CA
Enacted eff 2025-01-01
The Office of Emergency Services must perform a risk analysis of potential GenAI threats to California's critical infrastructure, including mass-casualty scenarios, and provide the analysis and any recommendations to the Governor.
CA
Engrossed eff 2027-07-01
Operators must, on or before July 1, 2027, and annually thereafter, perform and document a comprehensive risk assessment to identify any child safety risk posed by the design, configuration, and operation of the companion chatbot. The assessment must evaluate: (1) the likelihood of a covered harm occurring to users; (2) differential risks across age groups and developmental stages; (3) known vulnerabilities of children; (4) empirical data from actual use; and (5) relevant academic research and regulatory guidance.
AR
Introduced eff 2026-01-01
Healthcare insurers must establish an ongoing biannual quality assurance testing process for AI algorithms meeting Commissioner-specified safety and efficacy parameters aligned with national benchmarks, including validation for generalizability, risk-level-based evaluation, real-world evidence generation, benchmarking against Commissioner-approved standardized metrics in representative Arkansas populations, and multi-institutional, demographically representative testing datasets with documented provenance that are regularly updated.
AZ
Introduced
Chatbot providers must, on a monthly basis, evaluate their chatbot for potential risk of harm to users and make information about the chatbot publicly available on their website. Chatbot providers must mitigate any identified risk of harm to users. These evaluations and mitigations must comply with rules adopted by the attorney general.
AZ
Introduced
AI businesses must conduct a comprehensive pre-market risk assessment for each high-risk AI system, evaluating (1) the potential for discrimination or bias, (2) safety risks to children and vulnerable populations, (3) privacy and data protection risks, and (4) catastrophic risks.
GA
Introduced eff 2027-01-01
Before deploying any new design or materially modifying an existing design, covered entities must assess the risk that the design will cause compulsive use in minors. Where a reasonable lower-risk alternative exists, the alternative must be set as the default until the consumer explicitly requests the original AND has been age-assured as not a minor. Designs whose minor-compulsive-use risk outweighs the benefit may not be deployed to any consumer absent that same gate. Existing designs must be retroactively assessed and mitigated.
HI
Introduced eff 2026-07-01
Developers of AI products deemed by the office to have a higher potential risk must provide a correspondingly higher burden of affirmative proof demonstrating the safety of their product before deployment.
ID
Introduced eff 2026-07-01
AAASPs must demonstrate at licensure that they meet Board-published safety and performance benchmarks, submit annual performance reports proving continued benchmark compliance, and report adverse events and reportable events as defined. The Board may suspend a license on evidence of model drift or degraded safety outcomes.
ID
Introduced eff 2026-07-01
AAASPs must operate clinical AI services only within the model's validated technical specifications, training data, intended use case, and performance parameters as submitted to the Board, and must meet the human-equivalent standard of care for the clinical task.
IL
Introduced eff 2027-01-01
Large chatbot providers must write, implement, comply with, and publicly publish a safety plan detailing how they assess child safety risks, apply mitigations to address those risks, and use third parties to evaluate the potential for and effectiveness of mitigations of child safety risks.
IL
Introduced
Academic medical centers seeking the research exemption must ensure all AI systems used in the research are HIPAA-compliant, undergo documented safety testing before use with participants, include real-time monitoring to detect crisis situations, harmful content, or therapeutic errors, and operate only as adjuncts to (not replacements for) licensed mental health professionals. The program must also maintain a data safety monitoring plan and procedures for reporting adverse events to the IRB.
IL
Introduced eff 2027-01-01
Large chatbot providers must write, implement, comply with, and publicly publish a public safety and child protection plan that describes how they assess child safety risks, apply mitigations based on those assessments, and use third parties to evaluate child safety risks and mitigation effectiveness.
IL
Introduced
Developers must exercise reasonable care in the design of AI products, including accounting for intended and reasonably foreseeable unintended uses and adopting technologically feasible alternative designs that would reduce foreseeable risk of harm without significantly impairing product usefulness.
