already using automated decision systems must provide a list of those systems to the Algorithmic Accountability Review Board by January 1, 2024, complete an algorithmic accountability report on each system by January 1, 2026, and cease use of any unevaluated system if the deadline passes without a board-granted extension. High-risk systems require independent third-party evaluation of accuracy and bias.
WA
Failed
The Office must maintain and publish on its website a public inventory of all algorithmic accountability reports on automated decision systems (updated quarterly beginning December 1, 2023) and, beginning January 1, 2024, publish metrics on all approvals, conditional approvals, or denials of agency reports, including written explanations.
PS-01.2
Algorithmic impact assessment before deployment
Before deploying an AI system in a consequential public-facing role, the agency must conduct and publish a formal impact assessment covering system purpose, affected populations, discriminatory impact analysis, mitigation measures, and oversight mechanisms.
Enacted
5
Live
6
Failed
15
Total
26
CT
Enacted eff 2023-07-01
State agencies must not implement any AI system unless the agency has first performed an impact assessment under OPM's policies to ensure the system will not result in unlawful discrimination or disparate impact, and must not implement the system if the agency head determines it will cause such discrimination.
CT
Enacted eff 2023-07-01
The Judicial Department must not implement any AI system unless it has first performed an impact assessment ensuring the system will not cause unlawful discrimination or disparate impact, and must not implement the system if the Chief Court Administrator determines it will cause such harm. The department must also perform ongoing assessments of deployed AI systems.
CT
Enacted eff 2026-07-01
State agencies must not use AI in public-assistance delivery or rights-impacting functions unless compliant with OPM/DAS policies, must comply with OPM/DAS policies for AI procurement, and must complete and publicly post an AI impact assessment at least 60 days before deploying any procured AI technology.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Enacted eff 2024-07-01
Each unit of State government must conduct an impact assessment of high-risk AI systems — by December 31, 2026 for systems procured on or after February 1, 2026, and by July 1, 2027 for systems procured before that date.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–805
Enacted eff 2024-07-01
Units of State government that employ high-risk AI must conduct regular impact assessments at a cadence determined by the Governor's AI Subcabinet.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5522
Engrossed eff 2026-07-01
Public bodies must complete an impact assessment under § 2.2-5519 before implementing any high-risk AI system, perform ongoing post-implementation assessments, and cease using any system determined to be non-compliant.
CT
Introduced eff 2025-10-01
State agencies authorized to procure a high-risk AI system must contract with an impartial third party for an impact assessment (per Sec. 3(b) requirements), submit the assessment to the Commissioner of Administrative Services, and post it on the agency's website at least 60 days before deployment. Personally identifiable information may be redacted.
CT
Introduced eff 2026-10-01
State agencies authorized to procure AI technology must contract with an independent auditor for a bias audit under Section 8. The completed bias audit must be submitted to the Commissioner of Administrative Services and posted on the agency's website at least 60 days before deployment. The agency may redact personally identifiable information.
MA
Introduced
State agencies must conduct an impact assessment before deploying any automated decision system and at least every two years thereafter, and before any material change. The assessment must describe the system's objective, evaluate its ability to achieve objectives, summarize underlying algorithms and training data, test for accuracy, bias, discrimination across protected classes, cybersecurity and privacy risks, public health and safety risks, foreseeable misuse, sensitive data handling, and individual notification mechanisms.
MA
Introduced
State agencies must conduct an impact assessment before using any automated decision system, with reassessments at least every two years and before any material change. The assessment must include: (1) description of objectives; (2) evaluation of ability to achieve objectives; (3) description of underlying algorithms, computational modes, AI tools, design, and training data; (4) testing for accuracy, fairness, bias, and discrimination across protected characteristics with mitigation plans; (5) cybersecurity and privacy risk assessment with safeguards; (6) public health and safety risk assessment; (7) foreseeable misuse assessment with safeguards; (8) assessment of sensitive/personal data requirements, use, storage, and user controls; and (9) notification mechanisms for impacted individuals.
NJ
Introduced
Boards of education and boards of trustees that use surveillance systems with AI capabilities must adopt a policy that (1) describes the surveillance system, (2) identifies the types of information collected, (3) explains how the information will be used, (4) addresses data access in compliance with student-records law, and (5) requires posting of signage in prominent locations indicating AI-equipped surveillance is in use. Video surveillance policies must also comply with P.L.2017, c.119.
AK
Failed
State agency heads must conduct at least biennial impact assessments of each AI system used for consequential decisions, covering efficacy, human oversight, accountability, appeal processes, risks (including cybersecurity and IP), effects on individual liberty and privacy, discrimination or disparate impact, and governing policies. Completed assessments must be submitted to the Department of Administration for publication on its website.
