CA
Enacted eff 2025-01-01
The Office of Emergency Services must submit a high-level summary of its GenAI critical-infrastructure risk analysis to the Legislature annually.
CT
Enacted eff 2026-07-01
Covered operators must, by March 1, 2028 and annually thereafter, publicly disclose in a form prescribed by the Attorney General: total covered user count, portion with parental consent, portion with default minor settings enabled/not enabled, and average daily usage time broken down by age and hour of day.
IL
Enacted eff 2022-01-01
The Department of Commerce and Economic Opportunity must analyze the demographic data reported by employers and report to the Governor and General Assembly by July 1 of each year whether the data discloses a racial bias in the use of artificial intelligence.
IN
Enacted eff 2025-07-01
The Indiana Department of Education must annually survey teachers and students from urban, suburban, and rural schools on AI platform use and effectiveness, prepare a summary report, and submit that report by November 1 each year to the governor, legislative council, and AI task force.
MD
Enacted eff 2024-10-01
Law enforcement agencies must prepare and publish by February 1 each year an annual report disclosing, for the prior calendar year, the FRT systems and databases used, total searches by crime type, match counts with demographic breakdowns (age, race, gender), data breaches or unauthorized uses, and demographic data for all searches and matches.
TX
Enacted eff 2026-01-01
Sandbox program participants must submit quarterly reports to the Department of Information Resources including: (1) performance metrics for the AI system, (2) updates on how the AI system mitigates risks associated with its operation, and (3) feedback from consumers and affected stakeholders using the system. The department must maintain confidentiality of intellectual property, trade secrets, and other sensitive information.
CA
Engrossed
MROs must submit annual reports to the Legislature and Attorney General covering aggregated AI model capabilities, observed and potential societal risks and benefits, adequacy of evaluation resources, developer and security vendor certifications, aggregated assessment results, remedial measures and compliance, and additional identified risks beyond personal injury or property damage.
NY
Engrossed
Manufacturers and operators must publish annual transparency reports detailing the number of law enforcement requests received, the number complied with, and the legal process relied upon.
RI
Engrossed eff 2026-06-30
Insurers must supply OHIC/DBR the data needed for the annual report on AI use, including: (1) types of AI models used, (2) AI's role in claims and coverage decision-making, (3) training, testing, and risk management information including data governance measures, bias examination, and mitigation, and (4) performance metrics including claim counts, acceptance/denial rates, reviewer time per claim, appeal rates, and denial reversal rates.
CA
Introduced
The e-Safety Commission must, on or before January 1 of each year, report to the Legislature and the Governor on (1) the commission's activities under this chapter, (2) compliance rates among covered entities, and (3) enforcement actions taken and proposed statutory changes.
HI
Introduced
Health carriers must submit quarterly reports to the insurance commissioner detailing provider-to-patient ratios, average wait times, and referral outcomes, disaggregated by region or island.
HI
Introduced
Health carriers must compile and submit monthly data to the insurance commissioner on prior authorization approval and denial rates, average processing times, and the percentage of automated-decision-system-based denials overturned on appeal.
IA
Introduced
Upon a provider's request, health carriers must produce an annual report to that provider summarizing for the prior calendar year the total claims processed by the automated adjudication system, the number and percentage denied or downcoded by the system, and the number and percentage appealed and adjusted after clinical-reviewer review.
MA
Introduced
The Department of State Police must document as a public record every facial recognition search request and search performed, and report this information quarterly to the Executive Office of Public Safety and Security, including date, time, system used, offenses under investigation, match counts, requesting officer identity, warrant or emergency request copies, and the presumed race and gender of probe image subjects.
MA
Introduced
Each non-law-enforcement public agency must document as a public record every facial recognition search requested or performed by its public officials, and report this information quarterly to the Executive Office of Public Safety and Security, including date, time, requesting individual, reason for the search, operator identity, system used, match counts, and the presumed race and gender of probe image subjects.
MA
Introduced
The Department of State Police must document each facial recognition search request and search performed as a public record, and report this information quarterly to the Executive Office of Public Safety and Security, including date and time, system used, criminal offense(s) under investigation, number of matches, requesting officer identity and agency, warrant or emergency request copy, and the presumed race and gender of the person in the probe image.
MA
Introduced
Each non-law-enforcement public agency must document every facial recognition search request and search performed by its public officials as a public record, and report this information quarterly to the Executive Office of Public Safety and Security, including date and time, requesting individual, reason for search, system used, number of matches, and the presumed race and gender of the person in the probe image.
MA
Introduced
The Department of State Police must document each facial recognition search request and search as a public record and report this information quarterly to the Executive Office of Public Safety and Security, including date and time, system used, offenses investigated, match counts, requesting officer identity, warrant or emergency documentation, and the presumed race and gender of the probe image subject.
