R-01
Reporting & Regulatory Submissions
Incident Reporting
Deployers must report significant AI safety incidents to the designated regulatory authority within the required timeframe, on an accelerated basis for incidents posing imminent risk of death or serious injury.
Sub-obligations4
Bills58
Jurisdictions25
Enacted5
Show
Sort bills within section

4 sub-obligations of R-01

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
R-01.1 Regulator notification of safety incidents
Deployers must report safety incidents to the designated regulatory authority within the required timeframe, and on an accelerated basis — including to law enforcement or public-safety authorities where applicable — for incidents posing imminent risk of death or serious physical injury.
4Enacted 33Live 18Failed 55Total Jump →
R-01.2 Individual notification
Notification to individuals who were harmed or at risk of harm from a safety incident, analogous to data breach notification.
0Enacted 5Live 4Failed 9Total Jump →
R-01.3 Algorithmic Discrimination Discovery Reporting
Deployers must notify the appropriate enforcement authority when they discover a deployed high-risk AI system has caused algorithmic discrimination, and developers must notify known deployers and the enforcement authority upon discovering such discrimination risks, each within the required timeframe.
4Enacted 12Live 14Failed 30Total Jump →
R-01.4 Emergency services notification for imminent user risk
Deployers of conversational AI systems must, on obtaining knowledge that a user faces imminent risk of death or serious physical injury, make reasonable efforts within a defined timeframe to notify emergency services or law enforcement and provide the user with crisis resources.
0Enacted 3Live 0Failed 3Total Jump →
Bills That Map This Requirement 100 mappings
R-01.1
Regulator notification of safety incidents
Deployers must report safety incidents to the designated regulatory authority within the required timeframe, and on an accelerated basis — including to law enforcement or public-safety authorities where applicable — for incidents posing imminent risk of death or serious physical injury.
Enacted
4
Live
33
Failed
18
Total
55
CA
CA SB 53 (Frontier AI Transparency) § Bus. & Prof. Code § 22757.13
Enacted eff 2026-01-01
Frontier developers must report any critical safety incident pertaining to their frontier models to the Office of Emergency Services within 15 days of discovery. If a critical safety incident poses an imminent risk of death or serious physical injury, the developer must disclose the incident within 24 hours to an appropriate authority, including any law enforcement or public safety agency with jurisdiction. Amended reports may be filed when additional information is discovered. A federal equivalency safe harbor is available: OES may designate substantially equivalent federal reporting regimes, and a frontier developer that declares intent to comply with a designated federal regime is deemed in compliance until the developer revokes that intent or OES revokes the designation. Failure to meet the designated federal standards constitutes a violation of this chapter.
NY
Enacted eff 2025-12-19
Large developers must disclose each safety incident affecting a frontier model to the Division of Homeland Security and Emergency Services within 72 hours of learning of the incident or of learning facts sufficient to establish a reasonable belief that a safety incident has occurred. The disclosure must include: (1) the date of the safety incident; (2) the reasons the incident qualifies as a safety incident under the statutory definition; and (3) a short and plain statement describing the safety incident.
NY
Enacted eff 2027-01-01
Frontier developers must report any critical safety incident to the Office within 72 hours of determination or reasonable belief. If the incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to an appropriate authority, including law enforcement or a public safety agency.
NY
Enacted eff 2027-01-01
Frontier developers electing to comply with incident reporting via a designated substantially equivalent federal standard must declare that intent to the Office and concurrently send copies of any federal critical safety incident reports to the Office. Failure to meet the designated federal standard constitutes a violation of this article.