AK
Failed
State agency heads must conduct a biennial impact assessment of each generative AI system used for consequential decisions, covering efficacy, human oversight, accountability, appeals, risks, privacy effects, discrimination analysis, and governing procedures, and must submit the completed assessment to the Department of Administration.
CT
Failed
The Commissioner of Administrative Services must annually inventory all AI systems used by state agencies (including vendor, capabilities, decision-making role, and impact-assessment status), publish the inventory on the state open data portal, perform ongoing discrimination assessments, and beginning July 1, 2026, provide annual employee trainings on generative AI use and bias mitigation.
HI
Failed
The Chief Information Officer, Chief Data Officer, and cybersecurity coordinator must jointly assess the risks that the State's use of generative AI poses to critical infrastructure — including mass casualty and environmental emergency risks — and submit the assessment to the legislature no later than twenty days before the 2025 regular session, with periodic updates thereafter.
HI
Failed
Before adopting any automated decision system, a state agency must ensure the system has received appropriate consultation, testing, risk identification, and risk mitigation consistent with this chapter, and must obtain approval from the Chief Information Officer.
HI
Failed
The cybersecurity coordinator must carry out joint risk assessments of the State's uses of generative AI that potentially affect critical infrastructure, pursuant to the new chapter's requirements.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Failed
Each unit of State government must conduct an impact assessment of high-risk AI systems procured on or after February 1, 2026, by December 31, 2026, and of high-risk AI systems procured before that date by July 1, 2027.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–805
Failed
Units of State government employing high-risk AI must conduct regular impact assessments on a schedule determined by the Governor's AI Subcabinet.
NM
Failed
The General Services Department must conduct a structured assessment of each agency AI system — evaluating output methodology, data sources, accuracy, and bias — by July 1, 2025, and reassess all systems and assess new systems annually thereafter.
OK
Failed
Law enforcement agencies must, before using an ALPR system, adopt and make publicly available a written use policy that includes at minimum: supervisory oversight, user training protocol, hot list maintenance protocol, data access and security rules, data retention and destruction rules, and an audit schedule.
US
Failed
Covered agencies (DoD, intelligence community, FBI) must establish criteria for when AI systems warrant accredited privacy, civil rights, and civil liberties testing, adopt those criteria, and submit each qualifying AI system to a NIST-accredited organization for evaluation before procuring, fielding, or using the system.
WA
Failed
Public agencies must complete an algorithmic accountability report before developing, procuring, or using any automated decision system. Agencies with systems already in use at the effective date have until January 1, 2023 to complete the report and comply with Section 4(4) operational requirements.
WA
Failed
Agencies must assess new automated decision systems during procurement and assess existing systems currently in use for risks to rights and freedoms, bias or inaccuracy in results, and transparency to the public.
WA
Failed
Agencies intending to newly develop or procure an automated decision system for use before January 1, 2026 must produce and file with the Office an algorithmic accountability report at least one month before procurement or implementation, including independent third-party accuracy and bias evaluation for high-risk systems.
WA
Failed
Agencies intending to develop or procure an automated decision system for implementation after January 1, 2026 must submit an algorithmic accountability report and obtain an affirmative finding from the Algorithmic Accountability Review Board before deploying the system. The report must be posted for at least 30 days of public comment, and high-risk systems require independent third-party bias evaluation. A board finding of failure must include a reasoned explanation, and the agency may revise and resubmit.
PS-01.3
Public disclosure of registry and assessments
Registry entries and impact assessments must be publicly accessible, enabling citizens, journalists, and researchers to understand what AI systems government agencies use and for what purposes.
Enacted
5
Live
15
Failed
18
Total
38
CT
Enacted eff 2023-07-01
The Department of Administrative Services must conduct an annual inventory of all AI systems in use by state agencies — including system name, vendor, capabilities, decision-making role, and impact assessment status — and publish the inventory on the state's open data portal.
CT
Enacted eff 2023-07-01
The Judicial Department must conduct an annual inventory of its AI systems — including system name, vendor, capabilities, decision-making role, and impact assessment status — and publish the inventory on the department's website.
CT
Enacted eff 2026-07-01
The Department of Administrative Services must annually inventory all AI systems in use by state agencies — including system name, vendor, capabilities, decision-making role, impact assessment status, PII access, and known risks — and publish the inventory on the state's open data portal.
CT
Enacted eff 2026-07-01
State agencies must not use AI in public-assistance delivery or rights-impacting functions unless compliant with OPM/DAS policies, must comply with OPM/DAS policies for AI procurement, and must complete and publicly post an AI impact assessment at least 60 days before deploying any procured AI technology.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Enacted eff 2024-07-01
The Department must publish an aggregated statewide AI inventory on its website, withholding only information whose publication would compromise system security or integrity, and must provide withheld information to the Governor, General Assembly members, and law enforcement upon request.
