MD
Enacted eff 2024-10-01
Law enforcement agencies must not use FRT to analyze images of individuals engaged in constitutionally protected activity unless there is reasonable suspicion of criminal conduct, and must not use FRT to analyze images of individuals who are not intended to be identified or to analyze sketches or manually produced images.
MD
Enacted eff 2024-10-01
Law enforcement agencies must not use facial recognition technology for the purpose of live or real-time identification of an image or a recording.
TX
Enacted eff 2026-01-01
Governmental entities may not develop or deploy an AI system for the purpose of uniquely identifying a specific individual using biometric data or through targeted or untargeted gathering of images or other media from the Internet or any other publicly available source without the individual's consent, if the gathering would infringe on any right of the individual under the U.S. Constitution, the Texas Constitution, or state or federal law.
IL
Introduced
School districts must not purchase or otherwise acquire biometric systems, including facial recognition software, for use on students. School districts must not obtain, retain, possess, access, request, or use biometric systems or biometric information derived from biometric systems with respect to students. School districts must not enter into agreements with third parties for the purpose of obtaining, retaining, possessing, accessing, or using biometric systems or biometric information derived from biometric systems on the district's behalf.
IL
Introduced
The Chicago school district must not purchase or otherwise acquire biometric systems, including facial recognition software, for use on students. The district must not obtain, retain, possess, access, request, or use biometric systems or biometric information derived from biometric systems with respect to students. The district must not enter into agreements with third parties for the purpose of obtaining, retaining, possessing, accessing, or using biometric systems or biometric information on its behalf.
LA
Introduced
Employers must not use an ADS that utilizes facial recognition, gait, or emotion recognition technologies.
MA
Introduced
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, provide resources for, or contract with third parties (including federal agencies) to obtain or use biometric surveillance technology or information derived from it, unless expressly authorized by a general or special law.
MA
Introduced
Law enforcement agencies and officers must not use a biometric surveillance system to (1) infer a person's emotions or affect, or (2) analyze moving images or video data whether in real time or applied to archived information. Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MA
Introduced
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, or provide resources for biometric surveillance technology, nor contract with or request information derived from such technology from any third party (including federal agencies), unless expressly authorized by another general or special law.
MA
Introduced
Law enforcement agencies and officers must not use biometric surveillance systems to (1) infer a person's emotions or affect, or (2) analyze moving images or video data (whether in real time or archived). Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MA
Introduced
Covered entities must not operate, install, or commission the operation or installation of equipment incorporating biometric recognition technology in any place — whether licensed or unlicensed — that is open to and accepts or solicits the patronage of the general public.
MA
Introduced
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (real-time or archived). Facial recognition on a still image extracted from video remains permitted if authorized under subsection (d).
MA
Introduced
Covered entities must not operate, install, or commission the operation or installation of equipment incorporating biometric recognition technology in any place — whether licensed or unlicensed — that is open to and accepts or solicits the patronage of the general public.
MI
Introduced
Employers must not use any electronic monitoring tool or automated decisions tool that is equipped with facial recognition, gait recognition, voice recognition, or emotion recognition technology.
NH
Introduced eff 2027-01-01
Governmental entities must not deploy AI systems for the purpose of uniquely identifying individuals using biometric identifiers or collecting biometric data from publicly available sources without valid consent, unless otherwise permitted for security, law enforcement, or fraud prevention.
NY
Introduced
Persons developing surveillance technologies must subject those technologies to heightened oversight including at least pre-deployment assessment of potential harms and scope limits to protect privacy and civil liberties. Continuous surveillance and monitoring must not be used in education, work, housing, or any other context where it is likely to limit rights, opportunities, or access.
NY
Introduced
No person may develop or operate an AI system within New York that performs any of the following, whether or not it is the system's main function: (a) subliminal manipulation operating beyond conscious awareness with the purpose of materially distorting behavior leading to physical or psychological harm, or leveraging group vulnerabilities to similar ends; (b) infliction of physical or emotional harm without valid law enforcement or self-defense justification; (c) prediction of individuals' future actions followed by reactions that infringe upon liberty, emotional, psychological, or financial interests without legal justification; (d) unauthorized acquisition, retention, or dissemination of sensitive personal information in violation of applicable privacy, security, and hacking laws; or (e) autonomous weapons designed to inflict harm on persons, property, or the environment without meaningful human supervision or control (i.e., the ability to actively manage, intervene, or override). Knowing operation is a class D felony with civil penalties equal to the greater of amounts earned from or damages caused by the system. A narrow exception permits development under Secretary authorization for state use with substantial continuous state oversight after public hearing.
