CA
Enacted eff 2024-01-01
The Department of Technology must submit a report of the comprehensive inventory of high-risk automated decision systems to the Assembly Committee on Privacy and Consumer Protection and the Senate Committee on Governmental Organization on or before January 1, 2025, and annually thereafter until the reporting requirement sunsets on January 1, 2029.
CA
Enacted eff 2026-01-01
Large frontier developers must transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of their frontier models every three months, or on another reasonable schedule specified by the developer and communicated in writing to the Office of Emergency Services, with written updates as appropriate.
CA
Enacted eff 2025-01-01
The Department of Technology must update the Governor's report (per Executive Order N-12-23) as needed to respond to significant GenAI developments, consulting with academia, industry experts, and state employee representatives as appropriate.
CO
Enacted eff 2027-01-01
Covered entities must provide written disclosures to the Division of Insurance, the Department of Human Services, or the Department of Health Care Policy and Financing, as applicable, identifying: (1) the utilization review functions for which the AI system will be used; (2) the points in the utilization review process when the AI system is used; (3) the human oversight process, including the qualifications of the reviewer and whether a human must approve an adverse determination; and (4) the process for maintaining audit information sufficient to demonstrate compliance with the utilization review requirements.
IL
Enacted eff 2022-01-01
Employers that rely solely on AI analysis of video interviews to select applicants for in-person interviews must collect demographic data (race and ethnicity) on applicants who are and are not advanced to in-person interviews and applicants who are hired, and must report this data annually to the Department of Commerce and Economic Opportunity by December 31, covering the 12-month period ending November 30.
KY
Enacted eff 2022-04-08
Law enforcement agencies must adopt a facial recognition technology use policy before deploying the technology and must file a full copy of the policy (or any revision) with the Justice and Public Safety Cabinet within 30 days of adoption or revision.
MD
Enacted eff 2024-10-01
Law enforcement agencies must submit their annual FRT report to the Governor's Office of Crime Prevention, Youth, and Victim Services by May 1 each year. The Governor's Office must compile and transmit the reports, disaggregated by agency, to the Governor and General Assembly by October 1.
MD
Enacted eff 2024-07-01
Each public senior higher education institution and Baltimore City Community College must (1) establish functionally compatible high-risk AI governance policies for research and academic AI by June 1, 2025, and (2) submit an annual report to the Department by September 1, 2025, and each year thereafter, on all high-risk AI procured and deployed for a research or academic purpose.
MD
Enacted eff 2024-07-01
The AI Subcabinet must develop and submit to the Governor and General Assembly by December 1, 2024, a roadmap reviewing risks and opportunities of AI across twelve State service areas, including study plans, prioritization, stakeholders, and projected timelines.
MD
Enacted eff 2024-07-01
The AI Subcabinet must submit a report to the Governor and General Assembly by December 1, 2025, on the sufficiency of the Subcabinet structure and the potential transition to a standalone department or independent unit.
NY
Enacted eff 2027-01-01
Large frontier developers must transmit to the Office a summary of any assessment of catastrophic risk resulting from internal use of their frontier models every three months, or on another reasonable schedule agreed upon with the Office.
TN
Enacted eff 2026-05-27
Each executive branch department must report its AI malicious-use prevention plan, findings, and recommendations to every member of the general assembly no later than January 1, 2025.
WA
Enacted eff 2026-06-11
Health carriers writing at least 1% of total accident and health premiums in Washington must report annually to the OIC by October 1 the total number of prior authorization requests, approvals, and denials — including the percentage of denials aided by AI, the percentage of determinations exceeding statutory turnaround deadlines, and the number of nonelectronic requests — along with code-level data and trend data, broken out separately for carrier-direct and delegated health care benefit manager determinations.
CA
Engrossed
MRO applicants must conduct an annual independence audit covering board composition, resource availability, funding sources, and civil society representation, and must report audit findings to the Attorney General.
NY
Engrossed
Covered businesses must file an annual report with the Department of Labor by March 1 of each year covering the preceding calendar year. The report must include: (1) employment data estimating the number of employees displaced or whose hours were reduced due to AI, the number hired or whose hours increased due to AI, and the number of positions previously filled that the business decided not to fill due to AI; and (2) information on the nature of AI usage, including objectives of AI use, human oversight of AI, frequency and length of AI use, any use of AI in relation to sensitive personal data (including storage and access protections), and measures in place for oversight, risk reduction, or other protections related to AI use.
NY
Engrossed
Every developer and deployer of a high-risk AI system must file with the attorney general a copy of the last completed independent audit together with each report required under this section.
NY
Engrossed
Developers of high-risk AI systems must complete and file reports with the attorney general on the following schedule: (1) an initial report within six months after completion of development and initial offering to a deployer or initial deployment, (2) annually thereafter, and (3) within six months of any substantial change. Developer reports must include: a description of the system's intended uses and disallowed uses, an overview of how the system was developed, an overview of training data, and any other information necessary to allow deployers to understand the outputs, monitor compliance, and fulfill their duties under this article. For systems already deployed at the effective date, developers have 18 months to file the first report and associated audit.
NY
Engrossed
Deployers of high-risk AI systems must complete and file reports with the attorney general on the following schedule: (1) an initial report within six months after initial deployment, (2) a second report within one year of the first, (3) biennially thereafter, and (4) within six months of any substantial change. Deployer reports must include: a description of actual, intended, or planned uses for consequential decisions and whether any developer-unintended uses are occurring; and an impact assessment covering algorithmic discrimination risk and mitigation steps, monetization plans (if applicable), and a cost-benefit evaluation for consumers and end users. A deployer that is also a developer may submit a single joint report containing all required information. For systems already deployed at the effective date, deployers have 18 months to file the first report and associated audit.
RI
Engrossed
Insurers must disclose to OHIC and DBR how they use AI to manage healthcare claims and coverage, including the model types used, AI's role in decision-making, training datasets, performance metrics, governance and risk-management policies, and the decisions where AI made or substantially contributed.
VA
Engrossed
Carriers must publicly disclose to the Bureau of Insurance their use of AI to manage insurance claims and coverage, including the underlying algorithms, data used, and resulting determinations.