VA
VA SB 796 (AI Chatbots & Minors) § Va. Code § 59.1-616
Engrossed
Covered entities must submit a report to the Attorney General within 15 days of obtaining knowledge of a covered incident (death, suicide attempt, self-harm requiring medical attention, psychiatric emergency requiring urgent treatment, or serious physical injury requiring medical attention) connected to one or more of its chatbots. The report must include, to the extent known: (1) the date the operator obtained knowledge of the incident, (2) the date of the incident, (3) a brief description of the incident and the basis for the operator's belief that it is connected to the chatbot, and (4) a description of any responsive actions taken. The covered entity may submit a supplemental report within 60 days to update or correct information. Reports are confidential; the Attorney General may publish only aggregate statistics that do not identify individual users or disclose trade secrets.
HI
Introduced
Deployers must notify the Executive Director of the Office of Consumer Protection and the Attorney General within 90 days of discovering a material violation affecting a class of consumers, or that a high-risk AI system caused or materially contributed to algorithmic discrimination or other material consumer harm. The notification must describe the issue, affected consumer categories, mitigation steps, corrective actions, and changes to prevent recurrence.
IL
Introduced eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to one of their frontier models to the Attorney General within 15 days after discovering the incident.
IL
Introduced eff 2027-01-01
Frontier developers must, upon discovering that a critical safety incident poses an imminent risk of death or serious physical injury, disclose the incident within 24 hours to an appropriate authority, including any law enforcement or public safety agency with jurisdiction.
IL
Introduced eff 2027-01-01
Large chatbot providers must report any child safety incident pertaining to one of their covered chatbots to the Attorney General within 15 days after discovering the incident.
IL
Introduced
Frontier developers must report any critical safety incident to the Attorney General within 15 days of discovery. If an incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to appropriate law enforcement or public safety agencies.
IL
Introduced
Frontier developers that elect to comply with this section through a designated substantially equivalent federal reporting standard must declare that intent to the Attorney General. Upon declaration, compliance with the federal standard satisfies this section, but failure to meet the federal standard constitutes a violation of this Act.
IL
Introduced eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to one of their frontier models to the Attorney General within 15 days after discovering the incident.
IL
Introduced eff 2027-01-01
Frontier developers must, when a critical safety incident poses an imminent risk of death or serious physical injury, disclose the incident within 24 hours to an appropriate authority, including any law enforcement agency or public safety agency with jurisdiction.
IL
Introduced eff 2027-01-01
Large chatbot providers must report any child safety incident pertaining to one of their covered chatbots to the Attorney General within 15 days after discovering the incident.
IL
Introduced
Frontier developers must report any critical safety incident pertaining to their frontier models to the Agency within 15 days of discovery. If a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer must disclose it within 24 hours to an appropriate authority, including law enforcement or public safety agencies.
IL
Introduced
Frontier developers may satisfy incident reporting obligations by complying with a substantially equivalent federal reporting regime designated by the Agency, provided they declare their intent to the Agency; failure to meet the designated federal standard constitutes a violation of this Act.
LA
Introduced eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to their frontier models to the attorney general within 15 days of discovery, or within 24 hours if the incident poses imminent risk of death, serious physical injury, or an active cyberattack on critical infrastructure. Compliance with a substantially equivalent federal reporting regime designated by the attorney general satisfies this requirement.
MA
MA SB 2630 (Frontier AI Transparency & Safety) § G.L. c. 93M, § 2 (incident reporting subdivisions)
Introduced
Frontier developers must report any critical safety incident to the Attorney General within 15 days of discovery. If the incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to an appropriate authority, including law enforcement or public safety agencies.
MA
MA SB 2630 (Frontier AI Transparency & Safety) § G.L. c. 93M, § 2 (incident reporting subdivisions)
Introduced
Frontier developers may elect to comply with incident reporting requirements by complying with a substantially equivalent federal regime designated by the Attorney General, provided they declare intent to the Attorney General. Failure to meet the federal standard constitutes a violation of Massachusetts law.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must report each AI safety incident affecting a covered model or any derivative under their control to the attorney general within 72 hours of learning of the incident or facts sufficient to establish a reasonable belief that an incident has occurred.