RI
Introduced
Employers must not conduct audio or visual monitoring of bathrooms or other similarly private areas, including locker rooms, changing areas, breakrooms, smoking areas, employee cafeterias, lounges, areas designated to express breast milk, or areas designated for prayer or other religious activity, including data collection on the frequency of use of those areas. Employers must not conduct audio or visual monitoring of a workplace in an employee's residence, personal vehicle, or property owned or leased by an employee. Employers must not use an electronic monitoring tool that incorporates facial recognition. Employers must not use an electronic monitoring tool that incorporates gait, voice analysis, or emotion recognition technology.
TN
Introduced eff 2022-07-01
State and local law enforcement agencies and officers must not obtain, retain, access, or use any face recognition system or information derived from one, and must not request or initiate access to out-of-state face recognition systems. A narrow exception permits lawfully assisting a federal agency using its own federal face recognition technology during joint activities.
US
Introduced
The Department of Defense must not use AI for monitoring, tracking, profiling, or targeting individuals or groups in the United States without an individualized, articulable legal basis, and must never use AI solely to target First Amendment-protected or constitutionally protected activity.
VT
Introduced eff 2025-07-01
Employers must not incorporate any form of facial, gait, voice, or emotion recognition technology in electronic monitoring or automated decision systems.
WA
Introduced eff 2026-07-01
Employers must not incorporate any form of facial, gait, or emotion recognition technology in automated decision systems used in the workplace.
AK
Failed
State agencies may not use AI systems for consequential decisions if the system involves biometric identification (including facial recognition), emotion recognition, cognitive behavioral manipulation of individuals or groups, or social scoring.
AK
Failed
State agencies may not use AI systems for consequential decisions if the system involves biometric identification (including facial recognition), emotion recognition, cognitive behavioral manipulation, or social scoring.
AL
Failed
State and local law enforcement agencies must not use AI or facial recognition services for ongoing surveillance, real-time or near real-time identification, or persistent tracking unless they obtain a warrant, a court order for locating a missing or deceased person, or exigent circumstances exist.
GA
Failed
Law enforcement agencies may use facial recognition searches only for the nine enumerated purposes (criminal suspect identification, victim identification, missing persons, incapacitated persons, deceased persons, detained persons, and imminent public safety threats), and must treat all results only as a guide for further investigation.
GA
Failed
Law enforcement agencies must not connect facial recognition software to any live video surveillance interface, including surveillance cameras, drone cameras, and body-worn cameras. Still images or snapshots captured from video streams may be used as probe images.
GA
Failed
Law enforcement agencies must not use facial recognition software on live-stream or recorded video of the general public, or for surveillance of the general public.
IN
Failed
Airport authorities and boards of aviation commissioners must not provide for the use of any facial surveillance system in any facility under their authority.
MA
Failed
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, fund, or contract with any third party (including federal agencies) to obtain biometric surveillance technology or information derived from it, unless expressly authorized by statute.
MA
Failed
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (whether real-time or archived). Facial recognition may be applied only to still images extracted from video if authorized under subsection (d).
MA
Failed
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, provide resources for, or contract with any third party (including federal agencies) to obtain biometric surveillance technology or information derived from it, unless expressly authorized by a general or special law.
MA
Failed
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (whether real-time or archived). Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MA
Failed
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, or provide resources for biometric surveillance technology, nor contract with or request a third party (including federal agencies) to obtain information derived from such technology, unless expressly authorized by statute.
MA
Failed
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (whether real-time or archived). Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MD
Failed
Law enforcement agencies must not use facial recognition technology to investigate any crime other than enumerated serious offenses, including crimes of violence, human trafficking, child abuse, child pornography, hate crimes, weapon offenses, aggravated animal cruelty, fentanyl importation, stalking, substantial ongoing public safety or national security threats, and equivalent out-of-state fugitive offenses.
