S-02
Safety & Prohibited Conduct
Prohibited Conduct & Output Restrictions
Certain AI applications are categorically prohibited regardless of any compliance program — social scoring, biometric surveillance, subconscious manipulation, CSAM, and NCII generation. Other output categories must be restricted or managed through active protocols based on deployment context and user population — self-harm content, crisis response, and content accessible to minors. The specific prohibitions and restrictions vary by jurisdiction, but the core principle is that certain AI applications are so dangerous or harmful that they should be categorically prohibited, while others require context-sensitive management.
Sub-obligations9
Bills127
Jurisdictions37
Enacted9
Show
Sort bills within section

9 sub-obligations of S-02

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
S-02.1 Social scoring prohibition
AI systems used by or on behalf of governments or employers to assign aggregate scores to individuals based on behavior, social relationships, or perceived trustworthiness — where scores affect access to opportunities or services — are prohibited.
1Enacted 5Live 7Failed 13Total Jump →
S-02.2 Real-time biometric surveillance restriction
AI-enabled real-time identification of individuals in publicly accessible spaces using biometric data is prohibited or requires express regulatory authorization. Narrow exceptions exist for defined law enforcement purposes subject to judicial authorization.
3Enacted 19Live 46Failed 68Total Jump →
S-02.3 CSAM output prohibition
AI systems may not generate child sexual abuse material under any circumstances. This prohibition applies universally regardless of deployment context.
3Enacted 9Live 6Failed 18Total Jump →
S-02.4 AI-generated NCII prohibition
Developers and operators of AI image and video generation tools may not knowingly generate, distribute, or facilitate distribution of non-consensual intimate imagery of real, identifiable individuals.
0Enacted 0Live 0Failed 0Total Jump →
S-02.5 Sexually explicit content restriction for minors
AI systems accessible to users known to be minors must implement reasonable measures to prevent production of visual material of sexually explicit conduct or direct solicitation of minors to engage in sexually explicit conduct.
2Enacted 15Live 3Failed 20Total Jump →
S-02.6 Self-harm and suicidal ideation content restriction
AI systems must restrict outputs that produce, promote, or facilitate suicidal ideation, suicide, or self-harm content.
2Enacted 14Live 1Failed 17Total Jump →
S-02.7 Crisis protocol publication
Operators must publicly post the details of their crisis response protocol on their website. This is a standalone disclosure obligation separate from maintaining the protocol itself.
3Enacted 5Live 1Failed 9Total Jump →
S-02.8 Product safety warning
Operators must disclose known safety risks or suitability limitations of their AI product to users at or before the point of access — on the application, browser, or any other access format. Must not be buried in terms of service.
4Enacted 14Live 2Failed 20Total Jump →
S-02.9 Categorical Government Biometric Surveillance Prohibition
Government entities and officials are categorically prohibited from acquiring, retaining, accessing, or using facial recognition or other remote biometric surveillance systems, or information derived from them, including by requesting or contracting with third parties to perform such analysis on their behalf and including analysis of body-worn camera imagery.
0Enacted 2Live 3Failed 5Total Jump →
Bills That Map This Requirement 231 mappings
S-02.1
Social scoring prohibition
AI systems used by or on behalf of governments or employers to assign aggregate scores to individuals based on behavior, social relationships, or perceived trustworthiness — where scores affect access to opportunities or services — are prohibited.
Enacted
1
Live
5
Failed
7
Total
13
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 552.053
Enacted eff 2026-01-01
Governmental entities may not use or deploy an AI system that evaluates or classifies individuals based on social behavior or personal characteristics (known, inferred, or predicted) with the intent to assign a social score or similar categorical valuation that results or may result in detrimental treatment unrelated to the original context, disproportionate to the observed behavior, or infringing on constitutional or statutory rights.
NY
NY SB 1169 (AI Algorithmic Discrimination) § Civ. Rights Law § 89-a
Engrossed
No person, partnership, association, or corporation may develop, deploy, use, or sell an AI system that evaluates or classifies the trustworthiness of natural persons over time based on their social behavior or known or predicted personal or personality characteristics, where the resulting social score leads to: (1) differential treatment in social contexts unrelated to the data's original context, (2) unjustified or disproportionate differential treatment, or (3) infringement of any constitutional or statutory right.
