R-02
Reporting & Regulatory Submissions
Regulatory Disclosure & Submissions
Developers or deployers of certain AI systems must submit documentation — including system descriptions, risk assessments, and safety evaluation results — to regulatory authorities either proactively on a defined schedule or in response to regulatory requests. Proactive submission requirements cannot be satisfied by waiting to be asked.
Sub-obligations4
Bills221
Jurisdictions41
Enacted18
Show
Sort bills within section

4 sub-obligations of R-02

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
R-02.1 Scheduled proactive submission
Documentation must be submitted to regulators on a defined schedule — for example, annually or upon deployment of a new system or material modification — covering risk assessments, impact assessments, and safety evaluation results as required by applicable law.
13Enacted 92Live 75Failed 180Total Jump →
R-02.2 On-demand production upon regulatory request
Deployers must produce requested AI-system documentation — including risk-management policies, impact assessments, model and dataset cards, and related records — to a regulator within the required timeframe, and must keep such documentation in a form that can be assembled and produced promptly.
8Enacted 57Live 38Failed 103Total Jump →
R-02.3 Market authorization or registry submission
Developers and/or deployers of AI systems in regulated domains must register the system, obtain a license, or secure pre-market authorization before placing it on the market, submitting the required technical description, intended uses, evaluation results, and/or responsible-party identification.
2Enacted 16Live 27Failed 45Total Jump →
R-02.4 Annual AI Compliance Self-Certification
Regulated entities must annually certify to the applicable sector-specific regulator that their AI systems meet enumerated performance, fairness, non-discrimination, accuracy, and reliability standards on a continuing basis.
1Enacted 14Live 8Failed 23Total Jump →
Bills That Map This Requirement 353 mappings
R-02.1
Scheduled proactive submission
Documentation must be submitted to regulators on a defined schedule — for example, annually or upon deployment of a new system or material modification — covering risk assessments, impact assessments, and safety evaluation results as required by applicable law.
Enacted
13
Live
92
Failed
75
Total
180
CA
CA AB 302 (Government AI Inventory) § Gov. Code § 11546.45.5(d)
Enacted eff 2024-01-01
The Department of Technology must submit a report of the comprehensive inventory of high-risk automated decision systems to the Assembly Committee on Privacy and Consumer Protection and the Senate Committee on Governmental Organization on or before January 1, 2025, and annually thereafter until the reporting requirement sunsets on January 1, 2029.
CA
CA SB 53 (Frontier AI Transparency) § Bus. & Prof. Code § 22757.12
Enacted eff 2026-01-01
Large frontier developers must transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of their frontier models every three months, or on another reasonable schedule specified by the developer and communicated in writing to the Office of Emergency Services, with written updates as appropriate.
CA
CA SB 896 (GenAI Accountability Act) § Gov. Code § 11549.65
Enacted eff 2025-01-01
The Department of Technology must update the Governor's report (per Executive Order N-12-23) as needed to respond to significant GenAI developments, consulting with academia, industry experts, and state employee representatives as appropriate.
CO
CO HB 1139 (AI in Health Care) § C.R.S. § 10-16-112.7
Enacted eff 2027-01-01
Covered entities must provide written disclosures to the Division of Insurance, the Department of Human Services, or the Department of Health Care Policy and Financing, as applicable, identifying: (1) the utilization review functions for which the AI system will be used; (2) the points in the utilization review process when the AI system is used; (3) the human oversight process, including the qualifications of the reviewer and whether a human must approve an adverse determination; and (4) the process for maintaining audit information sufficient to demonstrate compliance with the utilization review requirements.
IL
Enacted eff 2022-01-01
Employers that rely solely on AI analysis of video interviews to select applicants for in-person interviews must collect demographic data (race and ethnicity) on applicants who are and are not advanced to in-person interviews and applicants who are hired, and must report this data annually to the Department of Commerce and Economic Opportunity by December 31, covering the 12-month period ending November 30.
KY
KY SB 176 (Facial Recognition Technology) § KRS Chapter 61, Section 1(4)
Enacted eff 2022-04-08
Law enforcement agencies must adopt a facial recognition technology use policy before deploying the technology and must file a full copy of the policy (or any revision) with the Justice and Public Safety Cabinet within 30 days of adoption or revision.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-510
Enacted eff 2024-10-01
Law enforcement agencies must submit their annual FRT report to the Governor's Office of Crime Prevention, Youth, and Victim Services by May 1 each year. The Governor's Office must compile and transmit the reports, disaggregated by agency, to the Governor and General Assembly by October 1.
MD
MD SB 818 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–802
Enacted eff 2024-07-01
Each public senior higher education institution and Baltimore City Community College must (1) establish functionally compatible high-risk AI governance policies for research and academic AI by June 1, 2025, and (2) submit an annual report to the Department by September 1, 2025, and each year thereafter, on all high-risk AI procured and deployed for a research or academic purpose.
MD
MD SB 818 (AI Governance Act of 2024) § Section 2 (uncodified)
Enacted eff 2024-07-01
The AI Subcabinet must develop and submit to the Governor and General Assembly by December 1, 2024, a roadmap reviewing risks and opportunities of AI across twelve State service areas, including study plans, prioritization, stakeholders, and projected timelines.
MD
MD SB 818 (AI Governance Act of 2024) § Section 3 (uncodified)
Enacted eff 2024-07-01
The AI Subcabinet must submit a report to the Governor and General Assembly by December 1, 2025, on the sufficiency of the Subcabinet structure and the potential transition to a standalone department or independent unit.
NY
Enacted eff 2027-01-01
Large frontier developers must transmit to the Office a summary of any assessment of catastrophic risk resulting from internal use of their frontier models every three months, or on another reasonable schedule agreed upon with the Office.
TN
TN HB 2341 (Executive Branch AI Plans) § Tenn. Code Ann. § 4-3-1xx(a)–(c)
Enacted eff 2026-05-27
Each executive branch department must report its AI malicious-use prevention plan, findings, and recommendations to every member of the general assembly no later than January 1, 2025.
WA
WA SB 5395 (Health Carrier Prior Authorization AI) § RCW 48.43.0161 (as amended by Sec. 8)
Enacted eff 2026-06-11
Health carriers writing at least 1% of total accident and health premiums in Washington must report annually to the OIC by October 1 the total number of prior authorization requests, approvals, and denials — including the percentage of denials aided by AI, the percentage of determinations exceeding statutory turnaround deadlines, and the number of nonelectronic requests — along with code-level data and trend data, broken out separately for carrier-direct and delegated health care benefit manager determinations.
CA
Engrossed
MRO applicants must conduct an annual independence audit covering board composition, resource availability, funding sources, and civil society representation, and must report audit findings to the Attorney General.
NY
Engrossed
Covered businesses must file an annual report with the Department of Labor by March 1 of each year covering the preceding calendar year. The report must include: (1) employment data estimating the number of employees displaced or whose hours were reduced due to AI, the number hired or whose hours increased due to AI, and the number of positions previously filled that the business decided not to fill due to AI; and (2) information on the nature of AI usage, including objectives of AI use, human oversight of AI, frequency and length of AI use, any use of AI in relation to sensitive personal data (including storage and access protections), and measures in place for oversight, risk reduction, or other protections related to AI use.
NY
Engrossed
Every developer and deployer of a high-risk AI system must file with the attorney general a copy of the last completed independent audit together with each report required under this section.
NY
Engrossed
Developers of high-risk AI systems must complete and file reports with the attorney general on the following schedule: (1) an initial report within six months after completion of development and initial offering to a deployer or initial deployment, (2) annually thereafter, and (3) within six months of any substantial change. Developer reports must include: a description of the system's intended uses and disallowed uses, an overview of how the system was developed, an overview of training data, and any other information necessary to allow deployers to understand the outputs, monitor compliance, and fulfill their duties under this article. For systems already deployed at the effective date, developers have 18 months to file the first report and associated audit.
NY
Engrossed
Deployers of high-risk AI systems must complete and file reports with the attorney general on the following schedule: (1) an initial report within six months after initial deployment, (2) a second report within one year of the first, (3) biennially thereafter, and (4) within six months of any substantial change. Deployer reports must include: a description of actual, intended, or planned uses for consequential decisions and whether any developer-unintended uses are occurring; and an impact assessment covering algorithmic discrimination risk and mitigation steps, monetization plans (if applicable), and a cost-benefit evaluation for consumers and end users. A deployer that is also a developer may submit a single joint report containing all required information. For systems already deployed at the effective date, deployers have 18 months to file the first report and associated audit.
RI
RI SB 2010 (AI in Health Insurance) § R.I. Gen. Laws § 27-84-3
Engrossed
Insurers must disclose to OHIC and DBR how they use AI to manage healthcare claims and coverage, including the model types used, AI's role in decision-making, training datasets, performance metrics, governance and risk-management policies, and the decisions where AI made or substantially contributed.
VA
VA SB 586 (Health Carrier AI Disclosures) § Va. Code § 38.2-3407.15(B)(15)
Engrossed
Carriers must publicly disclose to the Bureau of Insurance their use of AI to manage insurance claims and coverage, including the underlying algorithms, data used, and resulting determinations.
AK
Introduced eff 2027-01-01
Social media platforms with known minor Alaska-resident users must submit an annual report to the attorney general that includes: (1) a description of design features used by the platform that may affect minors; (2) a description of measures taken to mitigate harm to minors; (3) a summary of data collection and privacy practices relating to minors; and (4) a description of any internal assessments conducted regarding engagement or wellbeing of minors. The report may not be required to disclose proprietary algorithms or trade secrets.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2107
Introduced eff 2026-01-01
Healthcare insurers must submit quality assurance testing results to the Insurance Commissioner at least semiannually and publish those results on a public website within 30 days of submission.
AZ
Introduced
AI businesses must submit a transparency report to the Attorney General before using or selling a high-risk AI system, including the system's purposes and operation, results from internal risk assessment evaluations, and measures implemented to mitigate bias and harmful outcomes.
CA
Introduced
The commission must, by January 1, 2028, adopt standards requiring electrical and gas corporations to disclose the types of artificial intelligence models they use and how those models are used.
CA
Introduced
Electrical and gas corporations must file a compliance plan with the commission demonstrating compliance with the adopted AI standards. The commission may request records to verify compliance. Plans filed by electrical corporations must be reviewable by the Office of Energy Infrastructure Safety to ensure AI models used for wildfire mitigation are consistent with the corporation's wildfire mitigation plan.
GA
Introduced
Developers must provide the Attorney General with documentation regarding each automated decision system, in a form and manner prescribed by the Attorney General, including: (1) a general statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) documentation disclosing the system's purpose, intended benefits, high-level training data summaries, known limitations and discrimination risks, mitigation measures, pre-distribution performance evaluation methods, data governance measures covering training data suitability and bias, intended use/non-use/monitoring instructions, and all information necessary for deployers to comply with their own obligations; and (3) any additional documentation reasonably necessary for deployers to understand outputs and monitor discrimination risk.
IL
Introduced eff 2027-01-01
Large frontier developers must transmit to the Attorney General a summary of any assessment of catastrophic risk resulting from internal use of their frontier models at least every 3 months.
IL
Introduced
Large frontier developers must transmit to the Attorney General a summary of catastrophic risk assessments from internal use of their frontier models every 3 months or on another reasonable schedule communicated in writing to the Attorney General.
IL
Introduced
State agencies must submit each impact assessment to the Governor and the General Assembly at least 30 days before implementing the automated decision-making system. All other public bodies must submit each assessment to the director, executive officers, or primary administrator of the relevant governing body at least 30 days before implementation. Employers may redact information from published or submitted assessments if disclosure would substantially harm public health or safety, infringe privacy, or impair IT/operational security, or if the assessment covers security-incident prevention technology — but must publish an explanatory statement describing the determination process for each redaction alongside the redacted assessment.
IL
Introduced
Academic medical centers conducting AI-assisted therapy research must (1) register each qualified research program with the Department within 30 days of IRB approval, (2) submit annual reports summarizing participant counts, serious adverse events, protocol modifications, and scientific findings, and (3) notify the Department within 10 business days of any IRB suspension or termination of a research protocol.
IL
Introduced
Auto insurers seeking any rate change must file a complete rate application with the Director of Insurance, bear the burden of proving the requested rate is justified and complies with the Section, and obtain prior approval before the change takes effect (deemed-approval after 60 days absent disapproval, hearing, or a Director-initiated review).
IL
Introduced eff 2027-01-01
Large frontier developers must transmit to the Attorney General a summary of any assessment of catastrophic risk resulting from internal use of their frontier models at least every 3 months.