MI
Introduced
If a security breach occurs involving data collected through an electronic monitoring tool or automated decisions tool, the employer must (a) promptly secure the affected systems, mitigate harm, and certify that corrective steps were taken; and (b) within 48 hours of discovering the breach, notify all affected covered individuals with a notice that includes: (i) a summary of how the breach occurred, (ii) the specific data compromised (if known), (iii) how the employer is responding, and (iv) steps the individual can take to secure their data or apply for employer-covered protections.
MI
Introduced
Employers must notify the Department of Labor and Economic Opportunity and the attorney general of any security breach involving data collected through an electronic monitoring tool or automated decisions tool.
MI
Introduced
On a security breach of monitoring or automated-decision data, employers must promptly secure and remediate the systems, notify affected workers within 48 hours with breach details and protective steps, notify the department and attorney general, and provide affected workers extensive remedies including 10 years of identity-theft protection with a $5,000,000 insurance policy, credit and dark web monitoring, a three-bureau credit freeze, and fraud remediation.
MN
MN HF 4532 (RAISE Act) § Minn. Stat. § 325M.41
Introduced
Developers must disclose each safety incident affecting the AI model to the attorney general within 72 hours of the date the developer learns of the incident or learns sufficient facts to establish a reasonable belief that an incident has occurred. The disclosure must include: (1) the date of the safety incident, (2) the reasons the incident qualifies as a safety incident under the statute, and (3) a short plain-language statement describing the incident.
MN
Introduced
Developers must disclose each safety incident affecting the AI model to the attorney general within 72 hours of learning of the incident or within 72 hours of learning sufficient facts to establish a reasonable belief that a safety incident has occurred. The disclosure must include: (1) the date of the safety incident; (2) the reasons the incident qualifies as a safety incident under the statute; and (3) a short statement describing the safety incident in plain language.
MN
MN SF 4674 (Social Media Threat Reporting) § Minn. Stat. § 325M.36
Introduced
Social media platforms must report articulable threats of targeted violence to the Minnesota Fusion Center and must follow MNFC reporting requests to facilitate transmission of threat information, files, personal information, and other data.
MN
MN SF 4674 (Social Media Threat Reporting) § Minn. Stat. § 325M.36
Introduced
Social media platforms must report articulable threats of targeted violence to the MNFC within 24 hours of discovery; if the content indicates a person may act on the threat within 24 hours of posting, the platform must report immediately through any practicable means.
NJ
Introduced
Employers and public entities must establish, implement, and maintain reasonable data security practices for employee, service beneficiary, and applicant data. In the event of a security breach, the employer/public entity and vendor must provide written notice to the Department and each affected individual within 48 hours, describing the categories of data compromised and remediation steps. Employers, public entities, and vendors are jointly and severally liable for damages from security failures.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 520
Introduced
Licensees must notify the Department of State when their system fails to operate as intended for any significant period of time — meaning a period during which the malfunction had the capacity to harm or did harm persons. For systems that interact with law enforcement or government systems, perform law enforcement or government functions, or operate as weapons, licensees must additionally notify the specific law enforcement agency or governmental entity designated by the Department at the time of licensing.
PA
Introduced
Participants must notify the Office and report on consumer-protection actions taken if a tested product or service fails before the end of the testing period.
SC
Introduced
Covered entities must submit a report to the Attorney General within 15 days of obtaining knowledge of a covered incident — defined as an incident in which a user suffered death, a suicide attempt, self-harm requiring medical attention, a psychiatric emergency requiring urgent treatment, or serious physical injury arising from chatbot interactions. The report must include, to the extent known: (a) the date the operator learned of the incident, (b) the date of the incident, (c) a brief description of the incident and the basis for believing it is connected to the chatbot, and (d) a description of actions taken in response. The entity may submit a supplemental report within 60 days to update or correct information. Reports are confidential and exempt from FOIA.