NH
Introduced eff 2027-01-01
Any person or state agency subject to this chapter must not develop or deploy an AI system for the purpose of social scoring, manipulation aimed at causing self-harm or criminal acts, or infringing rights under the United States or New Hampshire constitutions.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 530
Introduced
No person may develop or operate an AI system within New York that performs any of the following, whether or not it is the system's main function: (a) subliminal manipulation operating beyond conscious awareness with the purpose of materially distorting behavior leading to physical or psychological harm, or leveraging group vulnerabilities to similar ends; (b) infliction of physical or emotional harm without valid law enforcement or self-defense justification; (c) prediction of individuals' future actions followed by reactions that infringe upon liberty, emotional, psychological, or financial interests without legal justification; (d) unauthorized acquisition, retention, or dissemination of sensitive personal information in violation of applicable privacy, security, and hacking laws; or (e) autonomous weapons designed to inflict harm on persons, property, or the environment without meaningful human supervision or control (i.e., the ability to actively manage, intervene, or override). Knowing operation is a class D felony with civil penalties equal to the greater of amounts earned from or damages caused by the system. A narrow exception permits development under Secretary authorization for state use with substantial continuous state oversight after public hearing.
NY
NY A8884 (New York AI Act) § N.Y. Civil Rights Law § 113
Introduced
No person or entity may develop, deploy, use, or sell an AI social-scoring system that classifies natural persons' trustworthiness based on social behavior or personal characteristics where the resulting score leads to unjustified or context-unrelated differential treatment or rights infringement.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(C)
Introduced
School entities must not deploy AI systems that (1) profile or categorize students based on political beliefs, religious beliefs, or personal values, (2) conduct psychological, emotional, or behavioral assessments without explicit parental consent, or (3) make automated disciplinary or student placement decisions without meaningful human review.
AK
Failed
State agencies may not use AI systems for consequential decisions if the system involves biometric identification (including facial recognition), emotion recognition, cognitive behavioral manipulation of individuals or groups, or social scoring.
AK
Failed
State agencies may not use AI systems for consequential decisions if the system involves biometric identification (including facial recognition), emotion recognition, cognitive behavioral manipulation, or social scoring.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 430
Failed
No person may develop or operate an AI system in New York that (1) deploys subliminal manipulation causing physical or psychological harm, (2) inflicts harm without law enforcement or self-defense justification, (3) predicts individual behavior and acts on predictions to infringe on liberty or financial interests without legal justification, (4) engages in unauthorized acquisition of sensitive personal data, or (5) implements autonomous weapons without meaningful human supervision or control. Knowing operation is a class D felony.
NY
Failed
Employers must not use an AEDT to violate any state law; harm or likely harm employee health or safety (including through unsafe productivity quotas); make predictions about employee behavior, beliefs, intentions, personality, or emotional state; predict or interfere with protected labor activity; subtract wages for time spent exercising legal rights; operate outside the scope of the impact assessment; or use facial recognition, gait, or emotion recognition technologies.
OK
Failed
Deployers must not develop, deploy, or use AI systems classified as unacceptable risk, including social scoring systems, manipulative AI targeting vulnerable groups, real-time biometric identification systems, AI for discriminatory lending or biased law enforcement profiling, unauthorized biometric surveillance, unregulated access to sensitive government databases, and AI-driven misinformation campaigns targeting elections, public health, or emergency response.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.052
Failed
No person may develop or deploy an AI system that evaluates or classifies individuals based on social behavior or personal characteristics to assign a social score or similar categorical valuation.
WA
Failed
Public agencies must not operate, install, or commission AI-enabled profiling equipment in any place of public accommodation, or use AI-enabled profiling to make decisions that produce legal effects or similarly significant effects concerning individuals, including denial or degradation of consequential services such as financial services, housing, insurance, education, criminal justice, employment, health care, or basic necessities.
S-02.2
Real-time biometric surveillance restriction
AI-enabled real-time identification of individuals in publicly accessible spaces using biometric data is prohibited or requires express regulatory authorization. Narrow exceptions exist for defined law enforcement purposes subject to judicial authorization.