IL
Introduced
Developers earn a rebuttable presumption of non-defectiveness by (1) conducting documented NIST AI RMF-aligned testing, evaluation, verification, validation, and auditing; (2) mitigating foreseeable risks and considering alternatives; (3) disclosing foreseeable risks and mitigation tactics to deployers and consumers; (4) maintaining an AI data sheet — covering intended uses, training data, risk management, and red-teaming results — available to the Attorney General on request; (5) for products accessible to users under 17, documenting cognitive/emotional development impact assessments, implementing age-gating or content restrictions, and disclosing potential risks to deployers, consumers, and guardians; and (6) prominently including data-sheet information in product terms and conditions.
IL
Introduced
Developers may earn a rebuttable presumption of non-defectiveness by: (1) conducting documented NIST AI RMF-aligned testing, evaluation, verification, validation, and auditing; (2) mitigating foreseeable risks and considering alternatives; (3) disclosing foreseeable risks and mitigation tactics to deployers and consumers; (4) maintaining an AI data sheet — covering intended uses, training data, foreseeable risks, and red-teaming results per NIST guidance — available to the Attorney General on request; (5) for products accessible to minors under 17, documenting cognitive/emotional impact assessments, implementing age-gating, and disclosing risks to consumers and guardians; and (6) prominently including AI data sheet information in product terms and conditions.
MD
Introduced eff 2026-07-01
Manufacturers must conduct a child AI safety assessment for each artificial intelligence toy before marketing or selling it in Maryland, describing foreseeable risks and mitigation strategies. The assessment must be repeated annually and following any significant change to the toy's AI features. Toys already on the market before July 1, 2026, must have an initial assessment completed by January 1, 2027.
MD
Introduced eff 2026-10-01
Developers must exercise reasonable care in the design of their AI product, including knowing or discovering design defects, accounting for intended and reasonably foreseeable unintended uses, and ensuring no technologically feasible and practical alternative design would have mitigated the foreseeable risk of harm without significantly impairing the product's intended use.
MD
Introduced eff 2026-10-01
Developers may establish a rebuttable presumption of non-defectiveness by (1) conducting documented testing, evaluation, verification, validation, and auditing consistent with industry best practices, (2) mitigating foreseeable risks to the extent possible, (3) disclosing foreseeable risks and mitigation tactics directly to deployers and consumers, and (4) for products designed for or reasonably likely to be used by minors, considering and mitigating risks to minors including cognitive and emotional development impacts, implementing age and content restrictions, and providing clear disclosures to deployers, consumers, and guardians.
MN
Introduced
Developers must implement appropriate safeguards to prevent unreasonable risk of critical harm before deploying an AI model.
MN
Introduced
Developers must, before deploying any AI model, implement a written safety and security protocol that: (1) describes reasonable protections and procedures to reduce the risk of critical harm; (2) describes reasonable administrative, technical, and physical cybersecurity protections to reduce the risk of unauthorized access or misuse leading to critical harm; (3) describes in detail the testing procedure to evaluate whether the model poses an unreasonable risk of critical harm, could evade control, or could be misused or modified to increase the risk of critical harm; (4) enables the developer or third party to comply with the RAISE Act; and (5) designates senior personnel responsible for ensuring compliance. Developers must also implement appropriate safeguards to prevent unreasonable risk of critical harm.
NJ
Introduced
Artificial intelligence companies must annually conduct safety tests on all AI technology they sell, develop, deploy, use, or offer for sale in New Jersey, adhering to the minimum requirements established by the Office of Information Technology. The safety tests must address potential biases, inaccuracies, and cybersecurity threats.
NJ
Introduced
Artificial intelligence companies must annually conduct safety tests — covering cybersecurity threats, bias, inaccuracies, and legal compliance — on all AI technology they sell, develop, deploy, use, or offer for sale in New Jersey, adhering to OIT-established minimum requirements.
NJ
Introduced
Employers, public entities, and vendors must not deploy an AEDS or EMT unless it is pretested and validated to serve one of six enumerated allowable purposes and is limited to the least-invasive means, smallest population, and least data and collection frequency necessary for those purposes.
NY
Introduced
Persons developing automated systems must conduct pre-deployment testing, risk identification, and mitigation before deployment, and must subject the system to ongoing monitoring demonstrating safety and effectiveness based on intended use, mitigation of unsafe outcomes beyond intended use, and adherence to domain-specific standards.
NY
Introduced
Persons developing automated systems must not deploy any system that fails to meet the safety and effectiveness requirements of § 504. If an already-deployed system fails to meet those requirements, it must be removed. No automated system may be designed with the intent or a reasonably foreseeable possibility of endangering the safety of any New York resident or community.