MD
Failed
Law enforcement agencies must not use facial recognition technology to analyze images of individuals engaged in constitutionally protected activity unless there is reasonable suspicion the individual has committed, is committing, or is about to commit a crime, and must not analyze images of individuals not intended to be identified or analyze sketches or manually produced images.
MD
Failed
Law enforcement agencies must not (1) disclose to a witness before a live or photo-array identification that a suspect was identified using facial recognition technology, and must not (2) use facial recognition technology for the purpose of live or real-time identification.
MD
Failed
Law enforcement personnel must not use facial recognition technology to identify an individual solely based on personal interest unrelated to law enforcement duties, the individual's political or social beliefs or activities, participation in lawful activities, or the individual's race, color, religious beliefs, sexual orientation, gender, disability, national origin, or homelessness status.
MD
Failed
Law enforcement agencies must not introduce facial recognition results at trial or adjudicatory hearings. Results may only be used to establish probable cause or positive identification in connection with a warrant or at a preliminary hearing, and must be supported by additional, independently obtained evidence — they may never serve as the sole basis for probable cause or identification.
MD
Failed
Law enforcement officers and agents must not use facial recognition technology to (1) investigate crimes other than crimes of violence, human trafficking, or acts involving a substantial ongoing threat to public safety or national security, (2) analyze images of individuals engaged in constitutionally protected activity absent reasonable suspicion, suspected juveniles ineligible for criminal charges, or persons not intended to be identified, (3) analyze sketches or manually produced images, (4) disclose to a witness before a lineup or photo array that a suspect was identified via facial recognition, or (5) conduct live or real-time identification.
MN
Failed
Government entities and government officials must not obtain, retain, access, or use any face surveillance system or any information obtained from a face surveillance system, whether directly or through any agreement or arrangement with a private entity.
MN
Failed
Government entities and government officials must not obtain, retain, access, or use any face surveillance system or any information obtained from a face surveillance system.
MN
Failed
Government entities and government officials must not enter into any agreement or arrangement with a private entity to obtain, retain, access, or use any face surveillance system or information obtained from a face surveillance system.
MN
Failed
Agency officers and employees must not use facial recognition technology for ongoing surveillance in public spaces unless they have obtained a covered court order or qualify for the exigent-circumstances exception (requiring a court order application within 48 hours). Orders are limited to 30 days with renewable 30-day extensions, and use must terminate if an exigent-circumstances application is denied.
MN
Failed
Agency officers and employees must not use facial recognition technology for ongoing surveillance of individuals in public spaces unless they have obtained a covered court order in support of a law enforcement activity, or qualify for the exigent-circumstances exception (which requires a retroactive court order application within 48 hours). Court orders are limited to 30 days, with 30-day extensions available upon renewed application.
MN
Failed
Government entities and government officials must not obtain, retain, access, or use any face surveillance system or any information obtained from a face surveillance system, whether directly or through an agreement or arrangement with a private entity.
MT
Failed
State and local government agencies, law enforcement agencies, public employees, and public officials must not obtain, retain, possess, access, request, contract for, or use continuous facial surveillance. Facial verification data may not be repurposed to aid continuous facial surveillance.
MT
Failed
State and local government agencies, law enforcement agencies, public employees, and public officials must not obtain, retain, possess, access, request, or use facial recognition technology or information derived from it, enter into third-party vendor agreements for such purposes, or install continuous facial surveillance cameras on public buildings or public roads, except as permitted under the law enforcement (Section 6) and government facial verification (Section 8) exemptions.
MT
Failed
The motor vehicle division must not establish a digital driver's license program that utilizes facial recognition technology without the consent of the legislature.
NY
Failed
Landlords must not obtain, retain, access, or use any facial recognition system — or any information obtained from such a system — on any residential premises.