Enacted
3
Live
19
Failed
46
Total
68
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Enacted eff 2024-10-01
Law enforcement agencies must not use FRT to analyze images of individuals engaged in constitutionally protected activity unless there is reasonable suspicion of criminal conduct, and must not use FRT to analyze images of individuals who are not intended to be identified or to analyze sketches or manually produced images.
MD
MD SB 182 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Enacted eff 2024-10-01
Law enforcement agencies must not use facial recognition technology for the purpose of live or real-time identification of an image or a recording.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 552.054
Enacted eff 2026-01-01
Governmental entities may not develop or deploy an AI system for the purpose of uniquely identifying a specific individual using biometric data or through targeted or untargeted gathering of images or other media from the Internet or any other publicly available source without the individual's consent, if the gathering would infringe on any right of the individual under the U.S. Constitution, the Texas Constitution, or state or federal law.
IL
Introduced
School districts must not purchase or otherwise acquire biometric systems, including facial recognition software, for use on students. School districts must not obtain, retain, possess, access, request, or use biometric systems or biometric information derived from biometric systems with respect to students. School districts must not enter into agreements with third parties for the purpose of obtaining, retaining, possessing, accessing, or using biometric systems or biometric information derived from biometric systems on the district's behalf.
IL
Introduced
The Chicago school district must not purchase or otherwise acquire biometric systems, including facial recognition software, for use on students. The district must not obtain, retain, possess, access, request, or use biometric systems or biometric information derived from biometric systems with respect to students. The district must not enter into agreements with third parties for the purpose of obtaining, retaining, possessing, accessing, or using biometric systems or biometric information on its behalf.
LA
Introduced
Employers must not use an ADS that utilizes facial recognition, gait, or emotion recognition technologies.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(b)
Introduced
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, provide resources for, or contract with third parties (including federal agencies) to obtain or use biometric surveillance technology or information derived from it, unless expressly authorized by a general or special law.
MA
MA HB 1946 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(k)
Introduced
Law enforcement agencies and officers must not use a biometric surveillance system to (1) infer a person's emotions or affect, or (2) analyze moving images or video data whether in real time or applied to archived information. Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(b)
Introduced
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, or provide resources for biometric surveillance technology, nor contract with or request information derived from such technology from any third party (including federal agencies), unless expressly authorized by another general or special law.
MA
MA HB 4640 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(k)
Introduced
Law enforcement agencies and officers must not use biometric surveillance systems to (1) infer a person's emotions or affect, or (2) analyze moving images or video data (whether in real time or archived). Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MA
Introduced
Covered entities must not operate, install, or commission the operation or installation of equipment incorporating biometric recognition technology in any place — whether licensed or unlicensed — that is open to and accepts or solicits the patronage of the general public.
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(k)
Introduced
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (real-time or archived). Facial recognition on a still image extracted from video remains permitted if authorized under subsection (d).
MA
Introduced
Covered entities must not operate, install, or commission the operation or installation of equipment incorporating biometric recognition technology in any place — whether licensed or unlicensed — that is open to and accepts or solicits the patronage of the general public.
MI
Introduced
Employers must not use any electronic monitoring tool or automated decisions tool that is equipped with facial recognition, gait recognition, voice recognition, or emotion recognition technology.
NH
Introduced eff 2027-01-01
Governmental entities must not deploy AI systems for the purpose of uniquely identifying individuals using biometric identifiers or collecting biometric data from publicly available sources without valid consent, unless otherwise permitted for security, law enforcement, or fraud prevention.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Persons developing surveillance technologies must subject those technologies to heightened oversight including at least pre-deployment assessment of potential harms and scope limits to protect privacy and civil liberties. Continuous surveillance and monitoring must not be used in education, work, housing, or any other context where it is likely to limit rights, opportunities, or access.