AK
Introduced eff 2027-01-01
Social media platforms with known minor Alaska-resident users must submit an annual report to the attorney general that includes: (1) a description of design features used by the platform that may affect minors; (2) a description of measures taken to mitigate harm to minors; (3) a summary of data collection and privacy practices relating to minors; and (4) a description of any internal assessments conducted regarding engagement or wellbeing of minors. The report may not be required to disclose proprietary algorithms or trade secrets.
AR
Introduced eff 2026-01-01
Healthcare insurers must submit quality assurance testing results to the Insurance Commissioner at least semiannually and publish those results on a public website within 30 days of submission.
AZ
Introduced
AI businesses must submit a transparency report to the Attorney General before using or selling a high-risk AI system, including the system's purposes and operation, results from internal risk assessment evaluations, and measures implemented to mitigate bias and harmful outcomes.
CA
Introduced
The commission must, by January 1, 2028, adopt standards requiring electrical and gas corporations to disclose the types of artificial intelligence models they use and how those models are used.
CA
Introduced
Electrical and gas corporations must file a compliance plan with the commission demonstrating compliance with the adopted AI standards. The commission may request records to verify compliance. Plans filed by electrical corporations must be reviewable by the Office of Energy Infrastructure Safety to ensure AI models used for wildfire mitigation are consistent with the corporation's wildfire mitigation plan.
GA
Introduced
Developers must provide the Attorney General with documentation regarding each automated decision system, in a form and manner prescribed by the Attorney General, including: (1) a general statement of reasonably foreseeable uses and known harmful or inappropriate uses; (2) documentation disclosing the system's purpose, intended benefits, high-level training data summaries, known limitations and discrimination risks, mitigation measures, pre-distribution performance evaluation methods, data governance measures covering training data suitability and bias, intended use/non-use/monitoring instructions, and all information necessary for deployers to comply with their own obligations; and (3) any additional documentation reasonably necessary for deployers to understand outputs and monitor discrimination risk.
IL
Introduced eff 2027-01-01
Large frontier developers must transmit to the Attorney General a summary of any assessment of catastrophic risk resulting from internal use of their frontier models at least every 3 months.
IL
Introduced
Large frontier developers must transmit to the Attorney General a summary of catastrophic risk assessments from internal use of their frontier models every 3 months or on another reasonable schedule communicated in writing to the Attorney General.
IL
Introduced
State agencies must submit each impact assessment to the Governor and the General Assembly at least 30 days before implementing the automated decision-making system. All other public bodies must submit each assessment to the director, executive officers, or primary administrator of the relevant governing body at least 30 days before implementation. Employers may redact information from published or submitted assessments if disclosure would substantially harm public health or safety, infringe privacy, or impair IT/operational security, or if the assessment covers security-incident prevention technology — but must publish an explanatory statement describing the determination process for each redaction alongside the redacted assessment.
IL
Introduced
Academic medical centers conducting AI-assisted therapy research must (1) register each qualified research program with the Department within 30 days of IRB approval, (2) submit annual reports summarizing participant counts, serious adverse events, protocol modifications, and scientific findings, and (3) notify the Department within 10 business days of any IRB suspension or termination of a research protocol.
IL
Introduced
Auto insurers seeking any rate change must file a complete rate application with the Director of Insurance, bear the burden of proving the requested rate is justified and complies with the Section, and obtain prior approval before the change takes effect (deemed-approval after 60 days absent disapproval, hearing, or a Director-initiated review).
IL
Introduced eff 2027-01-01
Large frontier developers must transmit to the Attorney General a summary of any assessment of catastrophic risk resulting from internal use of their frontier models at least every 3 months.
IL
Introduced
Large frontier developers must transmit to the Agency a summary of catastrophic risk assessments resulting from internal use of their frontier models every 3 months or on another reasonable schedule communicated in writing to the Agency.
IL
Introduced
Employers must, when reporting the reason for a mass layoff or closing under the Illinois WARN Act, disclose any artificial intelligence-related job impacts, including the number of employees laid off substantially due to AI replacement or automation of their job functions.
LA
Introduced eff 2027-01-01
Large frontier developers must transmit to the attorney general a summary of any assessment of catastrophic risk resulting from internal use of their frontier models every three months or on another reasonable schedule communicated in writing to the department.
MA
Introduced
Carriers must annually submit to the Division of Insurance by December 31 a prescribed form detailing AI algorithms and data training sets used or planned for use in utilization review, together with an attestation that such algorithms and training data have minimized bias risk across protected characteristics and adhere to evidence-based clinical guidelines.
MA
Introduced
Large frontier developers must transmit to the Attorney General a summary of catastrophic risk assessments from internal use of their frontier models every three months, or on another reasonable schedule communicated in writing to the Attorney General.
MA
Introduced
Developers must annually submit to the attorney general a compliance statement signed by the CTO or more senior officer, containing (1) an assessment of critical harms the model may cause, (2) an assessment of residual risk despite safety protocol compliance, and (3) a description of the verification process. The initial statement must be submitted within 30 days of deployment or commercial release.
MN
Introduced eff 2027-01-01
Employers must submit a copy of every pre-use notice to the Commissioner of Labor and Industry within ten days of providing the notice to workers.
MO
Introduced
Employers must, within thirty days after each quarter-end, disclose to the director of the department of labor and industrial relations all AI-related job impacts for the preceding quarter, including AI-driven layoffs, AI-driven hires, positions left unfilled due to AI replacement, individuals being retrained due to AI, and corresponding NAICS codes.
NJ
Introduced
Employers must annually report the demographic data collected under subsection (d) to the Department of Labor and Workforce Development.
NJ
Introduced
Large frontier developers must annually submit to the Attorney General a Risk Management Disclosure explaining the technical and organizational protocols they have implemented to reduce the risk of frontier models contributing to catastrophic harm.
NJ
Introduced
Large frontier developers must structure their Risk Management Disclosure to map each of their actions to the suggested actions in the current NIST AI Risk Management Framework, stating for each whether it is relevant, whether adopted, how implemented or why not, the compliance criteria used, and who is responsible.