CA
CA AB 1405 (AI Auditor Enrollment) § Gov. Code § 11549.82
Engrossed
The Government Operations Agency must, beginning January 1, 2027, (1) publish all enrolled AI auditor information in a publicly accessible format on its website, (2) retain misconduct reports for as long as the auditor remains enrolled plus 10 years, and (3) share misconduct reports with other state agencies as necessary for enforcement purposes.
CT
Introduced eff 2025-10-01
State agencies authorized to procure a high-risk AI system must contract with an impartial third party for an impact assessment (per Sec. 3(b) requirements), submit the assessment to the Commissioner of Administrative Services, and post it on the agency's website at least 60 days before deployment. Personally identifiable information may be redacted.
CT
Introduced eff 2026-10-01
State agencies authorized to procure AI technology must contract with an independent auditor for a bias audit under Section 8. The completed bias audit must be submitted to the Commissioner of Administrative Services and posted on the agency's website at least 60 days before deployment. The agency may redact personally identifiable information.
MA
Introduced
State agencies must submit impact assessments to the governor, president of the senate, and speaker of the house at least 60 days before system implementation and publish approved assessments on the agency's website. Agencies may redact information that would substantially harm public health or safety, infringe privacy rights, or significantly impact IT security, provided an explanatory statement of the redaction determination is published alongside the redacted assessment.
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(h)
Introduced
The Executive Office of Public Safety and Security must publish annually by March 31 on its website disaggregated statistics on all law enforcement facial recognition searches from the prior calendar year, including totals by agency, warrant-based searches by offense, emergency searches, and the race and gender of search subjects.
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(j)
Introduced
The Executive Office of Public Safety and Security must publish annually by March 31 on its website disaggregated statistics on all non-law-enforcement public agency facial recognition searches from the prior calendar year, including the race and gender of search subjects for each agency.
MA
Introduced
State agencies must submit each impact assessment to the governor, president of the senate, and speaker of the house at least 60 days before implementing the assessed automated decision-making system. Approved and utilized systems' impact assessments must be published on the relevant agency's website. An agency may redact information if disclosure would substantially harm public health/safety, infringe privacy rights, or significantly impact information technology protection, provided the agency publishes an explanatory statement describing its determination process alongside the redacted assessment.
MO
Introduced
Contracting entities must execute the statewide digital privacy agreement, obtain academic-effectiveness verification, and submit all documentation to the state board of education for listing for each software product adopted. Local educational agencies must also maintain their local software inventory. The state board must publish and update the statewide master list on an ongoing basis and conduct compliance audits.
NJ
Introduced
Boards of education and boards of trustees must distribute the adopted AI surveillance policy to the parents and guardians of students within the district or school.
NY
Introduced
The Office of Information Technology Services must maintain and annually publish on the New York State Open Data website a statewide inventory of all state agency artificial intelligence systems, including the purpose and uses of each system. State agencies must submit required inventory data to the office at least 60 days before each annual publication date.
NY
Introduced
The Commissioner of Labor must maintain a database of AI/automation-related WARN reports and must prepare and publish quarterly summaries analyzing the number, sector, and location of workforce reductions identified as resulting from AI or automation. Reports must be made publicly available on the Department of Labor's website and shared with the Department of Economic Development for use in workforce innovation planning and retraining programs.
NY
Introduced
All state and local law enforcement agencies must conspicuously post the ALPR minimum standards policy on their website (or in their main office if no website exists) and make the policy available to the public upon request.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(I)
Introduced eff 2026-11-01
The State Department of Education must create and maintain a publicly accessible Data Transparency Portal that (1) lists all data elements collected, (2) identifies which elements are mandatory versus optional, (3) publishes copies of all active vendor contracts and data-sharing agreements, (4) reports all data breaches or unauthorized disclosures within thirty days, and (5) posts annual privacy and security compliance audits.
TX
TX SB 1411 (Healthcare AI Algorithms) § Ins. Code § 544.706
Introduced eff 2025-09-01
The Office of Public Insurance Counsel must include in its annual consumer report cards information identifying and objectively comparing the use of AI-based algorithms by health benefit plan issuers and utilization review agents, with collaboration from the Texas Department of Insurance and the Health and Human Services Commission.
US
Introduced
The Director of OMB must publish the foreign adversary AI list on a publicly available website within 180 days of enactment.
AK
Failed
The Department of Administration must conduct a biennial inventory of all AI systems used by state agencies for consequential decisions — including each system's name, vendor, capabilities, and pre-implementation impact assessment status — and publish the completed inventory on the department's website.
AK
Failed
State agency heads must conduct at least biennial impact assessments of each AI system used for consequential decisions, covering efficacy, human oversight, accountability, appeal processes, risks (including cybersecurity and IP), effects on individual liberty and privacy, discrimination or disparate impact, and governing policies. Completed assessments must be submitted to the Department of Administration for publication on its website.