IL
Introduced
Large frontier developers must transmit to the Agency a summary of catastrophic risk assessments resulting from internal use of their frontier models every 3 months or on another reasonable schedule communicated in writing to the Agency.
IL
Introduced
Employers must, when reporting the reason for a mass layoff or closing under the Illinois WARN Act, disclose any artificial intelligence-related job impacts, including the number of employees laid off substantially due to AI replacement or automation of their job functions.
LA
Introduced eff 2027-01-01
Large frontier developers must transmit to the attorney general a summary of any assessment of catastrophic risk resulting from internal use of their frontier models every three months or on another reasonable schedule communicated in writing to the department.
MA
Introduced
Carriers must annually submit to the Division of Insurance by December 31 a prescribed form detailing AI algorithms and data training sets used or planned for use in utilization review, together with an attestation that such algorithms and training data have minimized bias risk across protected characteristics and adhere to evidence-based clinical guidelines.
MA
Introduced
Large frontier developers must transmit to the Attorney General a summary of catastrophic risk assessments from internal use of their frontier models every three months, or on another reasonable schedule communicated in writing to the Attorney General.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must annually submit to the attorney general a compliance statement signed by the CTO or more senior officer, containing (1) an assessment of critical harms the model may cause, (2) an assessment of residual risk despite safety protocol compliance, and (3) a description of the verification process. The initial statement must be submitted within 30 days of deployment or commercial release.
MN
Introduced eff 2027-01-01
Employers must submit a copy of every pre-use notice to the Commissioner of Labor and Industry within ten days of providing the notice to workers.
MO
Introduced
Employers must, within thirty days after each quarter-end, disclose to the director of the department of labor and industrial relations all AI-related job impacts for the preceding quarter, including AI-driven layoffs, AI-driven hires, positions left unfilled due to AI replacement, individuals being retrained due to AI, and corresponding NAICS codes.
NJ
Introduced
Employers must annually report the demographic data collected under subsection (d) to the Department of Labor and Workforce Development.
NJ
Introduced
Large frontier developers must annually submit to the Attorney General a Risk Management Disclosure explaining the technical and organizational protocols they have implemented to reduce the risk of frontier models contributing to catastrophic harm.
NJ
Introduced
Large frontier developers must structure their Risk Management Disclosure to map each of their actions to the suggested actions in the current NIST AI Risk Management Framework, stating for each whether it is relevant, whether adopted, how implemented or why not, the compliance criteria used, and who is responsible.
NJ
Introduced
Large frontier developers must clearly identify which sections of their Risk Management Disclosure were written, edited, or otherwise contributed to by a generative AI system.
NJ
Introduced
Artificial intelligence companies must annually submit a report to the Office of Information Technology containing: (1) a list of all AI technologies tested; (2) a description of each safety test conducted, including the test's adherence to OIT requirements; (3) a list of all third parties used to conduct safety tests, if any; and (4) the results of each safety test administered.
NJ
Introduced
Employers must annually report the collected race and ethnicity demographic data to the Department of Labor and Workforce Development.
NJ
Introduced
Employers must report the demographic data collected under subsection (d) annually to the New Jersey Department of Labor and Workforce Development.
NJ
Introduced
Artificial intelligence companies must annually submit to the Office of Information Technology a report listing all AI technologies tested, describing each safety test conducted and its adherence to OIT requirements, identifying any third parties used for testing, and providing the results of each safety test.
NJ
Introduced
Employers with 100 or more employees that deploy AI systems resulting in layoffs must file an AI Impact Disclosure with the Department of Labor and Workforce Development. The disclosure must contain, at minimum, the date the AI tool was deployed, the date of layoffs, and the number of workers displaced by the AI deployment.
NJ
Introduced
AI infrastructure entities must conduct an environmental impact assessment at the time of initial deployment and annually thereafter, and file the assessment with the Department of Labor and Workforce Development. An additional environmental impact assessment must be conducted and filed with any capacity expansion.
NY
Introduced
Insurers must submit their AI-based algorithms and training data sets to the Superintendent, with a certification that they (1) minimize bias risk across protected characteristics and comply with antidiscrimination laws, (2) adhere to evidence-based clinical guidelines, (3) do not rely on non-compliant information, and (4) do not independently create or change clinical standards or coverage criteria.
NY
Introduced
Insurers must submit to the superintendent data on the amount of time each clinical peer reviewer spends examining an adverse determination before signing off, in such form and manner as the superintendent may require.
NY
NY AB 1342 (AI User Oath of Responsible Use) § Gen. Bus. Law § 394-cccc(4)
Introduced
Operators must submit a copy of each user oath to the Attorney General within thirty days of the user making the oath, in the form and manner designated by the Attorney General.
NY
Introduced
Insurers, Article 43 corporations, and HMOs must submit the artificial intelligence-based algorithms and training datasets that are being used or will be used in the utilization review process to the Department of Financial Services for bias certification review.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 510
Introduced
Any person developing an autonomous weapons system (as defined in § 501(2)(i)) within New York must disclose in writing to the Secretary of State, prior to active development, the names and addresses of all persons involved, a description of the system, the system's functions and intended use cases, and measures that will be taken to mitigate risks. The Secretary may require cessation of development based on this disclosure.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 513
Introduced
License applicants must submit a written, sworn application containing: (a) the exact name and address of the applicant (and member/officer/incorporation details as applicable); (b) the name and business and residential address of each member of the ethics and risk management board, each principal, and each officer; and (c) a description of all known general use cases of the advanced AI system, including any purposes foreseen to be implemented by the applicant.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 516
Introduced
The ethics and risk management board of each operator must annually submit to the Secretary a comprehensive report for each licensed high-risk advanced AI system covering: (a) all possible use cases (intended and unintended, likely and unlikely); (b) a thorough risk assessment for each use case evaluating potential harm across privacy, security, fairness, economic implications, societal well-being, and safety; (c) a detailed evaluation of known user use cases with recommendations on whether certain applications should be constrained or banned; (d) a mitigation plan for each identified risk including preemptive measures, monitoring processes, and responsive actions, plus a user/stakeholder communication strategy; (e) a comprehensive review of all incidents or failures in the past year; (f) user education efforts and plans considering varying digital literacy levels; (g) disclosure of ethics board conflicts of interest and measures to manage them; and (h) an update on measures taken to ensure adherence to applicable AI laws, regulations, and ethical guidelines.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 519
Introduced
Licensees must obtain express written consent from the Secretary before implementing any source code modification or upgrade in an accessible version of the system. The licensee must submit a written description of the purpose, new or modified functions, reason for the change, and an assessment of new or heightened risks. The Secretary has 30 business days to approve or reject (extendable by 30 additional business days); if no response is received, the change is deemed approved. Source code rewrites are subject to the same requirements but are reviewed as new applications within 180 business days (extendable by 180 days). All modifications, upgrades, and rewrites must be conducted in a pre-production environment. Updates (minor enhancements, bug fixes, cosmetic changes, security patches) are exempt from this requirement.
NY
Introduced
Employers must provide to the Department of Labor, no less than annually, the summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
Introduced
The Office of Information Technology Services must submit a copy of the AI inventory to the Governor, the Temporary President of the Senate, and the Speaker of the Assembly.
NY
NY AB 5429 (Workforce Stabilization Act) § Labor Law § 201-j(2)
Introduced
Employers must submit each impact assessment to the Department of Labor at least thirty days prior to the implementation of the artificial intelligence system that is the subject of the assessment.
NY
Introduced
Covered entities found by the Superintendent to have deployed automated lending decision-making tools producing discriminatory or biased outcomes must comply with any enhanced reporting requirements the Superintendent imposes, which may include additional annual reports, reports with additional information, or direct submission of all reports to the Department.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 111
Introduced
Covered developers and deployers must file each required report with the Department of Financial Services together with a copy of the last completed audit.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 111
Introduced
Covered developers must file reports with the Department of Financial Services within six months of completing development, annually thereafter, and within six months of any substantial change, describing intended and disallowed uses, how the system was developed, its training data, any audit, and information enabling deployer compliance.
NY
Introduced
Developers must submit documentation to the Attorney General affirming: (1) the identities and qualifications of professional domain experts involved in the AI technology, (2) the specific phases of development in which such experts contributed, and (3) any known risks, limitations, or ethical concerns disclosed during development. The Attorney General reviews submissions and issues certificates of compliance to compliant developers.
NY
NY AB 9654 (AI Civil Rights Act) § Civ. Rights Law § 104
Introduced
Developers and deployers must, within 30 days after completing a full pre-deployment evaluation, full impact assessment, or developer annual review: (1) submit the evaluation, assessment, or review to the Division of Consumer Protection; (2) publish a summary on their website in a manner easily accessible to individuals; and (3) submit the summary to the Division. Upon request, the evaluation, assessment, or review must be made available to the legislature. All evaluations, assessments, and reviews must be retained for at least 10 years. Trade secrets may be redacted from public disclosures; personal data must be redacted.
NY
Introduced
Insurers must submit to the Superintendent data on the amount of time each clinical peer reviewer spends examining an adverse determination before signing off, in the form and manner the Superintendent requires.
NY
NY SB 1854 (Workforce Stabilization Act) § Labor Law § 201-j(2)
Introduced
Employers must submit the completed AI impact assessment to the Department of Labor at least 30 days prior to implementation of the AI system that is the subject of the assessment.
NY
NY SB 2414 (Political AI Disclaimer) § Election Law § 14-106(2-b)
Introduced
Candidate committees must submit their synthetic media usage records to the State Board of Elections no later than one month after their election is certified. All other committees must submit such records no later than one month after election day.
NY
Introduced
Covered entities found by the superintendent to have deployed a tool producing discriminatory or biased outcomes must comply with any enhanced reporting requirements imposed by the superintendent, which may include additional annual reports, reports with additional information, or direct submission to the department.
NY
Introduced
Covered businesses must submit an annual report to the Department of Labor on or before March 1 of each year covering the preceding calendar year. The report must include: (1) employment data — estimates of employees displaced or whose hours were reduced due in full or in part to AI, employees hired or whose hours increased due in full or in part to AI, and positions previously filled that the business decided not to fill due in full or in part to AI; and (2) AI usage information — descriptions of the objectives of AI use, information regarding human oversight of AI, frequency and length of AI use, use of AI in relation to sensitive personal data including storage and access protections, and measures in place for oversight, risk reduction, or other protections related to AI use.
NY
NY SB 8928 (AI Workforce Impact Transparency) § Section 3 (Labor Law § 860-b(1)(f))
Introduced
Employers filing a WARN notice must include a statement indicating whether the employment losses are the result, in whole or in part, of the introduction, expansion, or adoption of AI systems, automation technologies, or machine-based processes that have replaced or materially altered the duties of affected employees. The statement must also include, to the extent known at the time of notice: (1) the estimated percentage of positions affected due to such automation or AI integration, and (2) a brief description of the technology or process that contributed to the reduction.
OH
OH HB 579 (Health Insurer AI Regulation) § Ohio Rev. Code § 3902.80
Introduced
Health plan issuers must file an annual report with the Superintendent of Insurance on or before March 1, covering: (1) each provider in the issuer's network; (2) the number of covered persons enrolled in health benefit plans in Ohio in the preceding calendar year; and (3) whether the issuer used, is using, or will use AI-based algorithms in utilization review processes, and if so: the algorithm criteria, data sets used to train the algorithm, the algorithm itself, outcomes of the software, and data on the amount of time a human reviewer spends examining each adverse determination before signing off. The report must be submitted in a form prescribed by the Superintendent, and an officer of the health plan issuer must verify its contents.
OH
Introduced
Licensed IVOs must provide written notice to the attorney general of any material changes to their verification plan, describing the proposed changes, the rationale, and how the changes will better ensure acceptable risk mitigation.
OH
OH SB 164 (Health Insurer AI Regulation) § Ohio Rev. Code § 3902.80
Introduced
Health plan issuers must annually file a report with the Superintendent of Insurance on or before March 1. The report must cover: (1) each provider in the issuer's network; (2) the number of covered persons enrolled in health benefit plans in Ohio in the preceding calendar year; and (3) whether the issuer used, is using, or will use AI-based algorithms in utilization review, and if so: the algorithm criteria, data sets used to train the algorithm, the algorithm itself, outcomes of the software, and data on the time a human reviewer spends examining each adverse determination before signing off. The report must be submitted in a form prescribed by the superintendent, and an officer of the health plan issuer must verify its contents.