NJ
Introduced
Large frontier developers must clearly identify which sections of their Risk Management Disclosure were written, edited, or otherwise contributed to by a generative AI system.
NJ
Introduced
Artificial intelligence companies must annually submit a report to the Office of Information Technology containing: (1) a list of all AI technologies tested; (2) a description of each safety test conducted, including the test's adherence to OIT requirements; (3) a list of all third parties used to conduct safety tests, if any; and (4) the results of each safety test administered.
NJ
Introduced
Employers must annually report the collected race and ethnicity demographic data to the Department of Labor and Workforce Development.
NJ
Introduced
Employers must report the demographic data collected under subsection (d) annually to the New Jersey Department of Labor and Workforce Development.
NJ
Introduced
Artificial intelligence companies must annually submit to the Office of Information Technology a report listing all AI technologies tested, describing each safety test conducted and its adherence to OIT requirements, identifying any third parties used for testing, and providing the results of each safety test.
NJ
Introduced
Employers with 100 or more employees that deploy AI systems resulting in layoffs must file an AI Impact Disclosure with the Department of Labor and Workforce Development. The disclosure must contain, at minimum, the date the AI tool was deployed, the date of layoffs, and the number of workers displaced by the AI deployment.
NJ
Introduced
AI infrastructure entities must conduct an environmental impact assessment at the time of initial deployment and annually thereafter, and file the assessment with the Department of Labor and Workforce Development. An additional environmental impact assessment must be conducted and filed with any capacity expansion.
NY
Introduced
Insurers must submit their AI-based algorithms and training data sets to the Superintendent, with a certification that they (1) minimize bias risk across protected characteristics and comply with antidiscrimination laws, (2) adhere to evidence-based clinical guidelines, (3) do not rely on non-compliant information, and (4) do not independently create or change clinical standards or coverage criteria.
NY
Introduced
Insurers must submit to the superintendent data on the amount of time each clinical peer reviewer spends examining an adverse determination before signing off, in such form and manner as the superintendent may require.
NY
Introduced
Operators must submit a copy of each user oath to the Attorney General within thirty days of the user making the oath, in the form and manner designated by the Attorney General.
NY
Introduced
Insurers, Article 43 corporations, and HMOs must submit the artificial intelligence-based algorithms and training datasets that are being used or will be used in the utilization review process to the Department of Financial Services for bias certification review.
NY
Introduced
Any person developing an autonomous weapons system (as defined in § 501(2)(i)) within New York must disclose in writing to the Secretary of State, prior to active development, the names and addresses of all persons involved, a description of the system, the system's functions and intended use cases, and measures that will be taken to mitigate risks. The Secretary may require cessation of development based on this disclosure.
NY
Introduced
License applicants must submit a written, sworn application containing: (a) the exact name and address of the applicant (and member/officer/incorporation details as applicable); (b) the name and business and residential address of each member of the ethics and risk management board, each principal, and each officer; and (c) a description of all known general use cases of the advanced AI system, including any purposes foreseen to be implemented by the applicant.
NY
Introduced
The ethics and risk management board of each operator must annually submit to the Secretary a comprehensive report for each licensed high-risk advanced AI system covering: (a) all possible use cases (intended and unintended, likely and unlikely); (b) a thorough risk assessment for each use case evaluating potential harm across privacy, security, fairness, economic implications, societal well-being, and safety; (c) a detailed evaluation of known user use cases with recommendations on whether certain applications should be constrained or banned; (d) a mitigation plan for each identified risk including preemptive measures, monitoring processes, and responsive actions, plus a user/stakeholder communication strategy; (e) a comprehensive review of all incidents or failures in the past year; (f) user education efforts and plans considering varying digital literacy levels; (g) disclosure of ethics board conflicts of interest and measures to manage them; and (h) an update on measures taken to ensure adherence to applicable AI laws, regulations, and ethical guidelines.
NY
Introduced
Licensees must obtain express written consent from the Secretary before implementing any source code modification or upgrade in an accessible version of the system. The licensee must submit a written description of the purpose, new or modified functions, reason for the change, and an assessment of new or heightened risks. The Secretary has 30 business days to approve or reject (extendable by 30 additional business days); if no response is received, the change is deemed approved. Source code rewrites are subject to the same requirements but are reviewed as new applications within 180 business days (extendable by 180 days). All modifications, upgrades, and rewrites must be conducted in a pre-production environment. Updates (minor enhancements, bug fixes, cosmetic changes, security patches) are exempt from this requirement.
NY
Introduced
Employers must provide to the Department of Labor, no less than annually, the summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
Introduced
The Office of Information Technology Services must submit a copy of the AI inventory to the Governor, the Temporary President of the Senate, and the Speaker of the Assembly.
NY
Introduced
Employers must submit each impact assessment to the Department of Labor at least thirty days prior to the implementation of the artificial intelligence system that is the subject of the assessment.
NY
Introduced
Covered entities found by the Superintendent to have deployed automated lending decision-making tools producing discriminatory or biased outcomes must comply with any enhanced reporting requirements the Superintendent imposes, which may include additional annual reports, reports with additional information, or direct submission of all reports to the Department.
NY
Introduced
Covered developers and deployers must file each required report with the Department of Financial Services together with a copy of the last completed audit.
NY
Introduced
Covered developers must file reports with the Department of Financial Services within six months of completing development, annually thereafter, and within six months of any substantial change, describing intended and disallowed uses, how the system was developed, its training data, any audit, and information enabling deployer compliance.
NY
Introduced
Developers must submit documentation to the Attorney General affirming: (1) the identities and qualifications of professional domain experts involved in the AI technology, (2) the specific phases of development in which such experts contributed, and (3) any known risks, limitations, or ethical concerns disclosed during development. The Attorney General reviews submissions and issues certificates of compliance to compliant developers.
NY
Introduced
Developers and deployers must, within 30 days after completing a full pre-deployment evaluation, full impact assessment, or developer annual review: (1) submit the evaluation, assessment, or review to the Division of Consumer Protection; (2) publish a summary on their website in a manner easily accessible to individuals; and (3) submit the summary to the Division. Upon request, the evaluation, assessment, or review must be made available to the legislature. All evaluations, assessments, and reviews must be retained for at least 10 years. Trade secrets may be redacted from public disclosures; personal data must be redacted.