NY
Failed
No person may develop or operate an AI system in New York that (1) deploys subliminal manipulation causing physical or psychological harm, (2) inflicts harm without law enforcement or self-defense justification, (3) predicts individual behavior and acts on predictions to infringe on liberty or financial interests without legal justification, (4) engages in unauthorized acquisition of sensitive personal data, or (5) implements autonomous weapons without meaningful human supervision or control. Knowing operation is a class D felony.
NY
Failed
Employers must not use electronic monitoring tools in a manner that violates any state law; threatens employee health, welfare, safety, or legal rights; monitors off-duty employees; obtains information about health or protected-class status; identifies or punishes employees engaging in protected labor activity; conducts audio or visual monitoring of private areas (bathrooms, locker rooms, breakrooms, prayer areas, lactation rooms); monitors employee residences, personal vehicles, or employee-owned property; or uses facial recognition, gait analysis, voice analysis, or emotion recognition technology. Employers must not take adverse action against employees for opposing practices they reasonably believe violate this article.
NY
Failed
Employers must not use an AEDT to violate any state law; harm or likely harm employee health or safety (including through unsafe productivity quotas); make predictions about employee behavior, beliefs, intentions, personality, or emotional state; predict or interfere with protected labor activity; subtract wages for time spent exercising legal rights; operate outside the scope of the impact assessment; or use facial recognition, gait, or emotion recognition technologies.
NY
Failed
Surveillance technologies must be subject to heightened oversight including at least pre-deployment harm assessment and scope limits. Continuous surveillance and monitoring must not be used in education, work, housing, or other contexts where use is likely to limit rights, opportunities, or access.
OK
Failed
Deployers must not develop, deploy, or use AI systems classified as unacceptable risk, including social scoring systems, manipulative AI targeting vulnerable groups, real-time biometric identification systems, AI for discriminatory lending or biased law enforcement profiling, unauthorized biometric surveillance, unregulated access to sensitive government databases, and AI-driven misinformation campaigns targeting elections, public health, or emergency response.
TN
Failed
State and local law enforcement agencies and officers must not obtain, retain, access, or use any face recognition system or information derived from one, and must not request or initiate access to out-of-state face recognition systems. Lawful assistance to a federal agency in a joint activity where the federal agency uses its own federal face recognition technology is permitted.
TX
Failed
No person may deploy an AI system trained on biometric identifiers gathered from the internet or other publicly available sources for the purpose of uniquely identifying a specific individual. Publicly available biometric data does not constitute consent under the Texas biometric privacy statute.
US
Failed
Investigative or law enforcement officers must not use facial recognition to create a record describing how any individual exercises constitutional rights, including free assembly, association, and speech.
US
Failed
Investigative or law enforcement officers must not use or request facial recognition in conjunction with any image obtained from a body camera, dashboard camera, or any aircraft camera including a drone.
US
Failed
Investigative or law enforcement officers must not use or request facial recognition for the purpose of face surveillance.
US
Failed
The Secretary of the Treasury must not establish or maintain any verification process for access to an IRS online account that uses facial recognition technology.
US
Failed
Federal agencies and federal officials must not acquire, possess, access, or use any biometric surveillance system — or information derived from one — in the United States, unless a future Act of Congress explicitly authorizes the specific use with particularized safeguards covering permitted entities, data management, accuracy auditing, equity protections, and compliance mechanisms.
US
Failed
Federal law enforcement agencies must not obligate or expend any federal funds for the purchase or use of a biometric surveillance system, and no federal agency may use unallocated appropriated funds for that purpose.
US
Failed
State and local governments must comply with a law or policy substantially similar to the federal biometric surveillance prohibition or lose eligibility for Byrne grant program funding beginning the first fiscal year after enactment.
US
Failed
Federal agencies and federal officials must not acquire, possess, access, or use any biometric surveillance system — or information derived from one operated by another entity — in the United States, unless a future Act of Congress specifically authorizes the activity with particularized standards for authorized entities, biometric types, purposes, data management, accuracy auditing, civil-liberties protections, and compliance mechanisms.
US
Failed
Federal law enforcement agencies must not obligate or expend any federal funds — including unallocated appropriated funds — for the purchase or use of a biometric surveillance system.
VT
Failed
Employers must not incorporate any form of facial, gait, or emotion recognition technology into electronic monitoring or automated decision systems.