CT
Failed
The Commissioner of Administrative Services must annually inventory all AI systems used by state agencies (including vendor, capabilities, decision-making role, and impact-assessment status), publish the inventory on the state open data portal, perform ongoing discrimination assessments, and beginning July 1, 2026, provide annual employee trainings on generative AI use and bias mitigation.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(h)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year the total number of law enforcement facial recognition searches, disaggregated by requesting agency, by warrant vs. emergency, by alleged offense, and by race and gender of search subjects.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(j)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year the total number of facial recognition searches performed by or at the request of non-law enforcement public agencies, disaggregated by agency and including the race and gender of search subjects.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(h)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year aggregate data on all law enforcement facial recognition searches from the prior calendar year, disaggregated by requesting agency, including warrant vs. emergency counts by offense and the race and gender of search subjects.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(j)
Failed
The Executive Office of Public Safety and Security must publish on its website by March 31 each year data on all facial recognition searches performed by or at the request of non-law-enforcement public agencies for the prior calendar year, disaggregated by agency and including the race and gender of search subjects.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–803
Failed
The Department must publish an aggregated statewide AI inventory on its website. Information that could compromise the security or integrity of a State system may be withheld from public disclosure but must be provided on request to the Governor, General Assembly members, and law enforcement.
NC
Failed
The Department must (1) maintain and make publicly available documents describing the AI systems used and their functions in the environmental permitting process, and (2) inform each permit applicant when AI was used to assist in reviewing their application or drafting their permit.
NM
Failed
The General Services Department must annually compile and provide an aggregate inventory report of all agency AI systems — including assessment results — to the governor, the legislative finance committee, and the appropriate legislative interim committee.
US
Failed
State DMVs must post conspicuous notices at each office, make written information available to applicants, and provide website information describing how law enforcement uses facial recognition to search driver's license and ID photos, including translations into languages common to a significant portion of customers.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must maintain a publicly available AI governance plan on a centralized agency webpage that describes agency AI policies and procedures, including the AI use case inventory required by the Advancing American AI Act.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3596
Failed
GSA must maintain a single, publicly accessible, machine-readable online Federal AI System Inventory cataloging all agency AI governance charters, and must provide agencies a clear process for timely revisions and updates.
UT
UT SB 205 (Law Enforcement AI) § Utah Code § 53-25-902
Failed eff 2026-05-06
Law enforcement agencies must publicly post on their website their AI use policy and AI technology disclosure information, updating the posting within 30 days of any change. Agencies without a website must post on the Utah Public Notice Website.
WA
Failed
Each algorithmic accountability review office must maintain and publish quarterly on its website a public inventory of all algorithmic accountability reports for automated decision systems proposed, in use, or under development by public agencies. Beginning January 1, 2022, the office must also publish metrics on all approval, conditional approval, or denial decisions with written explanations.
WA
Failed
Agencies must provide transparency regarding their use, procurement, and development of automated decision systems that produce legal effects on identified or identifiable persons, including monitoring or testing for accuracy and bias.
WA
Failed
The Office must post all Algorithmic Accountability Review Board findings and reports on its public website, and independently transmit reports finding failure to meet minimum standards to the legislature and the governor.
WA
Failed
The Office must maintain and publish on its website a public inventory of all algorithmic accountability reports on automated decision systems (updated quarterly beginning December 1, 2023) and, beginning January 1, 2024, publish metrics on all approvals, conditional approvals, or denials of agency reports, including written explanations.
PS-01.4
Procurement standards compliance
AI systems intended for government procurement must meet defined performance, safety, transparency, and documentation standards. Vendors must be able to produce documentation demonstrating compliance as part of the procurement process.
Enacted
10
Live
20
Failed
41
Total
71
CA
CA SB 892 (ADS Procurement Standards) § Pub. Contract Code § 12100.1(b)
Enacted eff 2025-01-01
The Department of Technology must develop and adopt regulations creating an ADS procurement standard that includes (1) a detailed risk assessment procedure covering governance, purpose, misuse potential, data legality and provenance, robustness, and explainability; (2) risk control methods; (3) adverse incident monitoring procedures; (4) prohibited use case identification; (5) a detailed equity assessment; (6) a human oversight assessment; and (7) data minimization standards prohibiting vendors from using agency data for proprietary training. The Department must consider specified AI risk management publications, collaborate with stakeholders, consult with the CPPA, and solicit public comment.
CA
CA SB 892 (ADS Procurement Standards) § Pub. Contract Code § 12100.1(b)
Enacted eff 2025-01-01
The Department of Technology must, beginning January 1, 2026, and annually thereafter, review and update both the ADS procurement standard and its implementing regulations.