SC
Introduced
Covered entities must submit a report to the Attorney General within 15 days of obtaining knowledge of a covered incident (death, suicide attempt, self-harm requiring medical attention, psychiatric emergency, or serious physical injury connected to a chatbot). The report must include, to the extent known: (1) the date the operator learned of the incident, (2) the date of the incident, (3) a brief description of the incident and the basis for the operator's belief that it is connected to the chatbot, and (4) a description of any responsive actions taken. A supplemental report may be submitted within 60 days to update or correct information. Reports are confidential and exempt from FOIA.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-20
Introduced
Developers must disclose to the Attorney General and to all known deployers or other developers any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended uses of their high-risk AI system, without unreasonable delay but no later than 90 days after (1) the developer discovers through ongoing testing and analysis that the system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination, or (2) the developer receives from a deployer a credible report that the system has been deployed and has caused algorithmic discrimination.
US
Introduced
Covered model developers must report to the Secretary of Commerce within 7 days of knowing or reasonably believing that a defined reportable safety incident—including loss-of-control behavior, model-weight theft or self-exfiltration, offensive-cyber uplift, autonomous AI R&D acceleration, CBRN/explosive weapons uplift, or an averted near-miss—has occurred in connection with a covered model.
US
Introduced
Covered model developers must file an initial incident report within the 7-day window, provide expedited reporting for any reportable activity posing imminent or ongoing risk of serious harm, submit supplemental reports as material information develops, and include the incident description, discovery date, causal/contextual information, and national-security or public-safety implications.
US
Introduced
Upon a determination that a Federal official published AI-generated or AI-manipulated content without the required disclaimer, the responsible official (President, Vice President, or agency head) must (1) retract the content to the greatest extent possible and (2) issue a corrective communication stating the content violated this section, describing the factors that led to its publication, and where appropriate publishing a revised compliant version to the same audience.
US
Introduced
Sandbox participants must notify the Director and the head of each relevant applicable agency of any incident resulting in consumer health or safety harm, economic damage, or an unfair or deceptive trade practice within 72 hours of occurrence.
CA
CA AB 3211 (Digital Content Provenance Standards) § Bus. & Prof. Code § 22949.90.1
Failed
Generative AI system providers must, within 24 hours of discovering a watermarking vulnerability or failure, report it to the Department of Technology and notify other providers that may be affected. Providers must also notify affected parties (platforms, researchers, users). Reports must be publicly posted on the provider's website; if public disclosure poses safety risks, providers may post a summary or delay disclosure up to 30 days while documenting mitigation efforts.
NC
Failed
Licensees must report any data breaches within 24 hours to the Department of Justice and within 48 hours to affected consumers, notwithstanding any other provision of law.
NC
Failed
Licensees must report any data breaches to the Department within 24 hours and to affected consumers within 48 hours.
NE
Failed eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to one of their frontier models to the Attorney General within 15 days after discovering the incident.
NE
Failed eff 2027-01-01
Frontier developers must, when they discover that a critical safety incident poses an imminent risk of death or serious physical injury, disclose that incident within 24 hours to an appropriate authority, including any law enforcement agency or public safety agency with jurisdiction based on the nature of the incident.
NE
Failed eff 2027-01-01
Large chatbot providers must report any child safety incident pertaining to one of their covered chatbots to the Attorney General within 15 days after discovering the incident.
NE
Failed eff 2027-01-01
Frontier developers and large chatbot providers that elect to comply with the Act's reporting requirements via a designated federal safe harbor must declare their intent to the Attorney General. Compliance with the designated federal law, regulation, or guidance document constitutes compliance with the corresponding state obligations for critical safety incidents (if the federal standard addresses catastrophic risk) or child safety incidents (if it addresses child safety risk). Failure to meet the designated federal standard is itself a violation of the Act. A developer or provider may revoke its election by declaration to the AG, and the AG must revoke a designation if its conditions are no longer met.