PA
Introduced
Facilities using AI-based algorithms for clinical decision making must annually file an AI compliance statement with the Department of Health, in the form and manner prescribed by the department. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the facility's process for overseeing and validating algorithm performance and compliance.
PA
Introduced
Insurers using AI-based algorithms in utilization review must annually file an AI compliance statement with the Insurance Department, in the form and manner prescribed by the department. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the insurer's process for overseeing and validating algorithm performance and compliance.
PA
Introduced
MA or CHIP managed care plans using AI-based algorithms in utilization review must annually file an AI compliance statement with the Department of Human Services. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the plan's oversight and validation process.
PA
Introduced
Suppliers must file the written disclosure policy with the Bureau of Consumer Protection, in the form and manner prescribed by the bureau, along with: (1) the name and address of the supplier; (2) the name of the chatbot; and (3) an annual filing fee as prescribed by the bureau.
PA
Introduced
Facilities using AI-based algorithms for clinical decision making must annually file an AI compliance statement with the Department of Health. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide evidence of compliance, and (5) describe the facility's process for overseeing and validating AI performance and compliance.
PA
Introduced
Insurers using AI-based algorithms in utilization review must annually file an AI compliance statement with the Insurance Department. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest compliance with responsible-use requirements and provide evidence, and (5) describe the insurer's process for overseeing and validating AI performance and compliance.
PA
Introduced
MA or CHIP managed care plans using AI-based algorithms in utilization review must annually file an AI compliance statement with the Department of Human Services. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest compliance with responsible-use requirements and provide evidence, and (5) describe the plan's process for overseeing and validating AI performance and compliance.
RI
RI HB 7190 (AI Use by Health Insurers) § R.I. Gen. Laws § 27-84-3
Introduced
Insurers must disclose to OHIC and DBR how they use artificial intelligence to manage healthcare claims and coverage, including: the types of AI models used, the role of AI in the decision-making process, training datasets, performance metrics, governance and risk management policies, and the specific decisions on claims and coverage where AI made or was a substantial factor in the decision.
SD
SD SB 169 (Health Carrier AI Utilization Review) § Section 3 (new section, chapter 58-17H)
Introduced
Health carriers using AI, algorithms, or software tools for utilization review must compile an annual report detailing (1) how the AI tool was used in the utilization review process during the preceding fiscal year, and (2) the nature and degree of human review and oversight used to affirm or negate determinations. The report must be forwarded to the Executive Board of the Legislative Research Council on or before December 1 of each year.
TX
TX SB 1411 (Healthcare AI Algorithms) § Ins. Code § 544.704
Introduced eff 2025-09-01
Health benefit plan issuers must submit their AI-based algorithms and training datasets used or potentially used in utilization review to the Texas Department of Insurance in the form and manner prescribed by the commissioner.
US
Introduced
The Secretaries of Treasury, Homeland Security, and Commerce must jointly submit to Congress, within 180 days of enactment and annually thereafter, a report describing interagency policies to defend against AI-enabled financial crimes, itemizing currently available resources, and identifying additional resource needs — addressing deepfakes, voice cloning, foreign election interference, synthetic identities, market-disrupting false signals, and overall digital fraud.
US
Introduced
The Secretaries of Treasury, Homeland Security, and Commerce must jointly submit to Congress, within 90 days of each annual report, legislative recommendations and best practices to assist American businesses and government entities with risk mitigation and incident response to AI-enabled financial crimes.
US
Introduced
Covered entities must submit to the FTC (1) an annual summary report for each deployed covered algorithm's ongoing impact assessment and (2) an initial summary report for any new covered algorithm prior to deployment.
US
Introduced
Covered entities must include in their summary reports to the FTC: entity identification, a description of the critical decision the algorithm addresses, intended purpose, stakeholder consultation records, performance testing and differential performance evaluation results, publicly stated guardrails, data sourcing documentation, transparency and explainability measures, identified material negative impacts and remediation steps, infeasibility documentation, and any identified improvement resources — all in the format specified by the FTC.
US
Introduced
Developers and deployers must submit full pre-deployment evaluations, impact assessments, and annual reviews to the FTC within 30 days of completion, make them available to Congress on request, publish summaries on their websites, and retain all records for at least 10 years. Trade secrets may be redacted; personal data must be redacted from public disclosures.
US
Introduced
The Director of OMB must issue regulations or policies within 180 days of enactment to ensure federal-official compliance with the AI-content disclosure requirement and to establish specific formatting, placement, and wording guidelines for the disclaimer across various media formats.
US
Introduced
Each covered agency's civil rights office must submit a biennial report to its congressional oversight committees — first due one year after enactment — detailing the state of covered-algorithm technology and risks, mitigation steps taken, stakeholder engagement actions, and legislative or administrative recommendations regarding algorithmic bias, discrimination, and related harms.
US
Introduced
Covered entities must submit specified information related to each foundation model to the FTC and make certain information publicly available for each foundation model they provide.
US
Introduced
Covered entities must submit to the FTC (1) an annual summary report for each ongoing deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to its deployment.
US
Introduced
Covered entities must include in each summary report submitted to the FTC: entity identifying information, the specific critical decision being made, intended purpose, stakeholder consultation records, testing and evaluation documentation including differential performance results, publicly stated guardrails, data sourcing information, transparency and explainability measures, consumer contest/appeal mechanisms, identified material negative impacts and remediation steps, infeasible requirement documentation, and improvement resources, all in the format specified by the FTC.
US
Introduced
Regulated entities supervised by more than one financial regulatory agency must notify each such agency of any AI Innovation Lab application within 5 business days of submission to the appropriate financial regulatory agency.
US
Introduced
Developers and deployers must submit all full pre-deployment evaluations, full impact assessments, and developer annual reviews to the FTC within 30 days of completion, make them available to Congress on request, publish a summary on their website, and retain all records for at least 10 years. Trade secrets may be redacted; personal data must be redacted from public disclosures.
US
Introduced
Each covered agency's office of civil rights must submit biennial reports to its congressional oversight committees detailing (1) the state of covered algorithm technology and associated bias risks, (2) agency mitigation steps, (3) stakeholder engagement actions, and (4) recommendations for legislative or administrative action to address algorithmic bias and discrimination.
US
Introduced
The Secretary of Defense must notify Congress within five days of issuing an autonomous weapon system waiver for development, fielding, or substantial system modification, including the rationale, system description, operational parameters and safeguards, performance testing results, and anticipated waiver duration, in unclassified form with optional classified annex.
VT
Introduced eff 2025-07-01
Developers and deployers must file reports with the Attorney General prior to deployment of an automated decision system used in a consequential decision and then annually, or after each substantial change to the system, whichever comes first. Each report must be accompanied by a copy of the last completed independent audit and a legal attestation that the system either (1) does not violate any provision of this subchapter, or (2) may violate or does violate one or more provisions, together with a remediation plan and summary.
VT
Introduced eff 2025-07-01
Developers must file with the Attorney General a report containing: (1) system description including software stack, purpose, expected benefits, current and intended uses, impacted stakeholders; (2) intended outputs and whether they may be used beyond articulated purposes; (3) training methodology including pre-processing steps, dataset descriptions, data sources, collection rationale, data quality and appropriateness, breadth of training data, data gap remediation, and compliance with privacy, data security, and copyright laws; (4) use and data management policies; (5) information necessary for deployers to understand outputs and monitor compliance; (6) information necessary for deployer compliance with deployer reporting requirements; (7) system capabilities and developer-imposed limitations including out-of-scope uses, safeguards, guardrails, and testing thereof; (8) internal risk assessment with testing documentation and results covering algorithmic discrimination, validity and reliability, privacy and autonomy, and safety and security risks, plus actions taken and subsequent testing; and (9) monitoring requirements.
VT
Introduced eff 2025-07-01
Deployers must file with the Attorney General a report containing: (1) system description including software stack, purpose, expected benefits, current and intended uses, impacted stakeholders; (2) intended outputs and whether they may be used beyond articulated purposes; (3) revenue and monetization disclosures; (4) whether the system makes consequential decisions autonomously or supports human decision-making; (5) system capabilities and deployer-imposed limitations including out-of-scope uses, safeguards, guardrails, and testing thereof; (6) cost-benefit assessment for consumers given system purpose, capabilities, and probable use cases; (7) internal risk assessment with testing documentation and results covering algorithmic discrimination, accuracy and reliability, privacy and autonomy, and safety and security risks, plus actions taken and subsequent testing; and (8) monitoring requirements.
VT
VT HB 341 (AI Safety Standards) § 9 V.S.A. § 4193e
Introduced eff 2025-07-01
Deployers must submit an AI System Safety and Impact Assessment to the Division of Artificial Intelligence prior to deploying any inherently dangerous AI system in Vermont and every two years thereafter. Deployers must also submit an updated assessment whenever a material and substantial change is made to the system's purpose or the type of data the system processes or uses for training.
VT
VT HB 341 (AI Safety Standards) § 9 V.S.A. § 4193e
Introduced eff 2025-07-01
Deployers must ensure each AI System Safety and Impact Assessment includes all 13 enumerated categories: (1) system purpose; (2) deployment context and intended use cases; (3) benefits of use; (4) foreseeable risks of unintended or unauthorized uses and mitigation steps; (5) whether the model is proprietary; (6) description of training data; (7) whether training data has been processed to remove personal information, copyrighted information, and do-not-train data; (8) transparency measures including identifying to individuals when the system is in use; (9) identification of third-party AI systems or datasets relied on; (10) whether the developer disclosed testing results, vulnerabilities, and safe-use parameters; (11) description of post-deployment input data; (12) post-deployment monitoring and user safeguards including the oversight process; and (13) how the model impacts consequential decisions or biometric data collection.
VT
Introduced eff 2025-07-01
Providers must submit a description of the AI model to the Secretary of State as part of annual registration, including the model's capacity, training data, intended use, design process, and methodologies.
CA
CA AB 331 (Automated Decision Tools) § Bus. & Prof. Code § 22756.7
Failed
Deployers and developers must submit each completed impact assessment to the Civil Rights Department within 60 days of its completion.
FL
Failed
The Division of Emergency Management must submit a report to the Legislature by November 15, 2026, covering the pilot program's results, scalability findings, and recommendations for broader government use of provenance data.
GA
GA HB 1651 (Automated Decision-Making Commission) § O.C.G.A. § 50-1-11(b)(11)–(12)
Failed
The Commission must file a report of its survey findings on state automated decision system use with the Clerk of the House, Secretary of the Senate, and designated committee chairs by March 31, 2023, and publish the report on the commission's website.
GA
GA HB 1651 (Automated Decision-Making Commission) § O.C.G.A. § 50-1-11(b)(11)–(12)
Failed
The Commission must file a recommendations report, together with drafts of legislation necessary to implement those recommendations, with the Clerk of the House, Secretary of the Senate, and designated committee chairs by December 31, 2023, and publish the report on the commission's website.
HI
Failed
Covered entities must annually submit to the Department of the Attorney General, on a prescribed form, a report containing the audit results including: types of algorithmic determinations made, data and methodologies, optimization criteria, training data and sources, performance metrics including accuracy and confidence intervals, impact assessment results, rationale for each decision, complaints received, and any reliance on the affirmative-action exemption. A covered entity may substitute a report previously filed with another government entity if it contains the required information or is supplemented.
HI
Failed
The Office of Enterprise Technology Services must submit to the legislature a report on the potential risks and benefits of using generative AI for state purposes — covering beneficial uses, risks to individuals and communities, cybersecurity breach risks, and emerging technology developments — no later than twenty days before the 2025 regular session and as often thereafter as necessary.
HI
Failed
Covered entities must annually submit to the Department of the Attorney General a structured report containing audit results, including determination types, data and methodologies, optimization criteria, training data sources, rendering methodologies, performance metrics, impact assessment results and methodology, rationale for design decisions, complaint history, and any reliance on the affirmative-action exemption. An equivalent report previously submitted to another government entity may be substituted if it contains or is supplemented with all required information.
HI
Failed
Covered entities must annually submit to the Department of the Attorney General a report containing the full results of the mandated bias audit — including determination types, algorithm methodologies and optimization criteria, training data and sources, performance metrics, impact assessment results and rationale, complaint history, and any reliance on the affirmative action exemption. A previously filed federal or state report may substitute if it contains or is supplemented to contain all required information.
IL
Failed
Deployers must submit each completed impact assessment to the Department of Human Rights within 60 days of completion. Each day the automated decision tool is used without a submitted assessment constitutes a distinct violation subject to up to $10,000 per violation in administrative fines for knowing violations.