MA
Introduced
Each non-law-enforcement public agency must document as a public record every facial recognition search requested or performed by its public officials and report this information quarterly to the Executive Office of Public Safety and Security, including date and time, requesting individual, reason, searcher identity, system used, match counts, and presumed race and gender of the probe image subject.
MD
Introduced eff 2026-10-01
Carriers must include in their quarterly reports to the Commissioner the total number of grievances that received human review under the new AI-related grievance provision, disaggregated by: (A) type of claim, (B) race, gender, and profession of the member, and (C) type of policy (individual, small group, or large group, and whether purchased on the Health Benefit Exchange).
MN
Introduced
IVOs must submit annual reports to the commissioner and relevant legislative committee chairs covering aggregated AI capabilities and risks, verification assessment results, remediation compliance, additional observed risks, a list of verified AI systems, evaluation methods, and governance or funding changes affecting independence. Trade secrets, sensitive business information, and PII may be redacted.
MN
Introduced
Licensed IVOs must submit an annual report to the commissioner and legislative committee chairs covering aggregated AI capabilities, societal risks and benefits, verification assessment results, anonymized remediation compliance, observed emerging risks, a list of verified AI models and applications, evaluation methods, and governance or funding changes affecting independence. Trade secrets, sensitive business information, and PII may be redacted.
NH
Introduced eff 2027-01-01
Approved sandbox participants must submit quarterly reports to the Department of Information Technology during their participation period (up to 36 months).
NJ
Introduced
The Office must submit an annual report to the Governor and Legislature summarizing algorithmic systems reviewed, bias or discrimination findings, corrective actions taken by State entities, and recommendations for legislative or regulatory changes.
NJ
Introduced
AI infrastructure entities must submit annual reports to the Department of Labor and Workforce Development detailing energy consumption, water usage, and carbon emissions.
NY
Introduced
Utilities must submit quarterly reports to the Public Service Commission detailing the number of billing anomalies detected, confirmed billing errors, average resolution time, total amounts credited or refunded to customers, and any other metrics the commission may require.
NY
Introduced
The commission must make utility quarterly reports publicly available in aggregated and anonymized format and maintain a publicly accessible online dashboard displaying billing accuracy rates, anomaly counts, customer refunds, resolution times, and comparative performance metrics across utilities.
NY
Introduced
Each operator must annually file a report with the Secretary covering business and operations during the preceding calendar year, in the form prescribed by the Secretary, subscribed and affirmed as true under penalties of perjury. The Secretary may also require additional regular or special reports as deemed necessary for proper supervision, also affirmed under penalties of perjury.
NY
Introduced
The Department of Labor must annually report to the legislature on the number of surcharge waivers granted in the preceding year and the justification for each waiver. The report must be sent to the temporary president of the senate, the minority leader of the senate, the speaker of the assembly, and the minority leader of the assembly, and must be made publicly available on the Department of Labor's website.
OH
Introduced
Licensed IVOs must submit an annual report to the General Assembly, the attorney general, and the auditor of state covering aggregated AI capabilities, societal risks and benefits, verification assessment results, remedial measures and compliance, verified AI systems, evaluation methods, and governance changes. Permissible redactions apply for trade secrets, competitive information, PII, and security-sensitive information.
US
Introduced
The President, Vice President, and each agency head must submit to Congress and publish on their applicable public website an annual audit describing compliance with the AI-content disclosure requirement, beginning within 180 days of enactment.
US
Introduced
Each financial regulatory agency must submit annual reports to the Senate Banking Committee and House Financial Services Committee on AI test project outcomes, beginning no later than two years after enactment and continuing for seven years, including aggregated findings, trends, and lessons learned, without disclosing participating entity names or proprietary information.
US
Introduced
Sandbox participants must submit periodic reports to the Director at three intervals per waiver period covering consumer counts, ongoing risk assessments and mitigation activities, unanticipated risks, adverse incident descriptions and remediation actions, and quantitative benefits data.
US
Introduced
The Director must submit annual reports to Congress on the Program covering application statistics, approved participants, public benefits and harms, waived provisions and frequency, affected consumer counts, and all related materials.
VT
Introduced eff 2025-07-01
Deployers of high-risk AI systems must submit testing results to the Division of Artificial Intelligence at one month, six months, and twelve months after deployment, showing the reliability of the system's results, any variance in results over the testing periods, and any mitigation strategies for variances.
IL
Failed eff 2027-01-01
Operators must submit an annual report to the Attorney General containing: (1) the total number of times the crisis intervention protocol was triggered during the preceding calendar year, and (2) a summary of the results of the most recent biennial compliance audit.