NY
Introduced
Persons developing automated systems must design those systems to proactively protect New York residents from harm stemming from unintended, yet foreseeable, uses or impacts.
NY
Introduced
Developers of AI technology intended for use in a professional domain regulated under Title VIII of the Education Law must demonstrate that at least one professional domain expert was directly and substantially involved in: (1) the technology design phase, (2) the data selection and training process, (3) validation and testing of system outputs, and (4) ongoing risk assessment and post-deployment evaluation. Covered application areas include healthcare diagnostics and treatment recommendations, legal decision-making or document generation, financial advising or lending tools, educational curriculum or assessment tools, construction and structural safety systems, and public safety or surveillance technologies.
OK
Introduced eff 2025-11-01
Deployers must have a diligent review and selection process for each AI device before deployment.
PA
Introduced
Suppliers must disclose in the written policy the procedures by which they: (i) conduct testing before making the chatbot publicly available and regularly thereafter to ensure output poses no greater risk than communicating with a human; (ii) identify reasonably foreseeable adverse outcomes and potentially harmful interactions; (iii) provide a mechanism for consumers to report potentially harmful interactions; (iv) implement protocols to assess and respond to risk of harm to consumers or others; (v) detail actions taken to prevent or mitigate adverse outcomes or harmful interactions; (vi) implement protocols to respond as soon as practicable to acute risks of physical harm; (vii) ensure regular, objective reviews of safety, accuracy, and efficacy, which may include internal or external audits; (viii) provide consumers with instructions on safe use of the chatbot; (ix) prioritize consumer mental health and safety over engagement metrics or profit; (x) implement measures to prevent discriminatory treatment of consumers; and (xi) ensure compliance with HIPAA security and privacy provisions (45 CFR Parts 160 and 164) as if the supplier were a covered entity.
PA
Introduced
Facilities must ensure that AI-based algorithms used for clinical decision making do not create foreseeable, material risks of harm to the patient.
PA
Introduced
Insurers must ensure that AI-based algorithms used in utilization review do not create foreseeable, material risks of harm to the covered person.
PA
Introduced
MA or CHIP managed care plans must ensure that AI-based algorithms used in utilization review do not create foreseeable, material risks of harm to the enrollee.
TX
Introduced eff 2025-09-01
An AI mental health application may be considered to have successfully completed testing only after testing results demonstrate competency and safety in providing AI mental health services.
US
Introduced
Covered entities must assess the need for guardrails or limitations on covered algorithm uses, including whether certain applications should be prohibited or restricted through terms of use, licensing agreements, or other legal agreements.
US
Introduced
Covered entities must disclose benchmark evaluation results — whether self-driven or through audit — for each foundation model, including the precautions the model takes in high-risk domains such as healthcare, CBRN weapons, national security, cybersecurity, critical infrastructure, elections, law enforcement, financial and housing decisions, education, employment, public services, and information relating to vulnerable populations including minors and seniors.
US
Introduced
Covered entities must assess the need for guardrails or limitations on certain uses or applications of their automated decision systems or augmented critical decision processes, including whether particular uses should be prohibited or restricted through terms of use, licensing agreements, or other legal agreements.
US
Introduced
Developers must exercise reasonable care in the design of covered AI products; failure to do so creates liability for proximately caused harm. A product whose design is manifestly unreasonable triggers liability without the claimant needing to prove a reasonable alternative design. Noncompliance with an applicable product safety statute or regulation creates a presumption of defectiveness.
US
Introduced
Covered advanced AI system developers must participate in the DOE Advanced Artificial Intelligence Evaluation Program, which conducts standardized safety testing, adversarial red-team evaluation, and classified assessments of advanced AI systems.
US
Introduced
Developers and deployers must (1) take reasonable measures to prevent and mitigate harms identified in evaluations and assessments, (2) ensure independent auditors have all necessary information, (3) consult impacted stakeholders before deployment, (4) certify that the algorithm is not likely to cause harm, disparate impact, or deceptive practices, (5) ensure the algorithm performs consistent with its advertised purpose, (6) ensure data used is relevant and appropriate, and (7) ensure intended use will not violate this Act.