IL
Failed
Deployers must submit each completed impact assessment to the Attorney General within 60 days of completion. Knowing failure to submit subjects the deployer to administrative fines of up to $10,000 per violation; each day an automated decision tool is used without the required impact assessment submission constitutes a separate violation.
MD
MD HB 1271 (AI Governance Act of 2024) § Md. Code, State Fin. & Proc. § 3.5–802
Failed
Each public senior higher education institution and Baltimore City Community College must (1) establish functionally compatible AI governance policies for research/academic high-risk AI by June 1, 2025, and (2) submit an annual report to the Department by September 1, 2025, and each year thereafter, on all high-risk AI procured and deployed for research or academic purposes.
MD
MD HB 1271 (AI Governance Act of 2024) § Section 2 (uncodified)
Failed
The Governor's AI Subcabinet must develop a roadmap reviewing AI risks and opportunities across State services and submit it to the Governor and General Assembly by December 1, 2024, covering twelve enumerated study domains, stakeholder identification, prioritization methodology, and projected timelines.
MD
MD HB 1271 (AI Governance Act of 2024) § Section 3 (uncodified)
Failed
The AI Subcabinet must submit a report to the Governor and General Assembly by December 1, 2025, evaluating whether the Subcabinet structure is sufficient to accomplish the State's AI goals and whether it should be elevated to a department or independent unit.
MD
MD HB 697 (Health Insurance AI Reporting) § Md. Code Ann., Ins. § 15–147
Failed
Health insurance carriers must submit quarterly reports to the Maryland Insurance Commissioner on their creation, deployment, and use of AI or automated decision-making systems, including: purpose of use, person responsible for training, major data sources and methods, guidance used to make recommendations and alignment of outcomes with human expectations, and bias testing results and remediation steps taken.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-510
Failed
Law enforcement agencies must submit their annual facial recognition technology report to the Governor's Office of Crime Prevention, Youth, and Victim Services by May 1 each year.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–510
Failed
Law enforcement agencies must submit their annual facial recognition report to the Governor's Office of Crime Prevention, Youth, and Victim Services by May 1 each year.
MN
Failed
Judges must report to the Minnesota Supreme Court within 30 days after issuing, modifying, or denying a covered court order or extension authorizing facial recognition surveillance, including the disposition, authorized duration, and specified offense.
MN
MN HF 465 (Facial Recognition Technology) § Minn. Stat. § 626A.52
Failed
Issuing or denying judges must report to the Minnesota Supreme Court within 30 days after issuing a covered court order, extension, or denial, disclosing the application type, disposition, authorized duration, and underlying offense.
MT
Failed
State or local government agencies must report their use of facial recognition technology to the information technology board.
NC
Failed
Operators must annually submit a digital copy of the platform's privacy policy and a compliance certification to the Consumer Protection Division of the NC Department of Justice, beginning October 1, 2024. Substantive privacy policy changes must be reported to the registry.
NC
Failed
Covered platforms must submit to the Online Safety Division an annual Child Impact Assessment for new and existing services, including documentation of potential risks to children and assessment of addiction and compulsive usage risks, and must retain supporting documentation for at least three years.
NC
Failed
Covered platforms must submit to the Online Safety Division an annual Child Impact Assessment for new and existing services, documenting potential risks to children and assessing addiction and compulsive usage risks. Documentation supporting each annual assessment must be retained for at least three years.
NE
Failed eff 2027-01-01
Large frontier developers must transmit to the Attorney General a summary of any assessment of catastrophic risk resulting from internal use of their frontier models no less frequently than every three months. Submission must use the confidential mechanism established by the Attorney General.
NJ
Failed
Automobile insurers using automated or predictive underwriting systems must annually submit documentation and analysis to the Department of Banking and Insurance demonstrating (1) no discriminatory outcome in pricing on the basis of race, ethnicity, sexual orientation, or religion, and (2) that each pricing segment is balanced and not disproportionate to the overall policyholder population.
NV
Failed eff 2026-01-01
Each law enforcement agency must submit its AI use policy and any updates to the Bureau of Consumer Protection in the Office of the Attorney General.
NY
Failed
Employers must annually submit to the Department of Labor a summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
Failed
Employers must annually submit to the Department of Labor a summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
NY AB 8105 (AI User Oath Requirement) § Gen. Bus. Law § 394-cccc(4)
Failed
Operators must submit a copy of each collected user oath to the Attorney General within 30 days of the user making the oath, in the form and manner designated by the Attorney General.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 410
Failed
Any person developing an autonomous weapons AI system in New York must disclose in writing to the Secretary of State — prior to active development — the names and addresses of all persons involved, a description of the system, its functions and intended use cases, and the risk mitigation measures to be taken.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 413
Failed
License applicants must submit a written, sworn application disclosing the applicant's identity, the names and addresses of all ethics and risk management board members, principals, and officers, and a description of all known general use cases of the AI system.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 416
Failed
Operators must annually submit to the secretary a comprehensive report for each licensed system covering all possible use cases, risk assessments, ethical evaluations, mitigation plans, incident reviews, user education plans, board conflict-of-interest disclosures, and compliance updates.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 419
Failed
Licensees must notify the secretary in writing before implementing any source code modification or upgrade, including the purpose, new functions, reasons, and risk assessment, and must obtain the secretary's express written approval before deploying the change. Updates (minor enhancements, bug fixes) are exempt.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 427
Failed
Operators must annually file a sworn report with the secretary covering business and operations during the preceding calendar year, and must file additional regular or special reports as the secretary requires.
NY
Failed
Employers must annually submit to the Department of Labor a summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
Failed
Large frontier developers must transmit to the Office confidential summaries of catastrophic risk assessments resulting from internal use of their frontier models every three months, or on an alternative schedule agreed in writing with the Office.
NY
NY SB 8206 (AI User Oath of Responsible Use) § Gen. Bus. Law § 394-cccc(4)
Failed
Operators must submit a copy of each user oath to the Attorney General within 30 days of the user making the oath, in the form and manner designated by the Attorney General.
NY
Failed
Employers must submit the AI impact assessment to the Department of Labor at least 30 days before implementing the artificial intelligence that is the subject of the assessment.
OK
Failed
Sandbox participants must submit periodic progress reports and a final evaluation to the AI Council detailing the system's performance, risks identified, and mitigation measures taken.
OK
OK HB 3577 (AI Utilization Review) § 36 O.S. § 6980.3
Failed
Insurers must submit their AI-based algorithms and training data sets used in utilization review to the Oklahoma Insurance Department, and must annually certify by December 31 that these algorithms and data sets minimize bias across protected characteristics and adhere to evidence-based clinical guidelines.
PA
Failed
Insurers must submit their artificial intelligence-based algorithms and training data sets used or to be used in utilization review to the Insurance Department for bias certification and evidence-based clinical guideline adherence review.
TX
TX SB 1822 (AI in Utilization Review) § Ins. Code § 4201.156
Failed
Health insurance issuers and their utilization review agents must submit to the Texas Department of Insurance by December 31 of each year an AI compliance statement that (1) summarizes each AI algorithm's function and scope, (2) provides a logic or decision tree, (3) describes each training data set and its source, (4) attests to bias minimization and evidence-based clinical guideline compliance, and (5) describes the oversight and validation process.
US
Failed
Each covered agency's civil rights office must submit a biennial report to its congressional oversight committees — beginning one year after enactment — detailing the state of covered-algorithm technology and associated bias risks, mitigation steps taken, stakeholder engagement activities, and legislative or administrative recommendations.
US
Failed
The Federal Reserve Board, FDIC Board, Comptroller of the Currency, CFPB Director, and NCUA Board must, within 180 days of enactment, jointly submit to congressional committees and publish publicly a report examining AI benefits and risks in banking, including regulatory proposals and legislative recommendations, and must publish a request for information to collect public input.
US
Failed
The SEC must, within 180 days of enactment, submit to congressional committees and publish publicly a report examining AI benefits and risks in securities markets, including regulatory proposals and legislative recommendations, must publish a request for information, and must consult with self-regulatory organizations.
US
Failed
HUD, the Rural Housing Service, FHFA, and the CFPB must, within 180 days of enactment, submit to congressional committees and publish publicly a report examining AI benefits and risks in housing and mortgage markets, including regulatory proposals and legislative recommendations, and must publish a request for information.
US
Failed
The Secretary of the Treasury must, within 180 days of enactment, submit to congressional committees and publish publicly a report examining AI benefits and risks related to financial system national security (including Bank Secrecy Act compliance, sanctions, and cybersecurity), including regulatory proposals and legislative recommendations, must publish a request for information, and must consult with the five banking regulators.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to deployment.
US
Failed
Covered entities must include in each summary report submitted to the FTC: entity identification and contact information, a description of the critical decision category, the system's intended purpose, stakeholder consultation documentation, performance testing and differential-performance results, publicly stated use restrictions, data provenance information, transparency and explainability measures including consumer opt-out mechanisms, identified negative impacts and remediation steps, infeasible assessment requirements and rationale, and identified resource needs.
US
Failed
State agencies must forward the information collected from state judges and prosecutors to the Director of the Bureau of Justice Assistance and the Director of the Administrative Office of the United States Courts within 90 days of receipt, and annually thereafter.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each ongoing deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to its deployment.
US
Failed
Covered entities must include in each summary report to the FTC: entity identification, a description of the critical decision and its category, intended purpose, stakeholder consultation records, testing and evaluation results (including differential performance), publicly stated guardrails, data sourcing documentation, transparency and explainability measures, identified material negative impacts with remediation steps, infeasible assessment requirements with rationale, and improvement needs.
US
Failed
Covered entities must submit specified foundation model transparency information to the FTC as defined in the Commission's regulations.
US
Failed
The Secretary of the Treasury, the Secretary of Homeland Security, and the Secretary of Commerce must jointly submit to Congress, within 180 days of enactment and annually thereafter, a report describing interagency policies to defend U.S. financial markets from AI-enabled financial crimes and an itemized resource list needed to combat those risks, covering deepfakes, voice cloning, foreign election interference, synthetic identities, false market signals, and overall digital fraud.
US
Failed
The Secretary of the Treasury, the Secretary of Homeland Security, and the Secretary of Commerce must jointly submit to Congress, within 90 days of each annual report, legislative recommendations and best practices for businesses and government entities to mitigate risks and respond to incidents involving AI-enabled financial crimes.
US
Failed
Each covered agency's privacy and civil liberties officer must submit an annual report to Congress on the results of accredited AI system testing, covering the potential privacy, civil rights, and civil liberties effects of the agency's AI systems.
US
Failed
Each agency head must inform the relevant congressional committees of the CAIO appointment within one year of enactment and, if the CAIO holds dual responsibilities, provide a full description of any additional authorities and responsibilities the individual performs.
US
Failed
The Comptroller General must submit to the relevant congressional committees within two years of enactment a report on the implementation and effectiveness of AI Governance Boards and CAIOs, including recommendations for improvement.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to its deployment.
US
Failed
Covered entities must include in each summary report submitted to the FTC: entity identification and contact information, description of the critical decision and its category, intended purpose, stakeholder consultation documentation, performance testing results and differential performance evaluations, publicly stated use restrictions, data sourcing documentation, transparency and explainability measures, identified material negative impacts and remediation steps, infeasible assessment requirements with rationale, and identified improvement resources. Reports must follow FTC-specified format and include FTC-determined consumer-protection criteria.
US
Failed
The Director of OMB must brief the appropriate congressional committees on implementation of the AI Hygiene Working Group requirements — quarterly beginning 90 days after enactment through implementation, and annually thereafter.
US
Failed
Deployers of high-impact AI systems must submit to the Secretary of Commerce, before deployment and annually thereafter, a transparency report covering the system's purpose, intended use cases, deployment context, data inputs, training data, performance metrics, transparency measures, pre-deployment testing, third-party dependencies, and post-deployment monitoring. Updated reports must be submitted upon material changes to purpose or training data. Deployers must consider the NIST AI Risk Management Framework.
US
Failed
Each covered agency's office of civil rights must submit a biennial report to its congressional oversight committees detailing the state of algorithmic technology within the agency's jurisdiction (including bias and discrimination risks), mitigation steps taken, stakeholder engagement actions, and recommendations for legislation or administrative action.
US
US S 3554 (Financial AI Risk Reduction) § Sec. 3 / proposed 12 U.S.C. § 126(a)
Failed
FSOC must, within 180 days of enactment and in consultation with member agencies, financial institutions, and securities market participants, submit a report to the Senate Banking and House Financial Services committees identifying AI threats, regulatory gaps, and specific recommendations for closing those gaps.