MA
Failed
The commission must submit an annual public report by December 31 to the Governor, the legislative clerks, and the joint committee on state administration and regulatory oversight, detailing the extent of government automated decision-making, findings, recommendations for regulatory or legislative action (including areas where state agencies should not use automated decision systems), implementation timelines, cost estimates, and progress on prior recommendations.
MA
Failed
The Department of State Police must document each facial recognition search request and search performed as a public record and report this information quarterly to the Executive Office of Public Safety and Security, including date, time, system used, offenses investigated, match counts, requestor identity and agency, warrant or emergency documentation, and presumed race and gender of probe image subjects.
MA
Failed
Non-law enforcement public agencies must document each facial recognition search requested or performed by their officials as a public record and report this information quarterly to the Executive Office of Public Safety and Security, including date, time, requestor identity, reason for search, search operator identity, system used, match counts, and presumed race and gender of probe image subjects.
MA
Failed
The department of state police must document every facial recognition search request and search performed as a public record, and must report this information quarterly to the executive office of public safety and security, including date/time, system used, offenses under investigation, match counts, requester identity, warrant or emergency documentation, and the presumed race and gender of probe image subjects.
MA
Failed
Each non-law-enforcement public agency must document every facial recognition search requested and performed by its public officials as a public record, and must report this information quarterly to the executive office of public safety and security, including date/time, requester identity, reason, system used, match counts, and the presumed race and gender of probe image subjects.
MA
Failed
The Department of State Police must document each facial recognition search request and search performed as a public record and report quarterly to the Executive Office of Public Safety and Security, including date, time, system used, offenses investigated, matches returned, requesting officer identity and agency, warrant or emergency documentation, and the presumed race and gender of the probe image subject.
MA
Failed
Each non-law-enforcement public agency must document as a public record every facial recognition search requested or performed by its officials and report quarterly to the Executive Office of Public Safety and Security, including date, time, requesting individual, reason, conducting individual, system used, matches returned, and the presumed race and gender of the probe image subject.
MD
Failed
Health insurance carriers must submit quarterly reports to the Commissioner on adverse decisions and grievances, now disaggregated by zip code, race, ethnicity, gender, and age, and including: the number and outcomes of grievances, grievance monetary values, average hold and call times for grievance and appeal call centers, and the monetary value of adverse decision cases outside the subtitle's scope.
MD
Failed
Law enforcement agencies must prepare and publish by February 1 each year an annual report covering the prior calendar year, disclosing (1) each facial recognition system name and databases searched, (2) total searches per system with associated crime types, (3) total matches leading to further investigative action per system and database, and (4) any data breaches or unauthorized uses.
MD
Failed
Law enforcement agencies must prepare and publish by February 1 each year an annual report covering the prior calendar year's facial recognition activity, including total searches performed and associated crime types, matches returned, data breaches or unauthorized uses, extent of use, purpose descriptions including sole-basis versus supporting use, intended benefits with supporting data, technology capabilities and limitations, data inputs, result types, and any known or suspected policy violations.
MD
Failed
The Governor's Office of Crime Prevention, Youth, and Victim Services must submit to the Governor and the General Assembly by October 1 each year a consolidated report of all law enforcement agency facial recognition reports, disaggregated by agency.
ME
Failed
Carriers must report quarterly to the Bureau of Insurance, beginning April 15, 2026, on the number of AI-related coverage denials, the outcome of physician reviews, and the number and outcome of appeals of AI-related determinations.
MN
Failed
The Minnesota Supreme Court must annually submit to the legislature and make publicly available a comprehensive report summarizing all facial recognition surveillance activity, including the number of applications and orders, details of each order, frequency and scope of use, resources expended, and the number of misidentifications including arrests not resulting in charges.
MN
Failed
The Minnesota Supreme Court must annually compile and submit to the legislature — and make publicly available — a comprehensive report on government use of facial recognition technology, including the number of applications, grants, denials, duration of orders, applying agencies, facility types, frequency of use, number of persons analyzed, resources expended, and misidentification counts.
MT
Failed
Local law enforcement agencies that used facial recognition technology must submit an annual report by June 30 to the criminal intelligence information section covering the number of searches run, offenses investigated, and arrests and convictions resulting from the searches for the prior calendar year.
MT
Failed
The Department of Justice must submit an annual report by September 1 to the economic affairs and law and justice interim committees, consolidating local law enforcement facial recognition data and its own usage data including requesting agencies, search counts, offenses investigated, and resulting arrests and convictions.
MT
Failed
Third-party vendors providing facial recognition services to state agencies must submit annual reports by June 30 to thecontracting agency covering warrants/subpoenas/court orders received and a vendor audit summary. The state agency must forward these reports to the legislative interim committees and the information technology board by September 1.