VT
Introduced eff 2025-07-01
Developers and deployers of any inherently dangerous AI system that could reasonably be expected to impact consumers must exercise reasonable care to avoid any reasonably foreseeable risk arising out of the development, intentional and substantial modification, or deployment of the system that causes or is likely to cause: (1) crime or unlawful acts; (2) unfair or deceptive treatment; (3) physical, financial, relational, or reputational injury; (4) highly offensive psychological injuries; (5) offensive intrusion upon privacy or seclusion; (6) IP rights violations; (7) discrimination on the basis of race, color, ethnicity, sex, sexual orientation, gender identity, sex characteristics, religion, national origin, familial status, biometric information, or disability status; (8) behavioral distortion causing physical or psychological harm; or (9) exploitation of age- or disability-based vulnerabilities to distort behavior causing harm.
VT
Introduced eff 2025-07-01
Developers must not place any inherently dangerous AI system in the stream of commerce unless the developer has conducted documented testing, evaluation, verification, and validation at least as stringent as the latest version of the NIST AI Risk Management Framework. For any AI system that creates reasonably foreseeable risks under the standard-of-care provision, developers must mitigate those risks to the extent possible, consider alternatives, and disclose vulnerabilities and mitigation tactics to deployers.
VT
Introduced eff 2026-07-01
Developers must exercise reasonable care in the design of AI products, accounting for both intended uses and reasonably foreseeable unintended uses, ensuring no defective design that could cause harm when a technologically feasible and practical alternative design exists.
VT
Introduced eff 2026-07-01
Developers seeking the safe-harbor presumption of non-defectiveness must (1) conduct documented testing, evaluation, verification, validation, and auditing consistent with industry best practices, (2) mitigate foreseeable risks, (3) disclose foreseeable risks and mitigation tactics to deployers and consumers, (4) maintain an AI data sheet covering intended uses, training datasets, foreseeable risks, and red-teaming results available to the Attorney General on request, (5) for products designed for or likely used by minors, document impact assessments on cognitive and emotional development, implement age-gating or content restrictions, and provide clear risk disclosures to deployers, consumers, and guardians, and (6) prominently include the AI data sheet information in the product's terms and conditions.
VT
Introduced eff 2026-07-01
Deployers who materially and substantially change an AI product, or who intentionally misuse it contrary to the developer's express warranty, are liable as developers — subject to the same design-defect, failure-to-warn, and express-warranty standards applicable to developers.
HI
Failed
State agencies must complete risk and impact assessments under §§ -2, -3, and -5 before establishing any generative AI pilot project.
NC
Failed
Licensees must demonstrate the chatbot's effectiveness through: (1) peer-reviewed, controlled trials with appropriate validation studies done on appropriate sample sizes with real-world performance data; (2) a comparative analysis to human expert performance; and (3) meeting minimum domain benchmarks as established by the Department.
NC
Failed
Licensees must demonstrate effectiveness through peer-reviewed, controlled trials with appropriate validation studies on appropriate sample sizes with real-world performance data, demonstrate effectiveness in a comparative analysis to human expert performance, and meet minimum domain benchmarks established by the Department.
NE
Failed eff 2027-01-01
Large chatbot providers must, as part of their public safety and child protection plan, describe how they: (1) assess potential child safety risks; (2) apply mitigations to address child safety risk potential based on assessment results; and (3) use third parties to assess child safety risk potential and mitigation effectiveness.
NY
Failed
Persons developing automated systems must conduct pre-deployment testing, risk identification, and mitigation, and must subject deployed systems to ongoing monitoring demonstrating safety and effectiveness based on intended use, mitigation of unsafe outcomes beyond intended use, and adherence to domain-specific standards. Systems must also be designed to proactively protect residents from harm stemming from unintended yet foreseeable uses.
NY
Failed
Persons developing automated systems must conduct pre-deployment testing, risk identification, and mitigation, and must subject deployed systems to ongoing monitoring demonstrating safety and effectiveness. Systems that fail these requirements must not be deployed or must be removed. No system may be designed with the intent or foreseeable possibility of endangering residents, and systems must proactively protect against foreseeable harms from unintended uses.
TX
Failed
An AI technology application may not be considered to have completed testing until results demonstrate competency and safety in providing AI mental health services.