US
US S 3554 (Financial AI Risk Reduction) § Sec. 5 / proposed 12 U.S.C. § 1329
Failed
Regulated entities and the Office of Finance must notify the FHFA Director of any outsourced service relationship within 30 days of the earlier of executing the service contract or the service provider commencing performance.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each ongoing deployed automated decision system or augmented critical decision process and (2) an initial summary report prior to deploying any new system or process.
US
Failed
Covered entities must include in each summary report submitted to the FTC: entity identity and contact information, description of the critical decision and its category, intended purpose, stakeholder consultation records, testing and evaluation documentation including differential performance results, publicly stated use restrictions, data sourcing documentation, transparency and explainability measures, identified material negative impacts and remediation steps, infeasibility rationale, and identified improvement needs, in the format specified by the Commission.
US
Failed
Developers and deployers must (1) submit all full pre-deployment evaluations, full impact assessments, and developer annual reviews to the FTC within 30 days of completion, (2) publish a summary on their website within 30 days, (3) submit the summary to the FTC, (4) make evaluations available to Congress upon request, and (5) retain all evaluations, assessments, and reviews for at least 5 years. Trade secrets may be redacted; personal data must be redacted from public disclosures.
US
Failed
The Secretary of Defense must submit annual progress reports to Congress on implementation of the ledger and risk assessment process, beginning one year after enactment and continuing until three years after enactment.
US
Failed
The Secretary of Defense must submit to Congress annually, beginning three years after enactment, the complete AI ledger, a report on risk assessment findings for the covered year, and all export annotations made during the year. Submissions must be unclassified to the fullest extent possible, with a classified annex permitted where necessary.
UT
UT HB 286 (AI Transparency Act) § Utah Code § 13-72b-106
Failed eff 2026-05-06
Large frontier developers must submit quarterly reports to the Office of Artificial Intelligence Policy summarizing assessments of catastrophic risk resulting from internal use of their frontier models. An alternate schedule may be requested in writing and agreed to by the office.
UT
UT HB 329 (AI in Political Advertising) § Utah Code § 20A-11-901
Failed
A non-reporting-entity person who pays for an electioneering communication that qualifies as a generative A.I. political advertisement must include a statement in the 24-hour report filed with the lieutenant governor disclosing that the communication is a generative A.I. political advertisement.
UT
UT SB 149 (AI Policy Act) § Utah Code § 13-70-304
Failed
Learning Laboratory participants must provide required information to state agencies and report to the Office of Artificial Intelligence Policy as specified in the participation agreement.
VA
Failed
The Attorney General must submit an annual report (not exceeding eight pages) to the Joint Commission on Technology and Science by December 1 each year, summarizing complaint intake activity, enforcement referral patterns, interagency coordination, emerging trends, and legislative recommendations.
VT
Failed
Deployers must submit an AI System Safety and Impact Assessment to the Division of Artificial Intelligence before deploying any inherently dangerous AI system in Vermont, every two years thereafter, and upon any material change to system purpose or training data. The assessment must cover purpose, deployment context, benefits, foreseeable risks and mitigations, proprietary status, training data description, transparency measures, third-party dependencies, developer disclosures, post-deployment monitoring, and impact on consequential decisions or biometric data.
WA
Failed
Public agencies intending to develop, procure, or use a new automated decision system between the effective date and January 1, 2024 must produce and file an algorithmic accountability report with the applicable algorithmic accountability review office at least one month prior to procurement or implementation.
R-02.2
On-demand production upon regulatory request
Deployers must produce requested AI-system documentation — including risk-management policies, impact assessments, model and dataset cards, and related records — to a regulator within the required timeframe, and must keep such documentation in a form that can be assembled and produced promptly.
Enacted
8
Live
57
Failed
38
Total
103
CO
Enacted eff 2026-02-01
Developers must produce documentation to the Attorney General within 90 days of a request, covering the statements and documentation required under subsection (2). Materials are exempt from Colorado Open Records Act disclosure and may be designated as trade secret or proprietary.
CO
Enacted eff 2026-02-01
Deployers must produce to the Attorney General within 90 days of a request the risk management policy, impact assessments, and associated records. Materials are exempt from Colorado Open Records Act disclosure and may be designated as trade secret or proprietary.
CO
Enacted eff 2026-02-01
Developers must, upon request by the attorney general, disclose to the attorney general within 90 days the deployer documentation described in subsection (2). The AG may evaluate the documentation for compliance. The documentation is not subject to Colorado Open Records Act disclosure. Developers may designate materials as proprietary or trade secret, and disclosures of privileged or work-product-protected material do not constitute waiver.
CO
Enacted eff 2026-02-01
Deployers must, upon request by the attorney general, disclose to the attorney general within 90 days the risk management policy, impact assessment, or retained records. The AG may evaluate these materials for compliance. Materials are not subject to Colorado Open Records Act disclosure. Deployers may designate materials as proprietary or trade secret, and disclosures of privileged or work-product-protected material do not constitute waiver.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 552.103
Enacted eff 2026-01-01
Upon receipt of a civil investigative demand from the attorney general, developers and deployers must produce documentation including: a high-level description of the AI system's purpose, intended use, deployment context, and associated benefits; the type of data used for training; the categories of input data; the system's outputs; performance metrics; known limitations; post-deployment monitoring and user safeguards (including, for deployers, oversight and learning processes); and any other relevant documentation reasonably necessary for the investigation.
TX
Enacted eff 2025-09-01
Utilization review agents must make their automated decision systems used for utilization review available for audit and inspection by the Commissioner of Insurance at any time.
VA
Enacted eff 2026-07-01
Developers and deployers must comply with civil investigative demands from the Attorney General by producing requested information, statements, or documentation. Trade secrets may be redacted with an affirmative statement to the AG that the basis is trade secret protection. Attorney-client privileged materials are protected from waiver. All materials provided are exempt from FOIA disclosure.
VA
Enacted eff 2026-07-01
Developers must disclose to the Attorney General any statement or documentation described in the chapter when relevant to an AG investigation. Deployers must disclose risk management policies, impact assessments, and records maintained under the chapter when relevant to an AG investigation.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.4
Engrossed
Developers, deployers, and auditors must provide an unredacted copy of any performance evaluation or impact assessment to the Attorney General within 30 days of request. Disclosure does not waive attorney-client privilege, work-product protection, or trade secret protection. Documents are exempt from the California Public Records Act. Each day of continued ADS use without submission after an AG request constitutes an additional violation.
CA
CA SB 295 (Algorithmic Collusion) § Bus. & Prof. Code § 17372
Engrossed
Persons using or distributing pricing algorithms must, within 30 days of a written request from the Attorney General, provide information related to their pricing algorithms.
CA
CA SB 295 (Algorithmic Collusion) § Bus. & Prof. Code § 17372
Engrossed
A senior corporate officer (CEO, chief economist, CTO, or officer of similar authority) must certify the accuracy of any report submitted to the Attorney General regarding pricing algorithms.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.1
Engrossed eff 2026-01-01
State agencies must require developers of high-risk automated decision systems deployed by the state agency to provide a copy of the impact assessment to the state agency. The impact assessment provided to the state agency must be kept confidential.
CA
CA SB 420 (Automated Decision Systems) § Bus. & Prof. Code § 22756.6
Engrossed eff 2026-01-01
Developers must provide to the Attorney General or Civil Rights Department, within 30 days of a request, a copy of any impact assessment performed under this chapter. Impact assessments provided under this subdivision must be kept confidential.
IL
Engrossed
Health insurance issuers must comply with Department of Insurance requests for information and documentation relating to AI systems and predictive models, including documentation on AI systems governance, risk management, and use protocols; preacquisition and preutilization diligence, monitoring, and auditing of third-party AI systems and data; and implementation and compliance with the issuer's AI systems program. This includes responding to inquiries regarding any specific model, AI system, or application thereof during investigations or market conduct actions.
NY
Engrossed
Developers and deployers must disclose their risk management policy and program to the attorney general in a form and manner prescribed by the attorney general upon the attorney general's request. The attorney general may evaluate the program for compliance.
RI
RI SB 13 (Health Insurer AI Transparency) § R.I. Gen. Laws § 27-83-3
Engrossed eff 2026-06-30
Insurers must submit to OHIC and DBR, upon request, all information, documents, and software that permits enforcement of this chapter.
RI
RI SB 2010 (AI in Health Insurance) § R.I. Gen. Laws § 27-84-3
Engrossed
Insurers must produce to OHIC and DBR, on request, all information, documents, and software necessary to permit enforcement of the chapter.
VA
VA SB 586 (Health Carrier AI Disclosures) § Va. Code § 38.2-3407.15(B)(15)
Engrossed
Carriers must submit to the Bureau of Insurance, upon request, all information — including documents and software — necessary for enforcement of the AI disclosure requirements.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2104
Introduced eff 2026-01-01
Healthcare insurers must submit to the Insurance Commissioner data on the amount of time a human reviewer spends examining each adverse determination before signing off on a denial, in the form and manner the Commissioner requires.
CA
Introduced
Electrical and gas corporations must file a compliance plan with the commission demonstrating compliance with the adopted AI standards. The commission may request records to verify compliance. Plans filed by electrical corporations must be reviewable by the Office of Energy Infrastructure Safety to ensure AI models used for wildfire mitigation are consistent with the corporation's wildfire mitigation plan.
GA
Introduced
Developers must produce any documentation or records required by this section to the Attorney General within seven days of a request, in a form and manner prescribed by the Attorney General. Records disclosed are exempt from Georgia's open-records requirements. Developers may designate materials as proprietary or trade secret, and disclosure does not waive attorney-client privilege or work-product protection.
GA
Introduced
Deployers (or contracted third parties) must produce any documentation or records required by this chapter to the Attorney General within seven days of a request, in a form and manner prescribed by the Attorney General. Records disclosed are exempt from Georgia's open-records requirements. Deployers may designate materials as proprietary or trade secret, and disclosure does not waive attorney-client privilege or work-product protection.
IA
Introduced
Developers must produce to the attorney general any statement or documentation required under the deployer-disclosure provisions when requested in connection with an investigation, subject to trade secret, proprietary information, and attorney-client privilege protections. Disclosure to the attorney general does not waive privilege or work-product protection.
IL
Introduced
Developers that redact published documents must retain unredacted versions for at least 5 years and make them available to the Attorney General upon request, and must describe the character and justification of each redaction in the published version.
IN
Introduced eff 2026-07-01
Employers must file annual or special reports with the Indiana Department of Labor when required, on prescribed forms, answering specific questions about their use of automated decision systems for employment decisions. Employers must also maintain, keep, preserve, and make available to the department all records pertaining to compliance with this chapter.
LA
Introduced
Covered insurers must, upon request during a market conduct examination, provide the Commissioner with AI governance documentation, access to algorithmic systems and data, complete disparate impact audit reports, and demonstrations of system explainability. Insurers bear the cost of independent experts retained by the Commissioner.
LA
Introduced eff 2026-08-01
Upon request of the Commissioner of Insurance, health insurance issuers must disclose the data sources, training parameters, and validation methods used to develop any AI or automated decision system used in coverage determinations.
MA
Introduced
Developers must, upon request by the attorney general, disclose the documentation described in Section 2(b) no later than 90 days after the request in the form and manner prescribed by the attorney general. Developers may designate materials as proprietary or trade secret. Disclosures are exempt from the Massachusetts Public Records Law and do not waive attorney-client privilege or work-product protection.
MA
Introduced
Deployers must, upon request by the attorney general, disclose the risk management policy, impact assessments, and associated records no later than 90 days after the request in the form and manner prescribed by the attorney general. Deployers may designate materials as proprietary or trade secret. Disclosures are exempt from the Massachusetts Public Records Law and do not waive attorney-client privilege or work-product protection.
MI
Introduced eff 2026-01-01
Large developers must publish all compliance documents required by this act on a conspicuous page on their website. If redacting any document to protect trade secrets, public safety, national security, or to comply with applicable law, the large developer must: (1) retain the unredacted version for at least five years and provide the attorney general with the ability to inspect it on request, and (2) describe the character and justification of redactions in the published version. The same redaction and retention requirements apply to auditors publishing audit reports.
MO
Introduced
Contracting entities and vendors must provide the state board of education access to all records, documents, and data necessary for compliance audits and vendor reviews. Following each audit, the state board must issue a written compliance report identifying noncompliance findings, required corrective actions, and remediation timelines. The board may publish summary audit findings for public transparency.