NY
Introduced
Insurers must submit to the Superintendent data on the amount of time each clinical peer reviewer spends examining an adverse determination before signing off, in the form and manner the Superintendent requires.
NY
Introduced
Employers must submit the completed AI impact assessment to the Department of Labor at least 30 days prior to implementation of the AI system that is the subject of the assessment.
NY
Introduced
Candidate committees must submit their synthetic media usage records to the State Board of Elections no later than one month after their election is certified. All other committees must submit such records no later than one month after election day.
NY
Introduced
Covered entities found by the superintendent to have deployed a tool producing discriminatory or biased outcomes must comply with any enhanced reporting requirements imposed by the superintendent, which may include additional annual reports, reports with additional information, or direct submission to the department.
NY
Introduced
Covered businesses must submit an annual report to the Department of Labor on or before March 1 of each year covering the preceding calendar year. The report must include: (1) employment data — estimates of employees displaced or whose hours were reduced due in full or in part to AI, employees hired or whose hours increased due in full or in part to AI, and positions previously filled that the business decided not to fill due in full or in part to AI; and (2) AI usage information — descriptions of the objectives of AI use, information regarding human oversight of AI, frequency and length of AI use, use of AI in relation to sensitive personal data including storage and access protections, and measures in place for oversight, risk reduction, or other protections related to AI use.
NY
Introduced
Employers filing a WARN notice must include a statement indicating whether the employment losses are the result, in whole or in part, of the introduction, expansion, or adoption of AI systems, automation technologies, or machine-based processes that have replaced or materially altered the duties of affected employees. The statement must also include, to the extent known at the time of notice: (1) the estimated percentage of positions affected due to such automation or AI integration, and (2) a brief description of the technology or process that contributed to the reduction.
OH
Introduced
Health plan issuers must file an annual report with the Superintendent of Insurance on or before March 1, covering: (1) each provider in the issuer's network; (2) the number of covered persons enrolled in health benefit plans in Ohio in the preceding calendar year; and (3) whether the issuer used, is using, or will use AI-based algorithms in utilization review processes, and if so: the algorithm criteria, data sets used to train the algorithm, the algorithm itself, outcomes of the software, and data on the amount of time a human reviewer spends examining each adverse determination before signing off. The report must be submitted in a form prescribed by the Superintendent, and an officer of the health plan issuer must verify its contents.
OH
Introduced
Licensed IVOs must provide written notice to the attorney general of any material changes to their verification plan, describing the proposed changes, the rationale, and how the changes will better ensure acceptable risk mitigation.
OH
Introduced
Health plan issuers must annually file a report with the Superintendent of Insurance on or before March 1. The report must cover: (1) each provider in the issuer's network; (2) the number of covered persons enrolled in health benefit plans in Ohio in the preceding calendar year; and (3) whether the issuer used, is using, or will use AI-based algorithms in utilization review, and if so: the algorithm criteria, data sets used to train the algorithm, the algorithm itself, outcomes of the software, and data on the time a human reviewer spends examining each adverse determination before signing off. The report must be submitted in a form prescribed by the superintendent, and an officer of the health plan issuer must verify its contents.
PA
Introduced
Facilities using AI-based algorithms for clinical decision making must annually file an AI compliance statement with the Department of Health, in the form and manner prescribed by the department. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the facility's process for overseeing and validating algorithm performance and compliance.
PA
Introduced
Insurers using AI-based algorithms in utilization review must annually file an AI compliance statement with the Insurance Department, in the form and manner prescribed by the department. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the insurer's process for overseeing and validating algorithm performance and compliance.
PA
Introduced
MA or CHIP managed care plans using AI-based algorithms in utilization review must annually file an AI compliance statement with the Department of Human Services. Each statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide supporting evidence, and (5) describe the plan's oversight and validation process.
PA
Introduced
Suppliers must file the written disclosure policy with the Bureau of Consumer Protection, in the form and manner prescribed by the bureau, along with: (1) the name and address of the supplier; (2) the name of the chatbot; and (3) an annual filing fee as prescribed by the bureau.
PA
Introduced
Facilities using AI-based algorithms for clinical decision making must annually file an AI compliance statement with the Department of Health. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest that the algorithms and training data comply with responsible-use requirements and provide evidence of compliance, and (5) describe the facility's process for overseeing and validating AI performance and compliance.
PA
Introduced
Insurers using AI-based algorithms in utilization review must annually file an AI compliance statement with the Insurance Department. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest compliance with responsible-use requirements and provide evidence, and (5) describe the insurer's process for overseeing and validating AI performance and compliance.
PA
Introduced
MA or CHIP managed care plans using AI-based algorithms in utilization review must annually file an AI compliance statement with the Department of Human Services. The statement must: (1) summarize the function and scope of the AI algorithms, (2) provide a logic or decision tree, (3) describe each training data set including its source, (4) attest compliance with responsible-use requirements and provide evidence, and (5) describe the plan's process for overseeing and validating AI performance and compliance.
RI
Introduced
Insurers must disclose to OHIC and DBR how they use artificial intelligence to manage healthcare claims and coverage, including: the types of AI models used, the role of AI in the decision-making process, training datasets, performance metrics, governance and risk management policies, and the specific decisions on claims and coverage where AI made or was a substantial factor in the decision.
SD
Introduced
Health carriers using AI, algorithms, or software tools for utilization review must compile an annual report detailing (1) how the AI tool was used in the utilization review process during the preceding fiscal year, and (2) the nature and degree of human review and oversight used to affirm or negate determinations. The report must be forwarded to the Executive Board of the Legislative Research Council on or before December 1 of each year.
TX
Introduced eff 2025-09-01
Health benefit plan issuers must submit their AI-based algorithms and training datasets used or potentially used in utilization review to the Texas Department of Insurance in the form and manner prescribed by the commissioner.