NY
Failed
Large developers must disclose each safety incident affecting a frontier model to the Division of Homeland Security and Emergency Services within 72 hours of learning of the incident or learning facts sufficient to establish a reasonable belief that a safety incident has occurred. The disclosure must include: (1) the date of the safety incident, (2) the reasons the incident qualifies as a safety incident under the statutory definition, and (3) a short and plain statement describing the safety incident.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 420
Failed
Licensees must notify the department and, where applicable, relevant law enforcement or governmental entities when the system fails to operate as intended for a significant period of time — defined as a period where the malfunction had the capacity to or has harmed a person.
NY
Failed
Frontier developers must report any critical safety incident to the Office within 72 hours of determining or reasonably believing the incident occurred. If the incident poses imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to appropriate law enforcement or public safety authorities. Developers electing to comply via a designated substantially equivalent federal reporting standard must concurrently copy incident reports to the Office.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.003
Failed
Developers that believe or have reason to believe a deployed high-risk AI system does not comply with this chapter must immediately take corrective action — including withdrawing, disabling, or recalling the system — and inform affected distributors and deployers.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.003
Failed
Developers that know or should reasonably know their high-risk AI system presents risks of algorithmic discrimination, unlawful personal data disclosure, or deceptive manipulation must immediately investigate the causes and inform the attorney general in writing of the non-compliance and corrective actions taken.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.011
Failed
Deployers must notify in writing the AI Council, the attorney general or the appropriate sector regulator, and affected consumers as soon as practicable after discovering that a deployed high-risk AI system has caused algorithmic discrimination.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.011
Failed
Developers that discover a deployed high-risk AI system is producing Subchapter B-violating inputs or outputs must cease the system's operation as soon as technically feasible and notify the AI Council and attorney general within 10 days of discovery.
US
Failed
Critical-impact AI organizations that discover their system is noncompliant with TEVV standards, or that are notified of noncompliance by the Secretary, must (1) immediately notify the Secretary, (2) take remedial action, and (3) within 10 days submit a report describing the nature of the noncompliance, remedial measures taken, and actions to address affected stakeholders.
UT
UT HB 286 (AI Transparency Act) § Utah Code § 13-72b-106
Failed eff 2026-05-06
Large frontier developers must report any safety incident (child safety incident or critical safety incident) to the Office of Artificial Intelligence Policy within 15 days of discovery.
UT
UT HB 286 (AI Transparency Act) § Utah Code § 13-72b-106
Failed eff 2026-05-06
Large frontier developers must disclose a critical safety incident posing imminent risk of death or serious physical injury to a law enforcement or public safety agency with appropriate jurisdiction within 24 hours of discovery.
UT
UT SB 149 (AI Policy Act) § Utah Code § 13-70-304
Failed
Learning Laboratory participants must immediately report to the Office any incidents resulting in consumer harm, privacy breach, or unauthorized data usage.
R-01.2
Individual notification
Notification to individuals who were harmed or at risk of harm from a safety incident, analogous to data breach notification.
Enacted
0
Live
5
Failed
4
Total
9
MD
MD HB 1261 (AI Toy Safety) § Md. Code, Com. Law § 14-5104
Introduced eff 2026-07-01
Manufacturers must notify each readily identifiable parent or guardian of a child AI toy user within 48 hours of discovering a data breach or suspected data breach involving child user data.
MI
Introduced
If a security breach occurs involving data collected through an electronic monitoring tool or automated decisions tool, the employer must (a) promptly secure the affected systems, mitigate harm, and certify that corrective steps were taken; and (b) within 48 hours of discovering the breach, notify all affected covered individuals with a notice that includes: (i) a summary of how the breach occurred, (ii) the specific data compromised (if known), (iii) how the employer is responding, and (iv) steps the individual can take to secure their data or apply for employer-covered protections.