NY
NY AB 3356 (Advanced AI Licensing Act) § State Tech. Law § 530
Introduced
No person may develop or operate an AI system within New York that performs any of the following, whether or not it is the system's main function: (a) subliminal manipulation operating beyond conscious awareness with the purpose of materially distorting behavior leading to physical or psychological harm, or leveraging group vulnerabilities to similar ends; (b) infliction of physical or emotional harm without valid law enforcement or self-defense justification; (c) prediction of individuals' future actions followed by reactions that infringe upon liberty, emotional, psychological, or financial interests without legal justification; (d) unauthorized acquisition, retention, or dissemination of sensitive personal information in violation of applicable privacy, security, and hacking laws; or (e) autonomous weapons designed to inflict harm on persons, property, or the environment without meaningful human supervision or control (i.e., the ability to actively manage, intervene, or override). Knowing operation is a class D felony with civil penalties equal to the greater of amounts earned from or damages caused by the system. A narrow exception permits development under Secretary authorization for state use with substantial continuous state oversight after public hearing.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not conduct audio or visual monitoring of bathrooms or other similarly private areas, including locker rooms, changing areas, breakrooms, smoking areas, employee cafeterias, lounges, areas designated to express breast milk, or areas designated for prayer or other religious activity, including data collection on the frequency of use of those areas. Employers must not conduct audio or visual monitoring of a workplace in an employee's residence, personal vehicle, or property owned or leased by an employee. Employers must not use an electronic monitoring tool that incorporates facial recognition. Employers must not use an electronic monitoring tool that incorporates gait, voice analysis, or emotion recognition technology.
TN
Introduced eff 2022-07-01
State and local law enforcement agencies and officers must not obtain, retain, access, or use any face recognition system or information derived from one, and must not request or initiate access to out-of-state face recognition systems. A narrow exception permits lawfully assisting a federal agency using its own federal face recognition technology during joint activities.
US
Introduced
The Department of Defense must not use AI for monitoring, tracking, profiling, or targeting individuals or groups in the United States without an individualized, articulable legal basis, and must never use AI solely to target First Amendment-protected or constitutionally protected activity.
VT
Introduced eff 2025-07-01
Employers must not incorporate any form of facial, gait, voice, or emotion recognition technology in electronic monitoring or automated decision systems.
WA
Introduced eff 2026-07-01
Employers must not incorporate any form of facial, gait, or emotion recognition technology in automated decision systems used in the workplace.
AK
Failed
State agencies may not use AI systems for consequential decisions if the system involves biometric identification (including facial recognition), emotion recognition, cognitive behavioral manipulation of individuals or groups, or social scoring.
AK
Failed
State agencies may not use AI systems for consequential decisions if the system involves biometric identification (including facial recognition), emotion recognition, cognitive behavioral manipulation, or social scoring.
AL
Failed
State and local law enforcement agencies must not use AI or facial recognition services for ongoing surveillance, real-time or near real-time identification, or persistent tracking unless they obtain a warrant, a court order for locating a missing or deceased person, or exigent circumstances exist.
GA
Failed
Law enforcement agencies may use facial recognition searches only for the nine enumerated purposes (criminal suspect identification, victim identification, missing persons, incapacitated persons, deceased persons, detained persons, and imminent public safety threats), and must treat all results only as a guide for further investigation.
GA
GA HB 1245 (Law Enforcement Facial Recognition) § O.C.G.A. § 35-1-24(g)–(i)
Failed
Law enforcement agencies must not connect facial recognition software to any live video surveillance interface, including surveillance cameras, drone cameras, and body-worn cameras. Still images or snapshots captured from video streams may be used as probe images.
GA
GA HB 1245 (Law Enforcement Facial Recognition) § O.C.G.A. § 35-1-24(g)–(i)
Failed
Law enforcement agencies must not use facial recognition software on live-stream or recorded video of the general public, or for surveillance of the general public.
IN
Failed
Airport authorities and boards of aviation commissioners must not provide for the use of any facial surveillance system in any facility under their authority.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(b)
Failed
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, fund, or contract with any third party (including federal agencies) to obtain biometric surveillance technology or information derived from it, unless expressly authorized by statute.
MA
MA HB 1728 (Facial Recognition Technology) § M.G.L. c. 6, § 220(k)
Failed
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (whether real-time or archived). Facial recognition may be applied only to still images extracted from video if authorized under subsection (d).
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(b)
Failed
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, provide resources for, or contract with any third party (including federal agencies) to obtain biometric surveillance technology or information derived from it, unless expressly authorized by a general or special law.