US
Introduced
The Secretaries of Treasury, Homeland Security, and Commerce must jointly submit to Congress, within 180 days of enactment and annually thereafter, a report describing interagency policies to defend against AI-enabled financial crimes, itemizing currently available resources, and identifying additional resource needs — addressing deepfakes, voice cloning, foreign election interference, synthetic identities, market-disrupting false signals, and overall digital fraud.
US
Introduced
The Secretaries of Treasury, Homeland Security, and Commerce must jointly submit to Congress, within 90 days of each annual report, legislative recommendations and best practices to assist American businesses and government entities with risk mitigation and incident response to AI-enabled financial crimes.
US
Introduced
Covered entities must submit to the FTC (1) an annual summary report for each deployed covered algorithm's ongoing impact assessment and (2) an initial summary report for any new covered algorithm prior to deployment.
US
Introduced
Covered entities must include in their summary reports to the FTC: entity identification, a description of the critical decision the algorithm addresses, intended purpose, stakeholder consultation records, performance testing and differential performance evaluation results, publicly stated guardrails, data sourcing documentation, transparency and explainability measures, identified material negative impacts and remediation steps, infeasibility documentation, and any identified improvement resources — all in the format specified by the FTC.
US
Introduced
Developers and deployers must submit full pre-deployment evaluations, impact assessments, and annual reviews to the FTC within 30 days of completion, make them available to Congress on request, publish summaries on their websites, and retain all records for at least 10 years. Trade secrets may be redacted; personal data must be redacted from public disclosures.
US
Introduced
The Director of OMB must issue regulations or policies within 180 days of enactment to ensure federal-official compliance with the AI-content disclosure requirement and to establish specific formatting, placement, and wording guidelines for the disclaimer across various media formats.
US
Introduced
Each covered agency's civil rights office must submit a biennial report to its congressional oversight committees — first due one year after enactment — detailing the state of covered-algorithm technology and risks, mitigation steps taken, stakeholder engagement actions, and legislative or administrative recommendations regarding algorithmic bias, discrimination, and related harms.
US
Introduced
Covered entities must submit specified information related to each foundation model to the FTC and make certain information publicly available for each foundation model they provide.
US
Introduced
Covered entities must submit to the FTC (1) an annual summary report for each ongoing deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to its deployment.
US
Introduced
Covered entities must include in each summary report submitted to the FTC: entity identifying information, the specific critical decision being made, intended purpose, stakeholder consultation records, testing and evaluation documentation including differential performance results, publicly stated guardrails, data sourcing information, transparency and explainability measures, consumer contest/appeal mechanisms, identified material negative impacts and remediation steps, infeasible requirement documentation, and improvement resources, all in the format specified by the FTC.
US
Introduced
Regulated entities supervised by more than one financial regulatory agency must notify each such agency of any AI Innovation Lab application within 5 business days of submission to the appropriate financial regulatory agency.
US
Introduced
Developers and deployers must submit all full pre-deployment evaluations, full impact assessments, and developer annual reviews to the FTC within 30 days of completion, make them available to Congress on request, publish a summary on their website, and retain all records for at least 10 years. Trade secrets may be redacted; personal data must be redacted from public disclosures.
US
Introduced
Each covered agency's office of civil rights must submit biennial reports to its congressional oversight committees detailing (1) the state of covered algorithm technology and associated bias risks, (2) agency mitigation steps, (3) stakeholder engagement actions, and (4) recommendations for legislative or administrative action to address algorithmic bias and discrimination.
US
Introduced
The Secretary of Defense must notify Congress within five days of issuing an autonomous weapon system waiver for development, fielding, or substantial system modification, including the rationale, system description, operational parameters and safeguards, performance testing results, and anticipated waiver duration, in unclassified form with optional classified annex.
VT
Introduced eff 2025-07-01
Developers and deployers must file reports with the Attorney General prior to deployment of an automated decision system used in a consequential decision and then annually, or after each substantial change to the system, whichever comes first. Each report must be accompanied by a copy of the last completed independent audit and a legal attestation that the system either (1) does not violate any provision of this subchapter, or (2) may violate or does violate one or more provisions, together with a remediation plan and summary.
VT
Introduced eff 2025-07-01
Developers must file with the Attorney General a report containing: (1) system description including software stack, purpose, expected benefits, current and intended uses, impacted stakeholders; (2) intended outputs and whether they may be used beyond articulated purposes; (3) training methodology including pre-processing steps, dataset descriptions, data sources, collection rationale, data quality and appropriateness, breadth of training data, data gap remediation, and compliance with privacy, data security, and copyright laws; (4) use and data management policies; (5) information necessary for deployers to understand outputs and monitor compliance; (6) information necessary for deployer compliance with deployer reporting requirements; (7) system capabilities and developer-imposed limitations including out-of-scope uses, safeguards, guardrails, and testing thereof; (8) internal risk assessment with testing documentation and results covering algorithmic discrimination, validity and reliability, privacy and autonomy, and safety and security risks, plus actions taken and subsequent testing; and (9) monitoring requirements.
VT
Introduced eff 2025-07-01
Deployers must file with the Attorney General a report containing: (1) system description including software stack, purpose, expected benefits, current and intended uses, impacted stakeholders; (2) intended outputs and whether they may be used beyond articulated purposes; (3) revenue and monetization disclosures; (4) whether the system makes consequential decisions autonomously or supports human decision-making; (5) system capabilities and deployer-imposed limitations including out-of-scope uses, safeguards, guardrails, and testing thereof; (6) cost-benefit assessment for consumers given system purpose, capabilities, and probable use cases; (7) internal risk assessment with testing documentation and results covering algorithmic discrimination, accuracy and reliability, privacy and autonomy, and safety and security risks, plus actions taken and subsequent testing; and (8) monitoring requirements.
VT
Introduced eff 2025-07-01
Deployers must submit an AI System Safety and Impact Assessment to the Division of Artificial Intelligence prior to deploying any inherently dangerous AI system in Vermont and every two years thereafter. Deployers must also submit an updated assessment whenever a material and substantial change is made to the system's purpose or the type of data the system processes or uses for training.