MI
Introduced
On a security breach of monitoring or automated-decision data, employers must promptly secure and remediate the systems, notify affected workers within 48 hours with breach details and protective steps, notify the department and attorney general, and provide affected workers extensive remedies including 10 years of identity-theft protection with a $5,000,000 insurance policy, credit and dark web monitoring, a three-bureau credit freeze, and fraud remediation.
NJ
Introduced
Employers and public entities must establish, implement, and maintain reasonable data security practices for employee, service beneficiary, and applicant data. In the event of a security breach, the employer/public entity and vendor must provide written notice to the Department and each affected individual within 48 hours, describing the categories of data compromised and remediation steps. Employers, public entities, and vendors are jointly and severally liable for damages from security failures.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(F)
Introduced
School entities must promptly notify parents of any unauthorized disclosure or breach of student data involving AI systems.
CA
CA AB 3211 (Digital Content Provenance Standards) § Bus. & Prof. Code § 22949.90.1
Failed
Generative AI system providers must, within 24 hours of discovering a watermarking vulnerability or failure, report it to the Department of Technology and notify other providers that may be affected. Providers must also notify affected parties (platforms, researchers, users). Reports must be publicly posted on the provider's website; if public disclosure poses safety risks, providers may post a summary or delay disclosure up to 30 days while documenting mitigation efforts.
NC
Failed
Licensees must report any data breaches within 24 hours to the Department of Justice and within 48 hours to affected consumers, notwithstanding any other provision of law.
NC
Failed
Licensees must report any data breaches to the Department within 24 hours and to affected consumers within 48 hours.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.011
Failed
Deployers must notify in writing the AI Council, the attorney general or the appropriate sector regulator, and affected consumers as soon as practicable after discovering that a deployed high-risk AI system has caused algorithmic discrimination.
R-01.3
Algorithmic Discrimination Discovery Reporting
Deployers must notify the appropriate enforcement authority when they discover a deployed high-risk AI system has caused algorithmic discrimination, and developers must notify known deployers and the enforcement authority upon discovering such discrimination risks, each within the required timeframe.
Enacted
4
Live
12
Failed
14
Total
30
CO
Enacted eff 2026-02-01
Developers must disclose to the Attorney General and all known deployers any known or reasonably foreseeable risks of algorithmic discrimination within 90 days of discovering that a deployed system has caused or is reasonably likely to have caused algorithmic discrimination, or of receiving a credible deployer report of actual discrimination.
CO
Enacted eff 2026-02-01
Deployers must notify the Attorney General within 90 days of discovering that a deployed high-risk AI system has caused algorithmic discrimination.
CO
Enacted eff 2026-02-01
Developers must disclose to the attorney general and to all known deployers or other developers any known or reasonably foreseeable risks of algorithmic discrimination arising from intended uses, without unreasonable delay but no later than 90 days after: (1) the developer discovers through ongoing testing and analysis that the system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination; or (2) the developer receives a credible report from a deployer that the system has been deployed and has caused algorithmic discrimination.
CO
Enacted eff 2026-02-01
Deployers must notify the attorney general within 90 days of discovering that a deployed high-risk AI system has caused algorithmic discrimination, in a form and manner prescribed by the attorney general.
GA
Introduced
Deployers that discover a deployed automated decision system has caused algorithmic discrimination must send a notice disclosing the discovery to the Attorney General, in a form and manner prescribed by the Attorney General, without unreasonable delay but no later than 90 days after the date of discovery.
HI
Introduced
Deployers must notify the Executive Director of the Office of Consumer Protection and the Attorney General within 90 days of discovering a material violation affecting a class of consumers, or that a high-risk AI system caused or materially contributed to algorithmic discrimination or other material consumer harm. The notification must describe the issue, affected consumer categories, mitigation steps, corrective actions, and changes to prevent recurrence.