CA
CA SB 892 (ADS Procurement Standards) § Pub. Contract Code § 12100.1(c)
Enacted eff 2025-01-01
State agencies must not procure an ADS, enter into a contract for an ADS, or contract for any service utilizing an ADS until the Department of Technology has adopted the ADS procurement standard regulations.
CA
CA SB 892 (ADS Procurement Standards) § Pub. Contract Code § 12100.1(d)
Enacted eff 2025-01-01
State agencies must include in every ADS contract clauses that (1) provide a completed risk assessment analyzing governance, purpose, misuse potential, data legality and provenance, robustness, and explainability; (2) require adherence to appropriate procurement standards; (3) provide adverse incident monitoring procedures; (4) require agency authorization before deployment of ADS upgrades and enhancements; and (5) provide a termination right for significant vendor breaches.
CT
Enacted eff 2023-07-01
State contracting agencies must include a provision in every contract entered on or after October 1, 2023 requiring the contracting business to comply with the Connecticut Data Privacy Act (Conn. Gen. Stat. §§ 42-515 to 42-525).
CT
Enacted eff 2026-07-01
State agencies must not use AI in public-assistance delivery or rights-impacting functions unless compliant with OPM/DAS policies, must comply with OPM/DAS policies for AI procurement, and must complete and publicly post an AI impact assessment at least 60 days before deploying any procured AI technology.
IN
Enacted eff 2025-07-01
The Indiana Department of Education must establish guidelines for creating school AI policies and publish a model school AI policy, covering disclosure requirements for students, proper and improper use examples, privacy policies, and recommendations on restricting AI platform use.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–805
Enacted eff 2024-07-01
Beginning July 1, 2025, units of State government may not deploy any new AI system unless it complies with the policies and procedures adopted by the Department under § 3.5–804.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 13–116
Enacted eff 2024-07-01
Units of State government seeking to test new technology (including AI) through a proof-of-concept pilot must obtain approval from the Secretary of Information Technology, enter into a memorandum of understanding with DoIT, and comply with competitive solicitation requirements. The Department of General Services must adopt policies and procedures for competitive proof of concept procurements.
UT
UT HB 276 (AI Content Provenance & NCII) § Utah Code § 63A-16-215
Enacted eff 2027-01-01
The state chief information officer must establish by rule provenance standards for digital content on public-facing state agency webpages used for transactions or services, requiring provenance records identifying the software or tool used, creation date, content identifier, and prior content identifiers.
CA
CA SB 420 (Automated Decision Systems) § Pub. Contract Code § 10285.8
Engrossed eff 2026-01-01
State agencies must not award a contract for a high-risk automated decision system to any person who has violated the Unruh Civil Rights Act, the California Fair Employment and Housing Act, or the Automated Decision Systems chapter (Bus. & Prof. Code § 22756 et seq.).
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5522
Engrossed eff 2026-07-01
Public bodies must not implement any high-risk AI system unless they have fulfilled all requirements of Chapter 55.6 and complied with the CIO's high-risk AI policies and procedures.
VA
VA HB 2046 (Public Body High-Risk AI) § Va. Code § 2.2-5522
Engrossed eff 2026-07-01
Public bodies must include a CIO-developed high-risk AI system compliance clause in all procurement contracts for high-risk AI systems for which negotiation or renegotiation begins on or after July 1, 2026.
CT
Introduced eff 2025-10-01
State agencies must not procure, purchase, or acquire any high-risk AI system utilizing automated decision systems except where specifically authorized by law.
CT
Introduced eff 2026-10-01
State agencies and entities acting on their behalf must not use AI technology in any function related to public assistance delivery or materially impacting individuals' rights, civil liberties, safety, or welfare unless specifically authorized by law. State agencies must not procure, purchase, or acquire AI technology unless specifically authorized by law.
LA
LA HB 734 (AI Bill of Rights) § R.S. 38:2320.21
Introduced
The state and its political subdivisions must not enter into, modify, renew, or extend an AI technology contract unless the contracting entity provides a sworn affidavit attesting it is not owned by, controlled by, or organized under the laws of a foreign country of concern.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Introduced
The Department of State Police may perform facial recognition searches only for four authorized purposes: executing a felony warrant, responding to an emergency involving imminent danger of death or serious physical injury, identifying a deceased person, or acting on behalf of another agency that has obtained a warrant or documented an emergency or deceased-identification basis.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Introduced
The Department of State Police must centralize all facial recognition search functions within a single facial recognition operations group and must use only facial recognition technology from the RMV, the FBI, or technology approved by the Executive Office of Technology Services and Security following a public hearing.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Introduced
The Department of State Police must limit facial recognition searches to the five enumerated purposes: Registrar identity verification, warrant-based felony identification, emergencies involving imminent danger of death or serious physical injury, deceased-person identification, and searches on behalf of other agencies that have obtained a warrant or documented emergency grounds.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(d)
Introduced
The Department of State Police must designate a single facial recognition operations group to receive, evaluate, and perform all facial recognition search requests, and must use only facial recognition technology currently used by the Registrar or FBI — or technology approved by the Executive Office of Technology Services and Security following a public hearing.