VT
Introduced eff 2025-07-01
Deployers must ensure each AI System Safety and Impact Assessment includes all 13 enumerated categories: (1) system purpose; (2) deployment context and intended use cases; (3) benefits of use; (4) foreseeable risks of unintended or unauthorized uses and mitigation steps; (5) whether the model is proprietary; (6) description of training data; (7) whether training data has been processed to remove personal information, copyrighted information, and do-not-train data; (8) transparency measures including identifying to individuals when the system is in use; (9) identification of third-party AI systems or datasets relied on; (10) whether the developer disclosed testing results, vulnerabilities, and safe-use parameters; (11) description of post-deployment input data; (12) post-deployment monitoring and user safeguards including the oversight process; and (13) how the model impacts consequential decisions or biometric data collection.
VT
Introduced eff 2025-07-01
Providers must submit a description of the AI model to the Secretary of State as part of annual registration, including the model's capacity, training data, intended use, design process, and methodologies.
CA
Failed
Deployers and developers must submit each completed impact assessment to the Civil Rights Department within 60 days of its completion.
FL
Failed
The Division of Emergency Management must submit a report to the Legislature by November 15, 2026, covering the pilot program's results, scalability findings, and recommendations for broader government use of provenance data.
GA
Failed
The Commission must file a report of its survey findings on state automated decision system use with the Clerk of the House, Secretary of the Senate, and designated committee chairs by March 31, 2023, and publish the report on the commission's website.
GA
Failed
The Commission must file a recommendations report, together with drafts of legislation necessary to implement those recommendations, with the Clerk of the House, Secretary of the Senate, and designated committee chairs by December 31, 2023, and publish the report on the commission's website.
HI
Failed
Covered entities must annually submit to the Department of the Attorney General, on a prescribed form, a report containing the audit results including: types of algorithmic determinations made, data and methodologies, optimization criteria, training data and sources, performance metrics including accuracy and confidence intervals, impact assessment results, rationale for each decision, complaints received, and any reliance on the affirmative-action exemption. A covered entity may substitute a report previously filed with another government entity if it contains the required information or is supplemented.
HI
Failed
The Office of Enterprise Technology Services must submit to the legislature a report on the potential risks and benefits of using generative AI for state purposes — covering beneficial uses, risks to individuals and communities, cybersecurity breach risks, and emerging technology developments — no later than twenty days before the 2025 regular session and as often thereafter as necessary.
HI
Failed
Covered entities must annually submit to the Department of the Attorney General a structured report containing audit results, including determination types, data and methodologies, optimization criteria, training data sources, rendering methodologies, performance metrics, impact assessment results and methodology, rationale for design decisions, complaint history, and any reliance on the affirmative-action exemption. An equivalent report previously submitted to another government entity may be substituted if it contains or is supplemented with all required information.
HI
Failed
Covered entities must annually submit to the Department of the Attorney General a report containing the full results of the mandated bias audit — including determination types, algorithm methodologies and optimization criteria, training data and sources, performance metrics, impact assessment results and rationale, complaint history, and any reliance on the affirmative action exemption. A previously filed federal or state report may substitute if it contains or is supplemented to contain all required information.
IL
Failed
Deployers must submit each completed impact assessment to the Department of Human Rights within 60 days of completion. Each day the automated decision tool is used without a submitted assessment constitutes a distinct violation subject to up to $10,000 per violation in administrative fines for knowing violations.
IL
Failed
Deployers must submit each completed impact assessment to the Attorney General within 60 days of completion. Knowing failure to submit subjects the deployer to administrative fines of up to $10,000 per violation; each day an automated decision tool is used without the required impact assessment submission constitutes a separate violation.
MD
Failed
Each public senior higher education institution and Baltimore City Community College must (1) establish functionally compatible AI governance policies for research/academic high-risk AI by June 1, 2025, and (2) submit an annual report to the Department by September 1, 2025, and each year thereafter, on all high-risk AI procured and deployed for research or academic purposes.
MD
Failed
The Governor's AI Subcabinet must develop a roadmap reviewing AI risks and opportunities across State services and submit it to the Governor and General Assembly by December 1, 2024, covering twelve enumerated study domains, stakeholder identification, prioritization methodology, and projected timelines.
MD
Failed
The AI Subcabinet must submit a report to the Governor and General Assembly by December 1, 2025, evaluating whether the Subcabinet structure is sufficient to accomplish the State's AI goals and whether it should be elevated to a department or independent unit.
MD
Failed
Health insurance carriers must submit quarterly reports to the Maryland Insurance Commissioner on their creation, deployment, and use of AI or automated decision-making systems, including: purpose of use, person responsible for training, major data sources and methods, guidance used to make recommendations and alignment of outcomes with human expectations, and bias testing results and remediation steps taken.
MD
Failed
Law enforcement agencies must submit their annual facial recognition technology report to the Governor's Office of Crime Prevention, Youth, and Victim Services by May 1 each year.
MD
Failed
Law enforcement agencies must submit their annual facial recognition report to the Governor's Office of Crime Prevention, Youth, and Victim Services by May 1 each year.
MN
Failed
Judges must report to the Minnesota Supreme Court within 30 days after issuing, modifying, or denying a covered court order or extension authorizing facial recognition surveillance, including the disposition, authorized duration, and specified offense.
MN
Failed
Issuing or denying judges must report to the Minnesota Supreme Court within 30 days after issuing a covered court order, extension, or denial, disclosing the application type, disposition, authorized duration, and underlying offense.
MT
Failed
State or local government agencies must report their use of facial recognition technology to the information technology board.
NC
Failed
Operators must annually submit a digital copy of the platform's privacy policy and a compliance certification to the Consumer Protection Division of the NC Department of Justice, beginning October 1, 2024. Substantive privacy policy changes must be reported to the registry.
NC
Failed
Covered platforms must submit to the Online Safety Division an annual Child Impact Assessment for new and existing services, including documentation of potential risks to children and assessment of addiction and compulsive usage risks, and must retain supporting documentation for at least three years.
NC
Failed
Covered platforms must submit to the Online Safety Division an annual Child Impact Assessment for new and existing services, documenting potential risks to children and assessing addiction and compulsive usage risks. Documentation supporting each annual assessment must be retained for at least three years.