US
Failed
Covered entities must assess the need for guardrails or limitations on certain uses or applications of the automated decision system or augmented critical decision process, including whether uses should be prohibited or limited through terms of use, licensing agreements, or other legal agreements.
US
Failed
Covered entities must assess the need for guardrails or use limitations on the automated decision system or augmented critical decision process, including whether certain uses or applications should be prohibited or restricted through terms of use, licensing agreements, or other contracts.
US
Failed
NIST must convene stakeholders to develop voluntary consensus standards for AI testing and evaluation; develop methods and principles for conducting such testing; establish testing resources; monitor and review all AI acquisition testing; make risk recommendations to agency heads; and continuously update methods based on evolving standards.
US
Failed
Covered entities must assess the need for guardrails or limitations on certain uses or applications of each automated decision system or augmented critical decision process, including whether specific uses should be prohibited or limited through terms of use, licensing agreements, or other legal agreements.
US
Failed
Covered entities must assess whether guardrails or limitations on certain uses or applications of the automated decision system or augmented critical decision process are needed, including whether specific uses should be prohibited or limited through terms of use, licensing agreements, or other legal agreements.
US
Failed
Developers and deployers must (1) take reasonable measures to prevent and mitigate harms identified in evaluations and assessments, (2) ensure independent auditors have all necessary information, (3) consult impacted communities before deployment, (4) certify that the algorithm is not likely to result in harm, disparate impact, or deceptive practices and that benefits outweigh harms, (5) ensure the algorithm performs at a reasonable professional standard and consistent with advertised capabilities, (6) ensure data used is relevant and appropriate, and (7) ensure intended use is not likely to violate the Act.
US
Failed
The Secretary of Defense must establish a risk assessment process that holistically evaluates each covered system for dependability, cybersecurity, privacy, bias, bias towards escalation, deployment span (singular vs. cluster/swarm deployment), and risk of civilian harm.
UT
Failed eff 2026-05-06
Large frontier developers that operate a covered chatbot must write, implement, comply with, and publicly publish on their website a child protection plan covering child safety risk assessments, mitigations, third-party evaluations, incident response, and internal governance. Material modifications must be published with justification within 30 days.
UT
Failed eff 2026-05-06
Suppliers must implement and maintain commercially reasonable safety protocols, informed by expert guidance and the state of the art, designed to identify and mitigate safety-critical situations — including technical measures to analyze user input across a full conversation to detect patterns of behavioral or mental health deterioration. A supplier is not liable for an individual detection failure if protocols were implemented in good faith, reflect a concerted effort, and are consistently applied.
VT
Failed
Developers must not offer a generative AI system in Vermont unless the system (1) reduces and mitigates foreseeable risks including through independent expert involvement, (2) uses only datasets subject to appropriate data governance measures examining bias, (3) achieves appropriate levels of performance, predictability, interpretability, corrigibility, safety, and cybersecurity throughout its lifecycle through documented analysis and extensive testing, and (4) incorporates provenance tracking, synthetic content detection, digital watermarking, and prevents generation of CSAM or non-consensual intimate imagery. Records must be retained for at least three years.
VT
Failed
Developers and deployers of inherently dangerous AI systems that could reasonably be expected to impact consumers must exercise reasonable care to avoid foreseeable risks arising from development, substantial modification, or deployment that cause or are likely to cause crime facilitation, unfair or deceptive treatment, physical/financial/relational/reputational injury, offensive psychological injury, privacy intrusion, IP violations, discrimination on protected characteristics, behavioral distortion causing harm, or exploitation of age- or disability-based vulnerabilities.
VT
Failed
Developers of inherently dangerous AI systems must document and disclose to actual or potential deployers all reasonably foreseeable risks — including risks from unintended or unauthorized uses — and all reasonably foreseeable risk mitigation processes relating to the enumerated harm categories.
VT
Failed
Developers must not place an inherently dangerous AI system in the stream of commerce unless they have conducted documented testing, evaluation, verification, and validation at least as stringent as the latest version of the NIST AI Risk Management Framework.
VT
Failed
Developers must not place in the stream of commerce any AI system that creates reasonably foreseeable risks under § 2495e unless the developer mitigates those risks to the extent possible, considers alternatives, and discloses vulnerabilities and mitigation tactics to a deployer.