NJ
Introduced
The Office of Information Technology must review each annual safety test report submitted by an artificial intelligence company.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 517
Introduced
Operators must submit to periodic Secretary-initiated evaluations of their source code and system outcomes. Following the Secretary's binding recommendations, operators must consult with the Secretary on implementation feasibility, provide a detailed implementation plan with a timeline, and comply with that plan. Amendments to the plan require written notice to the Secretary describing the unexpected occurrence and proposed changes; the Secretary has 30 days to approve or reject amendments. If amendments are rejected, the operator must proceed with the original plan.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 526
Introduced
Licensees must cooperate with Secretary-initiated investigations and examinations by producing all relevant books, records, accounts, documents, source code, and logs, and by making persons available for examination under oath. Licensees must pay all expenses incurred in any examination, including proportionate shares of travel and subsistence costs, upon written notice of the assessment from the Secretary.
NY
Introduced
Developers must, to the extent feasible, make available to deployers and other developers the documentation and information necessary for the deployer (or a third party contracted by the deployer) to complete an impact assessment under this article. Documentation must be delivered through model cards, dataset cards, or other impact assessments. A developer that also serves as deployer for the same system is not required to generate this documentation unless the system is provided to an unaffiliated deployer.
NY
Introduced
Developers must, upon request by the attorney general as part of an investigation, disclose to the attorney general the general statement and documentation described in subdivision 2 of this section, in a form and manner prescribed by the attorney general. The developer may designate trade secret, security-sensitive, or FOIL-exempt information, and such information shall be exempt from public disclosure. Attorney-client privilege and work product protection are preserved and not waived by disclosure.
NY
Introduced
Deployers (or their contracted third parties) must, upon AG request as part of an investigation, disclose to the attorney general within 90 days the risk management policy, the impact assessment, and records maintained under § 1552. Deployers may designate trade secret, FOIL-exempt, or legally protected information, and such information shall be exempt from public disclosure. Attorney-client privilege and work product protection are preserved.
NY
Introduced
Developers of general-purpose AI models must, upon AG request as part of an investigation, disclose to the attorney general within 90 days any documentation maintained under § 1553, in a form and manner prescribed by the AG. Developers may designate trade secret, FOIL-exempt, or legally protected information, and such information shall be exempt from public disclosure. Attorney-client privilege and work product protection are preserved.
NY
Introduced
Covered entities must comply with investigations by the Superintendent, including producing all relevant books, records, accounts, and documents upon demand and making individuals available for examination under oath.
NY
Introduced
Developers must produce, within 30 days of service (or upon entry of a protective order for trade secrets), records sufficient to identify with certainty the text and data from a journalism provider's content used to train the developer's generative AI system, including URLs accessed, dates and times of collection, and provenance information, when served with a subpoena requested by a journalism provider.
NY
Introduced
Developers must, upon request by the attorney general as part of an investigation, disclose the general statement or documentation described in subdivision 2 of this section, in a form and manner prescribed by the attorney general. The developer may designate trade-secret, FOIL-exempt, or attorney-client privileged information, which shall be exempt from public disclosure. Disclosure to the AG does not waive privilege or work-product protection.
NY
Introduced
Deployers must, upon request by the attorney general as part of an investigation, disclose the risk management policy, impact assessment, or records maintained under this section no later than 90 days after the AG's request, in the form and manner prescribed by the AG. The deployer may designate trade-secret, FOIL-exempt, or privileged information, which shall be exempt from public disclosure. Disclosure to the AG does not waive attorney-client privilege or work-product protection.
NY
Introduced
Developers of general-purpose AI models must, upon request by the attorney general as part of an investigation, disclose any documentation maintained under this section no later than 90 days after the AG's request, in the form and manner prescribed by the AG. The developer may designate trade-secret, FOIL-exempt, or privileged information, which shall be exempt from public disclosure. Disclosure to the AG does not waive attorney-client privilege or work-product protection.
NY
Introduced
Deployers and developers must, upon request by the Attorney General, produce all impact assessments performed under this article within 45 days. Attorney-client privilege, work-product protection, and trade secret exemptions from FOIL are preserved.
NY
Introduced
Insurance carriers authorized to do business in New York must provide DFS access to their underwriting models — including any algorithm, formula, or structured methodology used to assess risk, determine premiums, or evaluate coverage eligibility — upon request of the Superintendent, through mutually agreed department staff.
NY
Introduced
Insurance carriers must, when underwriting models are not available, provide DFS access to granular claim data — including claim type, amount, date, geographic location, and resolution status — sufficient to allow the department to evaluate the carrier's underwriting practices and risk assessment methodologies.
OH
OH SB 79 (Pricing Algorithms) § R.C. § 1331.16
Introduced
Persons subject to an Attorney General investigative demand must produce information on the development or distribution of a pricing algorithm, including the identity of the person responsible for development or distribution and how the pricing algorithm works.
PA
Introduced
Facilities must produce additional information and evidence to the Department of Health upon request regarding their AI disclosure, responsible-use, and compliance-statement obligations.
PA
Introduced
Insurers must produce additional information and evidence to the Insurance Department upon request regarding their AI disclosure, responsible-use, and compliance-statement obligations.
PA
Introduced
MA or CHIP managed care plans must produce additional information and evidence to the Department of Human Services upon request regarding their AI disclosure, responsible-use, and compliance-statement obligations.
PA
Introduced
Facilities must produce additional information and evidence regarding their AI disclosures, responsible use, and compliance statements when requested by the Department of Health.
PA
Introduced
Insurers must produce additional information and evidence regarding their AI disclosures, responsible use, and compliance statements when requested by the Insurance Department.
PA
Introduced
MA or CHIP managed care plans must produce additional information and evidence regarding their AI disclosures, responsible use, and compliance statements when requested by the Department of Human Services.
RI
RI HB 5172 (Health Insurer AI Transparency) § R.I. Gen. Laws § 27-83-3
Introduced
Insurers must submit to the OHIC and EOHHS, upon request, all information — including documents and software — that permits enforcement of this chapter.
RI
RI HB 7190 (AI Use by Health Insurers) § R.I. Gen. Laws § 27-84-3
Introduced
Insurers must submit to OHIC and DBR, upon request, all information including documents and software that permits enforcement of this chapter.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-3
Introduced eff 2025-10-01
Developers must produce documentation to the attorney general upon request as part of an investigation, with trade secret and attorney-client privilege protections preserved.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-5
Introduced eff 2025-10-01
Deployers must produce risk management policies, impact assessments, and related records to the attorney general within 90 days of a request as part of an investigation, with trade secret and attorney-client privilege protections preserved.
RI
RI SB 627 (Artificial Intelligence Act) § R.I. Gen. Laws § 6-61-6
Introduced eff 2025-10-01
Developers of general-purpose AI models must produce technical documentation to the attorney general within 90 days of a request as part of an investigation, with trade secret and attorney-client privilege protections preserved.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-20
Introduced
Developers must, upon request by the Attorney General, disclose the documentation described in subsection (B) within 90 days, in a form and manner prescribed by the Attorney General. Developers may designate materials as proprietary or trade secret. Attorney-client privilege and work-product protection are preserved; disclosure to the AG does not constitute waiver. Documents produced are not subject to disclosure under the South Carolina Freedom of Information Act.
SC
SC SB 963 (AI Consumer Protection) § S.C. Code § 37-31-30
Introduced
Deployers must, upon request by the Attorney General, disclose within 90 days the risk management policy, impact assessment, or records maintained under Section 37-31-30, in a form and manner prescribed by the Attorney General. Deployers may designate materials as proprietary or trade secret. Attorney-client privilege and work-product protection are preserved; disclosure does not constitute waiver. Documents produced are not subject to disclosure under the South Carolina Freedom of Information Act.
TX
TX HB 2922 (AI in Utilization Review) § Ins. Code § 4201.156(b)
Introduced eff 2025-09-01
Utilization review agents must make their use of artificial intelligence for utilization review available for audit and inspection by the Commissioner of Insurance at any time.
US
Introduced
Persons using or distributing a pricing algorithm must, within 30 days of a written request from the Attorney General or FTC, produce a written report covering the algorithm's developer/distributor identity, whether the algorithm sets prices autonomously, the rules and data inputs used, data sources and collection frequency, whether the algorithm engages in price or wage discrimination, and any algorithm changes made between request receipt and report certification.
US
Introduced
A senior corporate officer (CEO, Chief Economist, CTO, or officer of similar authority) must certify the accuracy of each pricing algorithm audit report under penalty of perjury.
US
Introduced
Covered advanced AI system developers must provide to the Secretary of Energy, on request, materials necessary to carry out the evaluation program, including underlying code, training data, model weights, interface engines, and detailed information regarding training and model architecture.
US
Introduced
Covered entities must make, keep, preserve, and make available to the Secretary of Labor records pertaining to compliance with Title II, and must file annual or special reports as the Secretary may require.
CA
CA AB 2811 (Attorney AI Disclosure Affidavit) § Bus. & Prof. Code § 6068.1
Failed
Attorneys must file the AI compliance affidavit with the court upon request or order by a California state or federal court, provided the seven-year retention period has not expired.
CA
CA AB 2930 (Automated Decision Tools) § Bus. & Prof. Code § 22756.7
Failed
Deployers and developers must produce any impact assessment to the Civil Rights Department within seven days of request. Failure to comply subjects the entity to an administrative fine of up to $10,000 per violation, with each day of continued noncompliance constituting a separate violation. Attorney-client privilege and work-product protections are preserved; trade secrets are exempt from public records disclosure.
CA
CA SB 1154 (Algorithmic Collusion) § Bus. & Prof. Code § 17372
Failed
Persons using or distributing pricing algorithms must, within 30 days of a written AG request, produce a detailed written report on each identified pricing algorithm — covering algorithm provenance, autonomy level, decision logic, all data inputs and sources, price discrimination practices, and any changes since the request date — certified under penalty of perjury by a C-suite officer.
CO
Failed
Developers must produce documentation to the attorney general within ninety days of request, in the form and manner prescribed. Developers may designate materials as proprietary or trade secret, and attorney-client privilege is preserved.
CO
Failed
Deployers must produce to the attorney general, within ninety days of request, the risk management policy, impact assessment, or associated records. Deployers may designate materials as proprietary or trade secret, and attorney-client privilege is preserved.
CO
Failed
Developers must produce documentation to the attorney general within 90 days of request, with trade-secret and privilege protections preserved.
CO
Failed
Deployers must produce risk management policies, impact assessments, and related records to the attorney general within 90 days of request, with trade-secret and privilege protections preserved.
CO
Failed eff 2025-05-05
Developers must maintain all required documentation and records throughout the distribution period and for at least three years after final distribution, and must produce them to the attorney general within 90 days of request.
CO
Failed eff 2025-05-05
Deployers must maintain all required documentation and records throughout deployment and for at least three years after final deployment, and must produce risk management policies, impact assessments, and records to the attorney general within 90 days of request.
CO
Failed
Developers must produce to the attorney general, within ninety days of request, the documentation described in § 6-1-1702(2). Developers may designate materials as proprietary or trade secret, and disclosure does not waive attorney-client or work-product protections. Effective June 30, 2026.
CO
Failed
Deployers must produce to the attorney general, within ninety days of request, the risk management policy, impact assessments, or records maintained under § 6-1-1703. Deployers may designate materials as proprietary or trade secret, and disclosure does not waive attorney-client or work-product protections. Effective June 30, 2026.
CT
Failed
Developers must, upon request by the Attorney General as part of an investigation, disclose the documentation described in section 2(b) in a form and manner the AG prescribes. Developers may designate trade-secret or security-sensitive information as exempt from public disclosure.
CT
Failed
Deployers must, upon AG request as part of an investigation, disclose their risk management policy, impact assessments, and related records within 90 days in a form and manner prescribed by the AG.
IL
Failed
Developers and deployers must provide any impact assessment performed under this Act to the Office of the Attorney General upon request. Assessments are confidential and exempt from FOIA disclosure.
IL
Failed
Insurers must comply with Department of Insurance requests for information and documentation regarding AI systems governance, risk management, use protocols, third-party diligence, and AI systems program compliance during any investigation or market conduct action.
IL
Failed
Insurers authorized to operate in Illinois must comply with Department of Insurance requests for information and documentation in connection with investigations or market conduct actions regarding AI systems and predictive models. Required documentation includes: AI systems governance, risk management, and use protocols; preacquisition and preutilization diligence, monitoring, and auditing of third-party AI systems and data; and implementation and compliance records for the insurer's AI systems program.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5002
Failed
Developers must provide the Attorney General with the standardized disclosure documentation required under § 14–5002(C) upon request by the Attorney General.