MA
Introduced
No executive office, department, division, agency, or commission of the commonwealth may procure, purchase, or acquire any service or system utilizing automated decision systems unless the use is specifically authorized by law.
MA
Introduced
No executive office, department, division, agency, or commission of the commonwealth may procure, purchase, or acquire any service or system utilizing or relying on automated decision systems unless the use of such system is specifically authorized by law.
NJ
Introduced
The Office of Information Technology must establish minimum requirements for AI safety tests applicable to all AI technology sold, developed, deployed, used, or offered for sale in New Jersey. The requirements must include at minimum: (1) an analysis of potential cybersecurity threats and vulnerabilities; (2) an analysis of the AI technology's data sources and potential sources of bias, inaccurate information, or violations of state or federal criminal, copyright, patent, or trade secret laws; and (3) descriptions of possible remedies or defensive measures to address identified threats, biases, inaccuracies, or potential legal violations.
NJ
Introduced
The Office of Information Technology must establish minimum requirements for AI safety tests — including cybersecurity threat analysis, data source and bias analysis, and remediation descriptions — and must review each annual safety test report submitted by AI companies.
NY
Introduced
State units must purchase algorithmic decision system products or services only if they adhere to responsible AI standards, including (1) harm avoidance (minimizing risks of physical or mental injury, unjustified information disclosure, and unwarranted damage to property, reputation, or environment), (2) transparency (full disclosure of system capabilities, limitations, and potential problems), (3) fairness (eliminating discrimination, embedding equality and justice as system goals, and providing feedback avenues to redress harms), and (4) comprehensive impact and risk evaluation.
OK
Introduced eff 2026-11-01
State governmental entities must not enter into, extend, or renew AI contracts unless the vendor provides a sworn affidavit attesting it is not owned by, controlled by, or organized under the laws of a foreign adversary.
US
US HR 8516 (American Leadership in AI Act) § Sec. 301 (NDAA FY2021 Title LIII, new Sec. 5305)
Introduced
NIST must develop standards, guidelines, and minimum requirements for federal agency use, risk management, and procurement of AI systems (excluding national security systems), including standards for authenticating, tracking provenance, and labeling agency-generated synthetic content, and standards for testing, evaluation, verification, and validation of AI acquisitions.
US
Introduced
Each executive agency head must, within 90 days of enactment, review all AI provided by a covered foreign adversary entity on the Section 2(a) list and consider it for exclusion and removal from agency procurement and use.
US
Introduced
Each executive agency head must use at minimum the supply chain risk management authorities in 41 U.S.C. § 4713 to consider exclusion and removal of listed foreign adversary AI.
VA
Introduced
The Department of Criminal Justice Services must establish and publicly post on its website a model policy governing the use of covered AI systems by state and local law-enforcement agencies and sheriff's departments, covering authorized uses, a default prohibition on unauthorized uses, data practices, anti-discrimination protections, criminal-investigation disclosure requirements, and disciplinary consequences for violations.
AK
Failed
State agencies may contract for AI systems used in consequential decisions only if the vendor has implemented multi-factor authentication to secure the system and its stored data.
AK
Failed
State agencies may contract for AI systems used in consequential decisions only if the vendor has implemented security and privacy controls meeting NIST SP 800-53 Rev. 5 or a successor publication designated by department regulation.
FL
FL HB 1395 (AI Bill of Rights) § Fla. Stat. § 287.138
Failed eff 2026-07-01
Government entities must not extend, renew, or enter into contracts for AI technology, software, or products with entities owned by, controlled by, or organized under the laws of a foreign country of concern.
FL
FL HB 1395 (AI Bill of Rights) § Fla. Stat. § 287.138
Failed eff 2026-07-01
Government entities must not accept bids or enter into AI contracts unless the vendor provides a sworn affidavit attesting that the entity is not owned by, controlled by, or organized under the laws of a foreign country of concern.
FL
FL SB 2 (AI Bill of Rights) § Fla. Stat. § 287.138
Failed eff 2026-07-01
Governmental entities must, beginning July 1, 2026, obtain a sworn affidavit from any vendor providing AI technology, software, or products (or any vendor whose contract includes AI as an optional component) attesting that the vendor is not owned by, controlled by, or organized in a foreign country of concern, before accepting a bid or entering into a contract.