NC
Failed
The Department must submit an annual report by January 15 to the Environmental Review Commission, the Joint Legislative Oversight Committee on Agriculture and Natural and Economic Resources, and the Fiscal Research Division, covering: (1) number and type of permits where AI was used, (2) AI system performance assessments, (3) processing-time comparisons, (4) AI error incidents and corrective actions, and (5) recommendations on continuation, expansion, modification, or discontinuation of AI use.
NC
Failed
Licensees must implement continuous monitoring systems for safety and risk indicators and submit quarterly performance reports to the Department, including incident reports.
NC
Failed
Licensees must implement continuous monitoring systems for safety and risk indicators and submit quarterly performance reports, including incident reports, to the Department.
NV
Failed eff 2026-01-01
Employers who receive the Department of Employment, Training and Rehabilitation's AI job displacement survey must complete and return it. The Department must compile results into an anonymized annual report and submit it to the Governor and Legislature by December 1 each year.
OK
Failed
Deployers must compile aggregated feedback data into an annual performance report and submit it to the AI Council by January 1 of each year.
PA
Failed
The Department of State must submit an annual report to the Commerce Committees of both chambers by January 1 of each year, including the total number of registered AI businesses, the number of registrants received by each state agency, and expenses incurred by the Department.
PA
Failed
The Department of State must submit annual reports to the Senate and House Commerce Committee leadership by January 1 of each year, disclosing the total number of registered AI businesses, the number of registrants received by each state agency, and expenses incurred by the Department.
US
Failed
Non-small-business online platforms that engage in content moderation must publish at least annually a publicly accessible, machine-readable transparency report disclosing total content moderation decisions, breakdowns by policy type, coordinated-behavior responses, demographic data, human vs. automated moderation, appeal rates and reversal rates, government demands, and other FTC-specified information. The report must be available without requiring account creation and must allow free copying and reuse of the data.
US
Failed
Non-small-business online platforms that engage in content moderation must publish at least annually a publicly available, machine-readable transparency report detailing total and disaggregated content moderation decisions broken down by policy category, coordinated-behavior responses, user demographics, moderation method (automated, employee, external), appeal and reversal rates, government-initiated moderation requests (by jurisdiction), and decision types.
US
Failed
State judges and prosecutors must annually report to a designated state agency detailed information about facial recognition orders issued, searches run, offenses investigated, arrests and convictions resulting from searches (disaggregated by race, ethnicity, gender, and age), motions to suppress, and databases used.
US
Failed
Federal judges and prosecutors must annually submit to the Director of the Administrative Office of the United States Courts the same categories of facial recognition use data required of state counterparts.
US
Failed
Operators must publish a quarterly transparency report, in a machine-readable open format with an open license and in an easily accessible location, disclosing total and algorithm-driven political-email spam flagging counts and percentages broken down by Republican and Democratic party affiliation, plus a summary of the tools and techniques used to determine which political campaign emails to flag.
US
Failed
Non-small-business online platforms that engage in content moderation must publish at least annually a public transparency report including total content moderation decisions, breakdowns by policy category, coordinated-behavior response, aggregate demographics, moderation method, appeal and reversal rates, government demands, and decision types. Reports must be publicly accessible without account creation, in machine-readable format, freely copyable, and available in all service languages.
US
Failed
Non-small-business online platforms that engage in content moderation must publish at least annually a publicly accessible transparency report containing total content moderation decisions, breakdowns by policy category, coordinated-behavior responses, aggregate demographics, moderation method, appeal and reversal rates, government requests, and decision types. Reports must be available without account creation, in all supported languages, and in machine-readable format with freely copyable data.
UT
Failed eff 2026-05-06
Suppliers must generate aggregated user engagement estimates — calculated separately for minors and adults using a statistically valid methodology — identifying median and 90th-percentile hours of use and number of chatbot interactions for each group.
VT
Failed
Deployers of high-risk AI systems must submit one-month, six-month, and twelve-month post-deployment testing results to the Division of Artificial Intelligence in the first year of deployment, showing system reliability, variance over the testing periods, and mitigation strategies for any variances.
WA
Failed
Beginning January 1, 2023, each agency using an automated decision system must publish on its website annual metrics on the number of requests for human review of decisions rendered by the system and the outcomes of those reviews.
WA
Failed
The Algorithmic Accountability Review Board must conduct an annual review of agency audits beginning January 1, 2026, and compile a public report covering agency compliance, known violations, systematic bias issues, and recommendations, published on the Office's website by March 1 annually (first report by March 1, 2025).
WA
Failed
Beginning January 1, 2025, each agency using an automated decision system must publish on its website annual metrics on the number of requests for human review of automated decisions and the outcomes of those reviews.