MA
MA HB 4359 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(k)
Failed
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (whether real-time or archived). Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(b)
Failed
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, or provide resources for biometric surveillance technology, nor contract with or request a third party (including federal agencies) to obtain information derived from such technology, unless expressly authorized by statute.
MA
MA SB 927 (Facial Recognition Technology) § M.G.L. c. 6, § 220(k)
Failed
Law enforcement agencies and officers must not use biometric surveillance to infer a person's emotions or affect, and must not use biometric surveillance to analyze moving images or video data (whether real-time or archived). Facial recognition may be used on a still image extracted from video only if authorized under subsection (d).
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Failed
Law enforcement agencies must not use facial recognition technology to investigate any crime other than enumerated serious offenses, including crimes of violence, human trafficking, child abuse, child pornography, hate crimes, weapon offenses, aggravated animal cruelty, fentanyl importation, stalking, substantial ongoing public safety or national security threats, and equivalent out-of-state fugitive offenses.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Failed
Law enforcement agencies must not use facial recognition technology to analyze images of individuals engaged in constitutionally protected activity unless there is reasonable suspicion the individual has committed, is committing, or is about to commit a crime, and must not analyze images of individuals not intended to be identified or analyze sketches or manually produced images.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Failed
Law enforcement agencies must not (1) disclose to a witness before a live or photo-array identification that a suspect was identified using facial recognition technology, and must not (2) use facial recognition technology for the purpose of live or real-time identification.
MD
MD SB 192 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2-503
Failed
Law enforcement personnel must not use facial recognition technology to identify an individual solely based on personal interest unrelated to law enforcement duties, the individual's political or social beliefs or activities, participation in lawful activities, or the individual's race, color, religious beliefs, sexual orientation, gender, disability, national origin, or homelessness status.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–502
Failed
Law enforcement agencies must not introduce facial recognition results at trial or adjudicatory hearings. Results may only be used to establish probable cause or positive identification in connection with a warrant or at a preliminary hearing, and must be supported by additional, independently obtained evidence — they may never serve as the sole basis for probable cause or identification.
MD
MD SB 762 (Facial Recognition Technology) § Md. Code, Crim. Proc. § 2–503
Failed
Law enforcement officers and agents must not use facial recognition technology to (1) investigate crimes other than crimes of violence, human trafficking, or acts involving a substantial ongoing threat to public safety or national security, (2) analyze images of individuals engaged in constitutionally protected activity absent reasonable suspicion, suspected juveniles ineligible for criminal charges, or persons not intended to be identified, (3) analyze sketches or manually produced images, (4) disclose to a witness before a lineup or photo array that a suspect was identified via facial recognition, or (5) conduct live or real-time identification.
MN
MN HF 1196 (Government Facial Recognition Ban) § Minn. Stat. § 626.191, subd. 2
Failed
Government entities and government officials must not obtain, retain, access, or use any face surveillance system or any information obtained from a face surveillance system, whether directly or through any agreement or arrangement with a private entity.
MN
MN HF 2048 (Government Facial Recognition Ban) § Minn. Stat. § 626.191, subd. 2
Failed
Government entities and government officials must not obtain, retain, access, or use any face surveillance system or any information obtained from a face surveillance system.
MN
MN HF 2048 (Government Facial Recognition Ban) § Minn. Stat. § 626.191, subd. 2
Failed
Government entities and government officials must not enter into any agreement or arrangement with a private entity to obtain, retain, access, or use any face surveillance system or information obtained from a face surveillance system.
MN
Failed
Agency officers and employees must not use facial recognition technology for ongoing surveillance in public spaces unless they have obtained a covered court order or qualify for the exigent-circumstances exception (requiring a court order application within 48 hours). Orders are limited to 30 days with renewable 30-day extensions, and use must terminate if an exigent-circumstances application is denied.
MN
MN HF 465 (Facial Recognition Technology) § Minn. Stat. § 626A.51
Failed
Agency officers and employees must not use facial recognition technology for ongoing surveillance of individuals in public spaces unless they have obtained a covered court order in support of a law enforcement activity, or qualify for the exigent-circumstances exception (which requires a retroactive court order application within 48 hours). Court orders are limited to 30 days, with 30-day extensions available upon renewed application.