FL
FL SB 2 (AI Bill of Rights) § Fla. Stat. § 287.138
Failed eff 2026-07-01
Governmental entities must not knowingly enter into a contract with any entity for AI technology, software, or products if the entity is owned by, controlled by, or organized in a foreign country of concern.
FL
FL SB 482 (AI Bill of Rights) § Fla. Stat. § 287.138
Failed
Government entities must not enter into, extend, or renew contracts for AI technology, software, or products with entities that are owned by, have a controlling interest held by, or are organized under the laws of or have their principal place of business in a foreign country of concern.
FL
FL SB 482 (AI Bill of Rights) § Fla. Stat. § 287.138
Failed
Government entities must require AI technology vendors to provide a sworn affidavit, signed under penalty of perjury, attesting that the vendor is not owned by, controlled by, or organized under the laws of a foreign country of concern before accepting bids, proposals, or entering contracts for AI technology, software, or products.
FL
Failed
The Department of Management Services must, by January 1, 2025 and in consultation with the Advisory Council, prescribe by rule the form, contents, and manner of submission of the automated decision systems inventory report.
GA
Failed
Law enforcement agencies must use only facial recognition software formally approved in writing by the agency. Use of software obtained through pilot programs, demonstration programs, personal accounts, or trial periods in any investigation is prohibited.
GA
Failed
The Commission must develop and propose recommendations for minimum technology standards, data governance policies, individual appeal and human review procedures, bias prevention, pre-deployment risk evaluation, data provenance, cybersecurity, prohibitions on secret profiling and unitary scoring, public transparency, and the creation of a permanent oversight body for government automated decision systems.
HI
Failed
The Office of Enterprise Technology Services must develop, maintain, and periodically update procurement guidelines for state AI technology — building on the NIST AI RMF and the White House Blueprint for an AI Bill of Rights — addressing safety, algorithmic discrimination, data privacy, high-risk uses, and AI-generated content disclosure, in consultation with employee organizations, trust and safety experts, and academic researchers.
HI
Failed
Before adopting any automated decision system, a state agency must ensure the system has received appropriate consultation, testing, risk identification, and risk mitigation consistent with this chapter, and must obtain approval from the Chief Information Officer.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(d)
Failed
The Department of State Police may perform facial recognition searches only for four enumerated purposes: executing a felony warrant, responding to an emergency involving immediate danger of death or serious injury, identifying a deceased person, or on behalf of another agency with appropriate warrant or documented emergency/deceased-person justification.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(d)
Failed
The Department of State Police must centralize all facial recognition search operations in a single designated operations group and must use only facial recognition technology currently used by the RMV or FBI, or technology approved by the Executive Office of Technology Services and Security following a public hearing.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(d)
Failed
The Department of State Police must designate a single facial recognition operations group to receive, evaluate, and execute all law enforcement facial recognition search requests, and must use only RMV, FBI, or Executive Office of Technology Services and Security-approved facial recognition technology, with new software requiring a public hearing before approval.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–805
Failed
Beginning July 1, 2025, units of State government must not deploy any new AI system unless it complies with the Department's AI policies and procedures.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-506
Failed
The State Police, in consultation with other relevant state agencies, must adopt and publish a model statewide policy regarding the use of facial recognition technology.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-506
Failed
Law enforcement agencies must not use or contract for facial recognition technology unless the use conforms to the model statewide policy adopted and published by the State Police.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–506
Failed
The Department of Public Safety and Correctional Services must (1) adopt and publish a model statewide policy for facial recognition use, (2) develop and administer training and proficiency testing including cultural diversity and implicit bias components, (3) review and approve a single facial recognition technology for statewide law enforcement use, and (4) publish on its public website the name, version, and vendor of the currently and previously approved technologies.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–506
Failed
Law enforcement agencies must not use or contract for facial recognition technology unless the use conforms to the model statewide policy and the technology is currently approved by the Department of Public Safety and Correctional Services.
MN
Failed eff 2023-01-01
The Commissioner of Public Safety must use facial recognition technology on every driver's license and Minnesota identification card application and renewal to prevent duplicate issuance, identification fraud, and to expedite processing.
MN
Failed eff 2023-01-01
The Commissioner must incorporate facial recognition software that uses mathematical algorithms to compare applicant facial features against photographs and data in the Department of Public Safety's records, relevant FBI records, and any other relevant law enforcement or criminal history databases.
MT
Failed
Law enforcement agencies must limit facial recognition technology use to investigating serious crimes (with probable cause), locating missing/endangered persons, or identifying deceased persons; must obtain a warrant or court order before performing a search (with a 24-hour emergency exception); must not use sketches or manually produced images as inputs; and must not substantively manipulate images inconsistent with the provider's intended use.