NE
Failed eff 2027-01-01
Large frontier developers must transmit to the Attorney General a summary of any assessment of catastrophic risk resulting from internal use of their frontier models no less frequently than every three months. Submission must use the confidential mechanism established by the Attorney General.
NJ
Failed
Automobile insurers using automated or predictive underwriting systems must annually submit documentation and analysis to the Department of Banking and Insurance demonstrating (1) no discriminatory outcome in pricing on the basis of race, ethnicity, sexual orientation, or religion, and (2) that each pricing segment is balanced and not disproportionate to the overall policyholder population.
NV
Failed eff 2026-01-01
Each law enforcement agency must submit its AI use policy and any updates to the Bureau of Consumer Protection in the Office of the Attorney General.
NY
Failed
Employers must annually submit to the Department of Labor a summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
Failed
Employers must annually submit to the Department of Labor a summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
Failed
Operators must submit a copy of each collected user oath to the Attorney General within 30 days of the user making the oath, in the form and manner designated by the Attorney General.
NY
Failed
Any person developing an autonomous weapons AI system in New York must disclose in writing to the Secretary of State — prior to active development — the names and addresses of all persons involved, a description of the system, its functions and intended use cases, and the risk mitigation measures to be taken.
NY
Failed
License applicants must submit a written, sworn application disclosing the applicant's identity, the names and addresses of all ethics and risk management board members, principals, and officers, and a description of all known general use cases of the AI system.
NY
Failed
Operators must annually submit to the secretary a comprehensive report for each licensed system covering all possible use cases, risk assessments, ethical evaluations, mitigation plans, incident reviews, user education plans, board conflict-of-interest disclosures, and compliance updates.
NY
Failed
Licensees must notify the secretary in writing before implementing any source code modification or upgrade, including the purpose, new functions, reasons, and risk assessment, and must obtain the secretary's express written approval before deploying the change. Updates (minor enhancements, bug fixes) are exempt.
NY
Failed
Operators must annually file a sworn report with the secretary covering business and operations during the preceding calendar year, and must file additional regular or special reports as the secretary requires.
NY
Failed
Employers must annually submit to the Department of Labor a summary of the most recent disparate impact analysis for each automated employment decision tool in use.
NY
Failed
Large frontier developers must transmit to the Office confidential summaries of catastrophic risk assessments resulting from internal use of their frontier models every three months, or on an alternative schedule agreed in writing with the Office.
NY
Failed
Operators must submit a copy of each user oath to the Attorney General within 30 days of the user making the oath, in the form and manner designated by the Attorney General.
NY
Failed
Employers must submit the AI impact assessment to the Department of Labor at least 30 days before implementing the artificial intelligence that is the subject of the assessment.
OK
Failed
Sandbox participants must submit periodic progress reports and a final evaluation to the AI Council detailing the system's performance, risks identified, and mitigation measures taken.
OK
Failed
Insurers must submit their AI-based algorithms and training data sets used in utilization review to the Oklahoma Insurance Department, and must annually certify by December 31 that these algorithms and data sets minimize bias across protected characteristics and adhere to evidence-based clinical guidelines.
PA
Failed
Insurers must submit their artificial intelligence-based algorithms and training data sets used or to be used in utilization review to the Insurance Department for bias certification and evidence-based clinical guideline adherence review.
TX
Failed
Health insurance issuers and their utilization review agents must submit to the Texas Department of Insurance by December 31 of each year an AI compliance statement that (1) summarizes each AI algorithm's function and scope, (2) provides a logic or decision tree, (3) describes each training data set and its source, (4) attests to bias minimization and evidence-based clinical guideline compliance, and (5) describes the oversight and validation process.
US
Failed
Each covered agency's civil rights office must submit a biennial report to its congressional oversight committees — beginning one year after enactment — detailing the state of covered-algorithm technology and associated bias risks, mitigation steps taken, stakeholder engagement activities, and legislative or administrative recommendations.
US
Failed
The Federal Reserve Board, FDIC Board, Comptroller of the Currency, CFPB Director, and NCUA Board must, within 180 days of enactment, jointly submit to congressional committees and publish publicly a report examining AI benefits and risks in banking, including regulatory proposals and legislative recommendations, and must publish a request for information to collect public input.
US
Failed
The SEC must, within 180 days of enactment, submit to congressional committees and publish publicly a report examining AI benefits and risks in securities markets, including regulatory proposals and legislative recommendations, must publish a request for information, and must consult with self-regulatory organizations.
US
Failed
HUD, the Rural Housing Service, FHFA, and the CFPB must, within 180 days of enactment, submit to congressional committees and publish publicly a report examining AI benefits and risks in housing and mortgage markets, including regulatory proposals and legislative recommendations, and must publish a request for information.
US
Failed
The Secretary of the Treasury must, within 180 days of enactment, submit to congressional committees and publish publicly a report examining AI benefits and risks related to financial system national security (including Bank Secrecy Act compliance, sanctions, and cybersecurity), including regulatory proposals and legislative recommendations, must publish a request for information, and must consult with the five banking regulators.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to deployment.
US
Failed
Covered entities must include in each summary report submitted to the FTC: entity identification and contact information, a description of the critical decision category, the system's intended purpose, stakeholder consultation documentation, performance testing and differential-performance results, publicly stated use restrictions, data provenance information, transparency and explainability measures including consumer opt-out mechanisms, identified negative impacts and remediation steps, infeasible assessment requirements and rationale, and identified resource needs.
US
Failed
State agencies must forward the information collected from state judges and prosecutors to the Director of the Bureau of Justice Assistance and the Director of the Administrative Office of the United States Courts within 90 days of receipt, and annually thereafter.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each ongoing deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to its deployment.
US
Failed
Covered entities must include in each summary report to the FTC: entity identification, a description of the critical decision and its category, intended purpose, stakeholder consultation records, testing and evaluation results (including differential performance), publicly stated guardrails, data sourcing documentation, transparency and explainability measures, identified material negative impacts with remediation steps, infeasible assessment requirements with rationale, and improvement needs.
US
Failed
Covered entities must submit specified foundation model transparency information to the FTC as defined in the Commission's regulations.