IA
Introduced
Developers must disclose to the attorney general and all known deployers any known or foreseeable risks of algorithmic discrimination arising from intended uses of the high-risk AI system, no later than 90 days after discovering through testing that the system has caused or is reasonably likely to have caused algorithmic discrimination, or receiving a credible report from a deployer that the system has caused algorithmic discrimination.
MA
Introduced
Developers must notify the Attorney General and all deployers of any known or foreseeable risks of algorithmic discrimination within 90 days of discovery.
MA
Introduced
Developers must disclose to the attorney general and to all known deployers or other developers any known or reasonably foreseeable risks of algorithmic discrimination without unreasonable delay, but no later than 90 days after the date on which: (1) the developer discovers through ongoing testing and analysis that the system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination; or (2) the developer receives a credible report from a deployer that the system has caused algorithmic discrimination.
MA
Introduced
Deployers must, without unreasonable delay but no later than 90 days after discovering that a deployed high-risk AI system has caused algorithmic discrimination, send a notice disclosing the discovery to the attorney general in the form and manner prescribed by the attorney general.
NY
Introduced
Covered entities must report to the Department of Financial Services within 30 days if an impact assessment finds that an automated lending decision-making tool produces discriminatory or biased outcomes. Upon receipt of the report, the Department will direct the covered entity to cease all use of the tool and of any information produced by it.
NY
Introduced
Covered entities must report to the Department of Financial Services within 30 days if an impact assessment finds the automated lending decision-making tool produces discriminatory or biased outcomes. Upon receipt, the department must direct the covered entity to cease all use of the tool and of any information produced by it.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-3
Introduced eff 2025-10-01
Developers must disclose to the attorney general and all known deployers or other developers any known or reasonably foreseeable risks of algorithmic discrimination, within 90 days of discovering that the system has caused or is reasonably likely to have caused algorithmic discrimination to at least 1,000 consumers.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must notify the attorney general within 90 days of discovering that a deployed high-risk AI system has caused algorithmic discrimination to at least 1,000 consumers.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-20
Introduced
Developers must disclose to the Attorney General and to all known deployers or other developers any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended uses of their high-risk AI system, without unreasonable delay but no later than 90 days after (1) the developer discovers through ongoing testing and analysis that the system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination, or (2) the developer receives from a deployer a credible report that the system has been deployed and has caused algorithmic discrimination.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must, without unreasonable delay but no later than 90 days after discovery, notify the Attorney General in a prescribed form and manner upon discovering that a deployed high-risk AI system has caused algorithmic discrimination.
CO
Failed
Developers must disclose to the attorney general and all known deployers or other developers any known or reasonably foreseeable risks of algorithmic discrimination arising from intended uses of their high-risk AI system, without unreasonable delay and no later than ninety days after discovery.
CO
Failed
Deployers must, upon discovering that a deployed high-risk AI system has caused algorithmic discrimination, notify the attorney general without unreasonable delay and no later than ninety days after discovery.
CO
Failed
Developers must disclose to the attorney general and all known deployers any known or reasonably foreseeable risks of algorithmic discrimination within 90 days of discovery.
CO
Failed
Deployers must notify the attorney general within 90 days of discovering that a deployed high-risk AI system has caused algorithmic discrimination.
CO
Failed
Developers must disclose to the attorney general and all known deployers any known or reasonably foreseeable risks of algorithmic discrimination without unreasonable delay and no later than ninety days after the triggering event, effective June 30, 2026.
CO
Failed
Deployers who discover that a deployed high-risk AI system has caused algorithmic discrimination must notify the attorney general within ninety days of discovery, effective June 30, 2026.
CT
Failed
Developers must disclose to the Attorney General and all known deployers any known or reasonably foreseeable risks of algorithmic discrimination within 90 days of discovering (through testing or a credible deployer report) that the system has caused or is reasonably likely to have caused algorithmic discrimination to at least 1,000 consumers.