NC
Failed
Prime contractors must certify at contract execution and each annual renewal whether an AEDT was or will be used to select contract employees, provide the bias audit summary to the contracting agency before such use, and acknowledge that material noncompliance constitutes a breach of contract entitling the State to withhold payment or terminate for cause.
NC
NC SB 287 (Safeguard Health Ins. Utilization Reviews) § Section 2 (State Health Plan compliance review)
Failed
The State Treasurer and the Executive Administrator of the State Health Plan must review all State Health Plan practices and all third-party utilization review contracts to ensure compliance with the AI utilization review prohibition in G.S. 58-50-61(s).
NM
NM HB 184 (Government AI Transparency) § Section 13-1-200 NMSA 1978
Failed
Procurement contracts for AI products or services subject to the Act must include a vendor transparency requirement obligating the vendor to disclose the system's methodology, data types and sources, data collection and weighting methods, and error-correction processes.
NY
NY AB 5309 (Government AI Procurement Standards) § State Finance Law § 165(9)
Failed
State units must purchase algorithmic decision systems only if the product or service adheres to responsible AI standards covering (1) harm avoidance (minimizing risks of physical/mental injury, unjustified data disclosure, and property/reputation/environmental damage), (2) transparency (full disclosure of system capabilities, limitations, and potential problems), (3) fairness (eliminating discrimination, providing feedback avenues for redress), and (4) comprehensive impact and risk evaluation.
US
Failed
Federal law enforcement agencies and crime laboratories serving them must use only computational forensic software tested under NIST's Computational Forensic Algorithm Testing Program, must conduct and publicly publish an internal validation under the Computational Forensic Algorithm Testing Standards, and must update the validation upon any material software change.
US
Failed
The Administrator of Federal Procurement Policy must provide draft contract language for agency procurement that requires AI suppliers to adhere to framework-consistent actions and to provide access to data, models, and parameters sufficient for testing, evaluation, verification, and validation.
US
Failed
The Federal Acquisition Regulatory Council must promulgate regulations establishing requirements for AI acquisitions with risk-based framework compliance, and solicitation provisions and contract clauses referencing those requirements, within one year after OMB issues guidance under subsection (b)(1).
US
Failed
Federal law enforcement agencies and crime laboratories providing services to federal law enforcement must (1) use only computational forensic software tested under the NIST Computational Forensic Algorithm Testing Program, (2) conduct an internal validation per the Computational Forensic Algorithm Testing Standards and make results publicly available, and (3) update the internal validation whenever a material software change triggers retesting.
US
US HR 7532 (Federal AI Governance) § 44 U.S.C. § 3594
Failed
Each agency head must ensure that procurement contracts for federal AI systems are consistent with the subchapter's requirements and OMB guidance.
US
Failed
The FAR must be revised within six months of OMB guidance issuance to require contractors and subcontractors building, providing, operating, or maintaining federal AI systems to supply the information agencies need for AI governance charters and compliance reporting.
US
Failed
Covered agencies (DoD, intelligence community, FBI) must establish criteria for when AI systems warrant accredited privacy, civil rights, and civil liberties testing, adopt those criteria, and submit each qualifying AI system to a NIST-accredited organization for evaluation before procuring, fielding, or using the system.
US
Failed
The Director of OMB must, within one year of enactment and in consultation with the AI Hygiene Working Group, implement procurement-contract requirements ensuring that AI acquisitions align with OMB AI guidance, address privacy, civil rights, civil liberties, data ownership and security, and include requirements for securing training data, algorithms, and AI system components against misuse, unauthorized alteration, degradation, or inoperability. These requirements must be updated at least every two years.
WA
Failed
The Washington State CIO must adopt rules by January 1, 2022 governing the development, procurement, and use of automated decision systems by public agencies, incorporating the minimum standards set forth in Sections 4 and 5, after consulting with representatives of disproportionately impacted communities.
WA
Failed
Public agencies must ensure that procurement contracts for automated decision systems preserve all minimum standards in this section without impairment, require the vendor to waive any legal claims that would impair these standards, and must not contain nondisclosure or other provisions that prohibit or impair the minimum standards.
WA
Failed
The Office of the State CIO must, in consultation with the Office of Equity and impacted community representatives, adopt guidance for agencies on the development, procurement, and use of automated decision systems, incorporating the minimum standards set forth in the act.
WA
Failed
Agencies must ensure that for newly acquired systems (and to the maximum extent practicable for existing ones), the system and its training data are made freely available by the vendor before, during, and after deployment for agency or independent third-party testing, auditing, or research, subject to trade-secret protections that limit disclosure to outcomes only.
WA
Failed
Procurement contracts for automated decision systems entered into after the effective date must ensure the minimum standards can be effectuated without impairment, require the vendor to waive legal claims that would impair those standards, and may not contain nondisclosure or other provisions that would prohibit or impair the minimum standards.