US
Failed
The Secretary of the Treasury, the Secretary of Homeland Security, and the Secretary of Commerce must jointly submit to Congress, within 180 days of enactment and annually thereafter, a report describing interagency policies to defend U.S. financial markets from AI-enabled financial crimes and an itemized resource list needed to combat those risks, covering deepfakes, voice cloning, foreign election interference, synthetic identities, false market signals, and overall digital fraud.
US
Failed
The Secretary of the Treasury, the Secretary of Homeland Security, and the Secretary of Commerce must jointly submit to Congress, within 90 days of each annual report, legislative recommendations and best practices for businesses and government entities to mitigate risks and respond to incidents involving AI-enabled financial crimes.
US
Failed
Each covered agency's privacy and civil liberties officer must submit an annual report to Congress on the results of accredited AI system testing, covering the potential privacy, civil rights, and civil liberties effects of the agency's AI systems.
US
Failed
Each agency head must inform the relevant congressional committees of the CAIO appointment within one year of enactment and, if the CAIO holds dual responsibilities, provide a full description of any additional authorities and responsibilities the individual performs.
US
Failed
The Comptroller General must submit to the relevant congressional committees within two years of enactment a report on the implementation and effectiveness of AI Governance Boards and CAIOs, including recommendations for improvement.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each deployed automated decision system or augmented critical decision process, and (2) an initial summary report for any new system or process prior to its deployment.
US
Failed
Covered entities must include in each summary report submitted to the FTC: entity identification and contact information, description of the critical decision and its category, intended purpose, stakeholder consultation documentation, performance testing results and differential performance evaluations, publicly stated use restrictions, data sourcing documentation, transparency and explainability measures, identified material negative impacts and remediation steps, infeasible assessment requirements with rationale, and identified improvement resources. Reports must follow FTC-specified format and include FTC-determined consumer-protection criteria.
US
Failed
The Director of OMB must brief the appropriate congressional committees on implementation of the AI Hygiene Working Group requirements — quarterly beginning 90 days after enactment through implementation, and annually thereafter.
US
Failed
Deployers of high-impact AI systems must submit to the Secretary of Commerce, before deployment and annually thereafter, a transparency report covering the system's purpose, intended use cases, deployment context, data inputs, training data, performance metrics, transparency measures, pre-deployment testing, third-party dependencies, and post-deployment monitoring. Updated reports must be submitted upon material changes to purpose or training data. Deployers must consider the NIST AI Risk Management Framework.
US
Failed
Each covered agency's office of civil rights must submit a biennial report to its congressional oversight committees detailing the state of algorithmic technology within the agency's jurisdiction (including bias and discrimination risks), mitigation steps taken, stakeholder engagement actions, and recommendations for legislation or administrative action.
US
Failed
FSOC must, within 180 days of enactment and in consultation with member agencies, financial institutions, and securities market participants, submit a report to the Senate Banking and House Financial Services committees identifying AI threats, regulatory gaps, and specific recommendations for closing those gaps.
US
Failed
Regulated entities and the Office of Finance must notify the FHFA Director of any outsourced service relationship within 30 days of the earlier of executing the service contract or the service provider commencing performance.
US
Failed
Covered entities must submit to the FTC (1) an annual summary report for each ongoing deployed automated decision system or augmented critical decision process and (2) an initial summary report prior to deploying any new system or process.
US
Failed
Covered entities must include in each summary report submitted to the FTC: entity identity and contact information, description of the critical decision and its category, intended purpose, stakeholder consultation records, testing and evaluation documentation including differential performance results, publicly stated use restrictions, data sourcing documentation, transparency and explainability measures, identified material negative impacts and remediation steps, infeasibility rationale, and identified improvement needs, in the format specified by the Commission.
US
Failed
Developers and deployers must (1) submit all full pre-deployment evaluations, full impact assessments, and developer annual reviews to the FTC within 30 days of completion, (2) publish a summary on their website within 30 days, (3) submit the summary to the FTC, (4) make evaluations available to Congress upon request, and (5) retain all evaluations, assessments, and reviews for at least 5 years. Trade secrets may be redacted; personal data must be redacted from public disclosures.
US
Failed
The Secretary of Defense must submit annual progress reports to Congress on implementation of the ledger and risk assessment process, beginning one year after enactment and continuing until three years after enactment.
US
Failed
The Secretary of Defense must submit to Congress annually, beginning three years after enactment, the complete AI ledger, a report on risk assessment findings for the covered year, and all export annotations made during the year. Submissions must be unclassified to the fullest extent possible, with a classified annex permitted where necessary.
UT
Failed eff 2026-05-06
Large frontier developers must submit quarterly reports to the Office of Artificial Intelligence Policy summarizing assessments of catastrophic risk resulting from internal use of their frontier models. An alternate schedule may be requested in writing and agreed to by the office.
UT
Failed
A non-reporting-entity person who pays for an electioneering communication that qualifies as a generative A.I. political advertisement must include a statement in the 24-hour report filed with the lieutenant governor disclosing that the communication is a generative A.I. political advertisement.
UT
Failed
Learning Laboratory participants must provide required information to state agencies and report to the Office of Artificial Intelligence Policy as specified in the participation agreement.
VA
Failed
The Attorney General must submit an annual report (not exceeding eight pages) to the Joint Commission on Technology and Science by December 1 each year, summarizing complaint intake activity, enforcement referral patterns, interagency coordination, emerging trends, and legislative recommendations.
VT
Failed
Deployers must submit an AI System Safety and Impact Assessment to the Division of Artificial Intelligence before deploying any inherently dangerous AI system in Vermont, every two years thereafter, and upon any material change to system purpose or training data. The assessment must cover purpose, deployment context, benefits, foreseeable risks and mitigations, proprietary status, training data description, transparency measures, third-party dependencies, developer disclosures, post-deployment monitoring, and impact on consequential decisions or biometric data.
WA
Failed
Public agencies intending to develop, procure, or use a new automated decision system between the effective date and January 1, 2024 must produce and file an algorithmic accountability report with the applicable algorithmic accountability review office at least one month prior to procurement or implementation.