MD
MD HB 1331 (AI Consumer Protection) § Md. Code, Com. Law § 14–5007
Failed
Developers and deployers must produce disclosures otherwise required under the subtitle to the Attorney General upon request for compliance evaluation, subject to trade secret and privilege protections. Materials provided are exempt from public records disclosure.
NC
Failed
Licensees must permit physical and digital inspections by the Department, including examination of source code, algorithms, machine learning models, data processing and storage practices, cybersecurity measures, user data privacy protections, chatbot responses and behaviors, data collection/use/retention practices, software development processes, remote access capabilities, and integration with other digital health technologies. Licensees must provide access to all records relating to development, testing, validation, production, distribution, and performance of the chatbot upon request during any inspection. Trade secret protections apply to confidential information obtained during inspections.
NC
Failed
Licensees must permit physical and digital inspections by the Department, including examination of source code, algorithms, ML models, data practices, cybersecurity, privacy protections, chatbot responses, data retention, development processes, remote access, and platform integrations, and must provide access to all records relating to development, testing, validation, production, distribution, and performance upon request.
NE
Failed
Developers must, upon written demand from the Attorney General in connection with an investigation, disclose the documentation described in Section 3(2) in a form and manner prescribed by the Attorney General. Developers may designate disclosed materials as including proprietary information or trade secrets, and materials so designated are exempt from public disclosure.
NE
Failed
Deployers must, upon AG request in connection with an ongoing investigation, disclose the risk management policy, impact assessment, and/or maintained records to the Attorney General within 90 days, in a form and manner the AG prescribes. Disclosures are not public records. Deployers may designate materials as proprietary or trade secret.
NM
Failed
Developers must submit to the State Department of Justice within 90 days of a request a copy of the summary and documentation previously made available to deployer-recipients, with trade secret and privilege protections preserved.
NM
Failed
Deployers must submit to the State Department of Justice within 90 days of a request any risk management policy, impact assessment, or records conducted, implemented, maintained, or received under the Act, with trade secret designations preserved.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 417
Failed
Operators must cooperate with the secretary's periodic source code and outcome evaluations, and upon receipt of binding recommendations, must submit a detailed remediation plan with implementation timeline and comply with it.
NY
Failed
Deployers and developers must, within 45 days of an attorney general request, produce any impact assessment performed under this article. Disclosure does not waive attorney-client privilege or work-product protection, and trade secrets are exempt from public records disclosure.
OK
OK HB 3835 (Ethical AI Act) § 75A O.S. § 1002
Failed
Developers and deployers must provide any impact assessment to the Office of the Attorney General upon request. Assessments provided are confidential and exempt from open records requests.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-6
Failed
Developers and deployers must produce impact assessments and design evaluations to the attorney general upon subpoena in the course of an investigation.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-6
Failed
Developers and deployers must disclose to the attorney general the contents of relevant impact assessments or design evaluations when compelled by investigative subpoena.
TX
TX SB 668 (AI Disclosure) § Bus. & Com. Code § 2003.005
Failed
Covered persons must allow the attorney general to access their records to the extent necessary to ensure substantial compliance with this chapter.
US
Failed
Online platforms must make the complete algorithmic process record available to the FTC upon request.
US
Failed
Online platforms must make the complete algorithmic process record available to the FTC upon request.
US
Failed
Persons using or distributing a pricing algorithm must, within 30 days of a written request from the Attorney General or FTC, produce a certified written report covering the algorithm's provenance, decision logic, data inputs (including training data), data sources and collection frequency, price-discrimination behavior, and any changes made since receipt of the request. The report must be certified under penalty of perjury by the CEO, Chief Economist, CTO, or officer of similar authority.
VA
VA HB 747 (High-Risk AI Developer Act) § Va. Code § 59.1-607
Failed
Developers must disclose to the Attorney General any statement or documentation described in the chapter when relevant to an AG investigation. Deployers must disclose to the Attorney General any risk management policy, impact assessment, or record maintained under the chapter when relevant to an AG investigation.
VT
Failed
Developers must disclose to the Attorney General any documentation described in § 1002(b) if relevant to an Attorney General investigation. Such documentation is exempt from public records and protected by attorney-client privilege.
VT
Failed
Deployers must disclose to the Attorney General any risk management policy, impact assessment, or related record if relevant to an Attorney General investigation. Such materials are exempt from public records and protected by attorney-client privilege.
VT
Failed
Developers of generative AI systems must disclose to the Attorney General any impact assessment or record if relevant to an Attorney General investigation. Such materials are exempt from public records and protected by attorney-client privilege.
WA
Failed
Deployers and developers must provide any impact assessment performed under this section to the attorney general upon request. Submitted assessments are confidential and exempt from public disclosure.
R-02.3
Market authorization or registry submission
Developers and/or deployers of AI systems in regulated domains must register the system, obtain a license, or secure pre-market authorization before placing it on the market, submitting the required technical description, intended uses, evaluation results, and/or responsible-party identification.
Enacted
2
Live
16
Failed
27
Total
45
NY
Enacted eff 2027-01-01
Large frontier developers must file a disclosure statement with the Office before developing, deploying, or operating a frontier model in New York. The disclosure must identify the developer's identity, business names, principal place of business, New York office addresses, beneficial ownership (5% threshold for private companies, 50% for public), and three designated points of contact. The disclosure must be renewed every two years, upon ownership transfer, or upon material change, whichever occurs first.
VT
Enacted eff 2026-07-01
Suppliers of mental health chatbots seeking the affirmative defense must file their written policy with the Office of the Attorney General, providing: the supplier's name and address, the chatbot name, the written policy, and a $100 filing fee. Suppliers may also file policy revisions and additional documentation.
CA
CA AB 1405 (AI Auditor Enrollment) § Gov. Code § 11549.83
Engrossed
AI auditors must, prior to conducting any covered audit, enroll with the Government Operations Agency, pay the enrollment fee, and provide: (1) the auditor's name and contact information, (2) the types of AI systems or models the auditor is enrolling to audit, (3) any relevant certifications or accreditations and the identities of the certifying entities, (4) a written description of services (200 words max), and (5) a standard operating procedure describing audit procedures in sufficient detail for third-party best-practices assessment.
AR
AR HB 1816 (Healthcare AI Prohibition) § Ark. Code § 17-80-123
Introduced
Healthcare providers and healthcare insurers must not use AI in the delivery of healthcare services or for the generation of medical records unless the AI system is both approved by the U.S. Food and Drug Administration and verified by a quality assurance laboratory.
AZ
Introduced
AI businesses must obtain a certification from the Attorney General before entering the stream of commerce.
HI
Introduced eff 2026-07-01
Any person deploying an AI product in Hawaii must submit affirmative proof establishing the product's safety to the Office of Artificial Intelligence Safety and Regulation before deployment.
IL
Introduced
Academic medical centers with existing AI-assisted therapy research programs must register those programs with the Department of Financial and Professional Regulation within 90 days after the Act's effective date.
IL
Introduced
Academic medical centers conducting AI-assisted therapy research must (1) register each qualified research program with the Department within 30 days of IRB approval, (2) submit annual reports summarizing participant counts, serious adverse events, protocol modifications, and scientific findings, and (3) notify the Department within 10 business days of any IRB suspension or termination of a research protocol.
IL
Introduced
Auto insurers seeking any rate change must file a complete rate application with the Director of Insurance, bear the burden of proving the requested rate is justified and complies with the Section, and obtain prior approval before the change takes effect (deemed-approval after 60 days absent disapproval, hearing, or a Director-initiated review).
LA
Introduced
Covered insurers must file a pre-deployment notice with the Commissioner at least 60 days before deploying a new ADS or materially modifying an existing system, including a system description, pre-deployment disparate impact testing results, training data description, input variables, and a compliance certification. Deployment is stayed if the Commissioner requests additional information within 15 days.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 510
Introduced
Any person who develops a high-risk advanced AI system, in whole or in part, in New York must register the system with the Secretary of State by applying for a license before or upon the system's active deployment. This duty applies irrespective of the system's location of operation and extends to any updates, modifications, upgrades, or expansions of the system's capabilities or intended uses. Systems that more likely than not qualify as high-risk must register. If the Secretary determines that an unregistered system qualifies as high-risk, the creators must cease development and all public or private use until registration is completed.
NY
Introduced
Insurers must submit to the Superintendent all AI-based algorithms and training data sets used or to be used in utilization review, with certifications that the algorithms (1) have minimized the risk of bias across protected characteristics, (2) adhere to evidence-based clinical guidelines, (3) do not rely on information non-compliant with utilization review requirements, and (4) do not independently create or change clinical standards or coverage criteria.
NY
Introduced
The Commissioner must establish a public registry for collecting, storing, and making publicly available impact assessments or summaries submitted by employers or vendors. Employers and vendors must submit impact assessments to this registry (per § 1052(1)(a)(xi)). The Commissioner must promulgate redaction rules for proprietary, sensitive, or privacy-threatening information.
OH
Introduced
Applicants for an independent verification organization license must file with the attorney general a comprehensive plan covering risk definitions, measurable outcome metrics, technical and operational requirements for developers and deployers, audit methodologies, governance oversight, incident disclosure requirements, corrective action procedures, verification revocation standards, and independence-ensuring policies.
TX
TX HB 1265 (AI Mental Health Services) § Health & Safety Code § 616.003
Introduced eff 2025-09-01
Providers seeking to use an AI application for mental health services must submit testing results to the Health and Human Services Commission for evaluation, and the Commission must issue an order approving or disapproving the application's use.
US
Introduced
Regulated entities seeking to operate an AI test project must submit a detailed application to the appropriate financial regulatory agency that includes a project description, an alternative compliance strategy identifying the regulation to be waived or modified and an alternative compliance method, an explanation of public interest benefit, absence of systemic and national security risk, AML/CFT consistency, a proposed termination date, scope limitations, a business plan, and an economic impact estimate. Where the alternative compliance strategy involves a regulation issued by a different agency, the application must be submitted to both the appropriate agency and the issuing agency, and both must jointly approve.
VT
Introduced eff 2025-07-01
Providers of social media platforms must register annually with the Vermont Secretary of State by January 31, pay a $100 fee, submit contact information and the platform's current privacy policy and terms of service, and agree to statutory and AG-adopted product safety and privacy terms.
VT
Introduced eff 2025-07-01
Providers of AI systems must register annually with the Vermont Secretary of State by January 31, pay a $100 fee, submit contact information, current privacy policies and terms of service, the system's data collection, storage, and security practices, and agree to statutory and AG-adopted product safety and privacy terms.
HI
Failed
Any person deploying an AI product in Hawaii must submit affirmative proof establishing the product's safety to the Office of Artificial Intelligence Safety and Regulation before deployment.
IL
Failed
The University of Illinois Hospital must, before using any diagnostic algorithm to diagnose a patient, confirm that the algorithm (1) has been certified by the Department of Public Health and the Department of Innovation and Technology, (2) has been shown to achieve diagnostic results at least as accurate as other diagnostic means, and (3) is not the only method of diagnosis available to the patient.
IL
IL HB 1002 (Diagnostic Algorithm) § 210 ILCS 85/6.34
Failed
All hospitals licensed under the Hospital Licensing Act must, before using any diagnostic algorithm to diagnose a patient, confirm that the algorithm (1) has been certified by the Department of Public Health and the Department of Innovation and Technology, (2) has been shown to achieve diagnostic results at least as accurate as other diagnostic means, and (3) is not the only method of diagnosis available to the patient.
IL
Failed
The University of Illinois Hospital must, before using any diagnostic algorithm on a patient, confirm that the algorithm (1) has been jointly certified by the Department of Public Health and the Department of Innovation and Technology, (2) has demonstrated accuracy equal to or better than other diagnostic means, and (3) is not the only diagnostic method available to the patient.
IL
IL HB 5115 (Diagnostic Algorithm) § 210 ILCS 85/6.35
Failed
Licensed hospitals must, before using any diagnostic algorithm on a patient, confirm that the algorithm (1) has been jointly certified by the Department of Public Health and the Department of Innovation and Technology, (2) has demonstrated accuracy equal to or better than other diagnostic means, and (3) is not the only diagnostic method available to the patient.