CT
Failed
Deployers must notify the Attorney General within 90 days of discovering that a deployed high-risk AI system has caused algorithmic discrimination to at least 1,000 consumers.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5002
Failed
Developers who learn through internal testing or credible reports that a high-risk AI system has caused or is likely to cause algorithmic discrimination must disclose the potential discrimination to the Attorney General and to all purchasers of the system.
NE
Failed
Developers must disclose to all known deployers or other developers each known risk of algorithmic discrimination arising from any intended use of their high-risk AI system, without unreasonable delay after: (1) the developer discovers through ongoing testing and analysis that the system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination; or (2) the developer receives a credible report from a deployer that the deployed system has caused algorithmic discrimination. The Attorney General shall prescribe the form and manner of this disclosure.
NM
Failed
Developers must, within 90 days of a risk incident, disclose to the State Department of Justice and all known deployer-recipients the known and foreseeable risks of algorithmic discrimination arising from the intended uses of the system involved.
NM
Failed
Deployers must notify the State Department of Justice as expeditiously as possible but within 90 days of discovering that a deployed high-risk AI system has caused algorithmic discrimination.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.003
Failed
Developers that know or should reasonably know their high-risk AI system presents risks of algorithmic discrimination, unlawful personal data disclosure, or deceptive manipulation must immediately investigate the causes and inform the attorney general in writing of the non-compliance and corrective actions taken.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.011
Failed
Deployers must notify in writing the AI Council, the attorney general or the appropriate sector regulator, and affected consumers as soon as practicable after discovering that a deployed high-risk AI system has caused algorithmic discrimination.
R-01.4
Emergency services notification for imminent user risk
Deployers of conversational AI systems must, on obtaining knowledge that a user faces imminent risk of death or serious physical injury, make reasonable efforts within a defined timeframe to notify emergency services or law enforcement and provide the user with crisis resources.
Enacted
0
Live
3
Failed
0
Total
3
VA
VA SB 796 (AI Chatbots & Minors) § Va. Code § 59.1-616
Engrossed
Covered entities must, within 24 hours of obtaining knowledge that a user faces an imminent risk of death or serious physical injury, make reasonable efforts to notify appropriate emergency services or law enforcement based on information the operator already possesses or can obtain through reasonable user-facing prompts. If the operator lacks sufficient information to enable emergency response, the operator must instead: (1) promptly provide a clear and prominent message urging the user to contact emergency services and providing crisis services information, (2) make reasonable efforts to encourage the user to seek immediate help from a trusted adult or emergency services, and (3) document the steps taken and the basis for determining that direct notification was not practicable. An operator that notifies in good faith is not liable for damages solely for making the notification absent willful misconduct or gross negligence.
SC
Introduced
When a covered entity obtains knowledge that a user faces imminent risk of death or serious physical injury, the operator must make reasonable efforts within 24 hours to notify appropriate emergency services or law enforcement, based on information the operator already possesses or can obtain through reasonable user-facing prompts. If the operator lacks sufficient information for emergency notification, it must instead (a) promptly display a clear and prominent message urging the user to contact emergency services with crisis services information, (b) encourage the user to seek immediate help from a trusted adult or emergency services, and (c) document the steps taken and the basis for determining that notification was not practicable. Good-faith notifications are protected from liability absent willful misconduct or gross negligence.
SC
Introduced
Covered entities must, within 24 hours of obtaining knowledge that a user faces an imminent risk of death or serious physical injury, make reasonable efforts to notify appropriate emergency services or law enforcement, to the extent practicable based on information the entity already possesses or can obtain through reasonable user-facing prompts. If notification is not practicable due to insufficient information, the entity must: (1) promptly provide a clear and prominent message urging the user to contact emergency services with crisis services information; (2) make reasonable efforts to encourage the user to seek immediate help from a trusted adult or emergency services; and (3) document the steps taken and the basis for determining notification was not practicable. A good-faith notification under this provision is shielded from liability unless the operator acted with willful misconduct or gross negligence.