IL
IL HB 69 (Diagnostic Algorithm) § 110 ILCS 330/8d
Failed
The University of Illinois Hospital must, before using any diagnostic algorithm to diagnose a patient, confirm that the algorithm has been certified by the Department of Public Health and the Department of Innovation and Technology, has been shown to achieve equal or better accuracy than other diagnostic means, and is not the sole method of diagnosis available to the patient.
IL
IL HB 69 (Diagnostic Algorithm) § 210 ILCS 85/6.28
Failed
A hospital licensed under the Hospital Licensing Act must, before using any diagnostic algorithm to diagnose a patient, confirm that the algorithm has been certified by the Department of Public Health and the Department of Innovation and Technology, has been shown to achieve equal or better accuracy than other diagnostic means, and is not the sole method of diagnosis available to the patient.
MA
Failed
Licensed mental health professionals must obtain approval from the relevant professional licensing board before using AI to provide mental health services.
MA
Failed
Companies must register with the attorney general within 90 days of the act's effective date, providing company contact information, a description of the model (including capacity, training data, intended use, design process, and methodologies), and information on data collection, storage, and security practices.
MD
MD SB 987 (AI Health Software & Insurance Decisions) § Md. Code, Health–Gen. § 19–150
Failed
The Maryland Health Care Commission must establish and maintain a registry of artificial intelligence health software that may be distributed or operated in the state.
MD
MD SB 987 (AI Health Software & Insurance Decisions) § Md. Code, Health–Gen. § 19–150
Failed
Persons must register artificial intelligence health software with the Maryland Health Care Commission before distributing or operating the software in Maryland.
NC
Failed
Any person seeking to operate or distribute a chatbot that deals substantially with health information must first obtain a health information chatbot license from the NC Department of Justice. The license application must include: (1) detailed documentation of the chatbot's technical architecture and operational specifications, data collection/processing/storage/deletion practices, security measures and protocols, and privacy protection mechanisms; (2) quality control and testing procedures; (3) risk assessment and mitigation strategies; (4) evidence of compliance with applicable federal and state regulations; (5) proof of insurance coverage; (6) required application fees; and (7) any additional information required by the Department. The Department reviews based on technical competence, data protection, regulatory compliance, risk management, professional qualification requirements (including evidence-based efficacy and expert endorsement), and public safety.
NC
Failed
Persons operating or distributing a chatbot that deals substantially with health information must obtain a health information chatbot license from the Department of Justice before operation, submitting detailed documentation of the chatbot's technical architecture, data practices, security measures, privacy protections, quality control procedures, risk assessments, regulatory compliance evidence, proof of insurance, and application fees.
NV
Failed eff 2026-01-01
Artificial intelligence companies must register with the Bureau of Consumer Protection before engaging in business in Nevada, providing name, address, and data-storage information, and must renew the registration annually.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 410
Failed
Any person who develops a high-risk advanced AI system in New York must register it with the Secretary of State by applying for a license upon active deployment, including for any updates, modifications, upgrades, or expansions of the system's capabilities or intended uses.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 411
Failed
No person may develop or operate a high-risk advanced AI system within New York without first obtaining a license from the Secretary of State. The license application must be in writing, under oath, and accompanied by the prescribed fee.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 412
Failed
Corporate operators that develop additional high-risk AI systems after initial licensure must obtain a supplemental license for each additional system.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 419
Failed
Licensees who rewrite their system's source code must submit the rewrite for review as a new application, and the secretary has up to 180 business days (extendable by 180) to approve or reject. All modifications, upgrades, and rewrites must be conducted in a pre-production environment before deployment.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 423
Failed
Third-party systems integrating with a licensed high-risk AI system must obtain a certificate of compliance from the department demonstrating conformity with applicable cybersecurity standards prior to integration.
NY
Failed
Large frontier developers must file a disclosure statement with the Office before developing, deploying, or operating a frontier model in New York, identifying the developer's identity, trade names, principal place of business, New York offices, beneficial ownership, and three-tiered contact information. The disclosure must be renewed every two years, upon ownership transfer, or upon material change to reported information, whichever is earliest.
PA
PA HB 2903 (AI Registry) § Section 817(a)–(g)
Failed
Businesses operating artificial intelligence systems in Pennsylvania must register with the Department of State by providing their business name, IP address, AI code type, software intent, a contact person's name and contact details, and a signed consent statement.
RI
RI HB 6286 (Generative AI Models) § R.I. Gen. Laws § 6-59-4
Failed
Companies must register with the attorney general within 90 days of the effective date, providing the company's name and contact information, a description of the model (including capacity, training data, intended use, design process, and methodologies), and information on data collection, storage, and security practices.
TX
TX HB 4695 (AI Mental Health Services) § Health & Safety Code § 616.003
Failed
Before commission approval, licensed mental health professionals may provide AI mental health services only in a testing context, and only after obtaining specialized informed consent in which the participant acknowledges the technology has not been demonstrated competent or safe and releases the provider from testing-related liability.
TX
TX HB 4695 (AI Mental Health Services) § Health & Safety Code § 616.003
Failed
Persons seeking to deploy an AI mental health technology application must submit testing results to the commission and obtain an approval order before the application may be used to provide AI mental health services in Texas.
UT
UT HB 452 (Mental Health Chatbots) § Utah Code § 58-60-118
Failed
Suppliers must file the written policy with the Division of Consumer Protection, providing the supplier's name and address, the chatbot name, the written policy, and a filing fee, in a manner established by the division.
WA
Failed
Public agencies intending to develop, procure, or use an automated decision system for implementation after January 1, 2024 must submit an algorithmic accountability report to the applicable review office and obtain approval or conditional approval prior to any use. The review office must post the report publicly and invite at least 30 days of public comment.
WA
Failed
No agency may develop, procure, or use an automated decision system prior to obtaining approval (except during the transitional periods in subsections (1) and (2)), and after approval, the agency may use the system only in accordance with the policies and procedures set forth in the approved algorithmic accountability report.
R-02.4
Annual AI Compliance Self-Certification
Regulated entities must annually certify to the applicable sector-specific regulator that their AI systems meet enumerated performance, fairness, non-discrimination, accuracy, and reliability standards on a continuing basis.
Enacted
1
Live
14
Failed
8
Total
23
AL
Enacted eff 2026-10-01
Health benefit plan providers must annually certify to the Alabama Department of Insurance that the AI used for medical necessity determinations on prior authorization requests complies with all of the following: (1) the AI does not rely on a group dataset to make determinations, (2) the AI is fairly and equitably applied, including in accordance with applicable HHS regulations and guidance, and (3) the AI does not discriminate, directly or indirectly, against any subscriber group or enrollee in violation of state or federal law, including HHS regulations and guidance.
GA
GA HB 1520 (Rental Pricing Integrity Act) § O.C.G.A. § 10-1-393.22
Introduced
Landlords and coordinators that use any algorithmic rent-setting tool must annually certify to the Georgia Attorney General, in the form prescribed, that the tool does not use or incorporate nonpublic competitor data in violation of subsection (b). They must also retain for at least five years: (1) contracts with rental pricing software vendors; (2) documentation describing data inputs used by any algorithmic rent-setting tool; (3) records of rental price recommendations generated; and (4) records sufficient to demonstrate independent pricing decisions.
IL
Introduced
Developers who use the federal-agency-agreement pathway must file a certification with the Attorney General, in a form prescribed by the Attorney General, attesting that they have entered into a qualifying agreement. Materially false or misleading certifications violate the Act.
LA
Introduced eff 2027-01-01
Large frontier developers must, within 12 months of publishing their frontier AI framework and annually thereafter, provide the attorney general a written certification disclosing either that the developer has been in compliance with its framework during the prior year or describing any material deviations and corrective actions taken or planned.
MA
Introduced
Carriers must annually submit to the Division of Insurance by December 31 a prescribed form detailing AI algorithms and data training sets used or planned for use in utilization review, together with an attestation that such algorithms and training data have minimized bias risk across protected characteristics and adhere to evidence-based clinical guidelines.
NY
Introduced
Every covered entity must file an annual certification of compliance with the responsible capability scaling policy requirements with the Chief Information Officer.
PA
Introduced
Facilities using AI-based algorithms for clinical decision making must annually file an AI compliance statement with the Department of Health, in the form and manner prescribed by the department. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the facility's process for overseeing and validating algorithm performance and compliance.
PA
Introduced
Insurers using AI-based algorithms in utilization review must annually file an AI compliance statement with the Insurance Department, in the form and manner prescribed by the department. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the insurer's process for overseeing and validating algorithm performance and compliance.
PA
Introduced
MA or CHIP managed care plans using AI-based algorithms in utilization review must annually file an AI compliance statement with the Department of Human Services. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the plan's oversight and validation process.
PA
Introduced
Facilities using AI-based algorithms for clinical decision making must annually file an AI compliance statement with the Department of Health. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide evidence of compliance, and (5) describe the facility's process for overseeing and validating AI performance and compliance.
PA
Introduced
Insurers using AI-based algorithms in utilization review must annually file an AI compliance statement with the Insurance Department. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest compliance with responsible-use requirements and provide evidence, and (5) describe the insurer's process for overseeing and validating AI performance and compliance.
PA
Introduced
MA or CHIP managed care plans using AI-based algorithms in utilization review must annually file an AI compliance statement with the Department of Human Services. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest compliance with responsible-use requirements and provide evidence, and (5) describe the plan's process for overseeing and validating AI performance and compliance.
TX
TX SB 1411 (Healthcare AI Algorithms) § Ins. Code § 544.704
Introduced eff 2025-09-01
The Texas Insurance Commissioner must develop and implement a certification process to verify that submitted AI-based algorithms and training datasets have minimized discrimination risk and adhere to evidence-based clinical guidelines.
VT
Introduced eff 2025-07-01
Developers and deployers must file reports with the Attorney General prior to deployment of an automated decision system used in a consequential decision and then annually, or after each substantial change to the system, whichever comes first. Each report must be accompanied by a copy of the last completed independent audit and a legal attestation that the system either (1) does not violate any provision of this subchapter, or (2) may violate or does violate one or more provisions, together with a remediation plan and summary.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-9
Introduced eff 2026-07-01
By December 31 of each year, each covered medical facility, research facility, company, or nonprofit organization must certify to the Attorney General that it is in compliance with the West Virginia Genomic Information Privacy Act. The certification must be submitted by an attorney representing the entity.
NJ
Failed
Automobile insurers using automated or predictive underwriting systems must annually submit documentation and analysis to the Department of Banking and Insurance demonstrating (1) no discriminatory outcome in pricing on the basis of race, ethnicity, sexual orientation, or religion, and (2) that each pricing segment is balanced and not disproportionate to the overall policyholder population.
OK
OK HB 3577 (AI Utilization Review) § 36 O.S. § 6980.3
Failed
Insurers must submit their AI-based algorithms and training data sets used in utilization review to the Oklahoma Insurance Department, and must annually certify by December 31 that these algorithms and data sets minimize bias across protected characteristics and adhere to evidence-based clinical guidelines.
RI
RI HB 7786 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-6
Failed
Developers and deployers must publicly self-certify that they are in compliance with their obligations under this chapter. They may rely on impact assessments or design evaluations conducted under other laws if reasonably similar in scope.
RI
RI SB 2888 (Automated Decision Tools) § R.I. Gen. Laws § 6-60-6
Failed
Developers and deployers must publicly self-certify that they are in compliance with all obligations under this chapter. Assessments or evaluations conducted under other laws or regulations may be used if reasonably similar in scope.
TX
TX SB 1822 (AI in Utilization Review) § Ins. Code § 4201.156
Failed
Health insurance issuers and their utilization review agents must submit to the Texas Department of Insurance by December 31 of each year an AI compliance statement that (1) summarizes each AI algorithm's function and scope, (2) provides a logic or decision tree, (3) describes each training data set and its source, (4) attests to bias minimization and evidence-based clinical guideline compliance, and (5) describes the oversight and validation process.
US
Failed
Online platforms must have a senior officer (CEO, CPO, COO, CISO, or equivalent) certify under oath the accuracy and completeness of all algorithmic process, content moderation, and advertisement library disclosures within 30 days of disclosure and annually thereafter, plus upon any material change.
US
Failed
Online platforms must certify under oath, through a senior officer with personal knowledge, the accuracy and completeness of all algorithmic process, content moderation, and advertisement library disclosures within 30 days of publication, annually thereafter, and upon any material change.
US
Failed
Critical-impact AI organizations must self-certify to the Secretary of Commerce that each critical-impact AI system complies with applicable TEVV standards once those standards are issued. Certifications may not be issued if the organization has constructive knowledge that the certification is false or misleading in a material respect.