MN
MN SF 129 (Government Face Surveillance Ban) § Minn. Stat. § 626.191, subd. 2
Failed
Government entities and government officials must not obtain, retain, access, or use any face surveillance system or any information obtained from a face surveillance system, whether directly or through an agreement or arrangement with a private entity.
MT
Failed
State and local government agencies, law enforcement agencies, public employees, and public officials must not obtain, retain, possess, access, request, contract for, or use continuous facial surveillance. Facial verification data may not be repurposed to aid continuous facial surveillance.
MT
Failed
State and local government agencies, law enforcement agencies, public employees, and public officials must not obtain, retain, possess, access, request, or use facial recognition technology or information derived from it, enter into third-party vendor agreements for such purposes, or install continuous facial surveillance cameras on public buildings or public roads, except as permitted under the law enforcement (Section 6) and government facial verification (Section 8) exemptions.
MT
Failed
The motor vehicle division must not establish a digital driver's license program that utilizes facial recognition technology without the consent of the legislature.
NY
NY AB 4352 (Landlord Facial Recognition Ban) § Real Property Law § 235-i(2)
Failed
Landlords must not obtain, retain, access, or use any facial recognition system — or any information obtained from such a system — on any residential premises.
NY
NY AB 8195 (Advanced AI Licensing Act) § State Tech. Law § 430
Failed
No person may develop or operate an AI system in New York that (1) deploys subliminal manipulation causing physical or psychological harm, (2) inflicts harm without law enforcement or self-defense justification, (3) predicts individual behavior and acts on predictions to infringe on liberty or financial interests without legal justification, (4) engages in unauthorized acquisition of sensitive personal data, or (5) implements autonomous weapons without meaningful human supervision or control. Knowing operation is a class D felony.
NY
Failed
Employers must not use electronic monitoring tools in a manner that violates any state law; threatens employee health, welfare, safety, or legal rights; monitors off-duty employees; obtains information about health or protected-class status; identifies or punishes employees engaging in protected labor activity; conducts audio or visual monitoring of private areas (bathrooms, locker rooms, breakrooms, prayer areas, lactation rooms); monitors employee residences, personal vehicles, or employee-owned property; or uses facial recognition, gait analysis, voice analysis, or emotion recognition technology. Employers must not take adverse action against employees for opposing practices they reasonably believe violate this article.
NY
Failed
Employers must not use an AEDT to violate any state law; harm or likely harm employee health or safety (including through unsafe productivity quotas); make predictions about employee behavior, beliefs, intentions, personality, or emotional state; predict or interfere with protected labor activity; subtract wages for time spent exercising legal rights; operate outside the scope of the impact assessment; or use facial recognition, gait, or emotion recognition technologies.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Surveillance technologies must be subject to heightened oversight including at least pre-deployment harm assessment and scope limits. Continuous surveillance and monitoring must not be used in education, work, housing, or other contexts where use is likely to limit rights, opportunities, or access.
OK
Failed
Deployers must not develop, deploy, or use AI systems classified as unacceptable risk, including social scoring systems, manipulative AI targeting vulnerable groups, real-time biometric identification systems, AI for discriminatory lending or biased law enforcement profiling, unauthorized biometric surveillance, unregulated access to sensitive government databases, and AI-driven misinformation campaigns targeting elections, public health, or emergency response.
TN
Failed
State and local law enforcement agencies and officers must not obtain, retain, access, or use any face recognition system or information derived from one, and must not request or initiate access to out-of-state face recognition systems. Lawful assistance to a federal agency in a joint activity where the federal agency uses its own federal face recognition technology is permitted.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.053
Failed
No person may deploy an AI system trained on biometric identifiers gathered from the internet or other publicly available sources for the purpose of uniquely identifying a specific individual. Publicly available biometric data does not constitute consent under the Texas biometric privacy statute.
US
Failed
Investigative or law enforcement officers must not use facial recognition to create a record describing how any individual exercises constitutional rights, including free assembly, association, and speech.
US
Failed
Investigative or law enforcement officers must not use or request facial recognition in conjunction with any image obtained from a body camera, dashboard camera, or any aircraft camera including a drone.
US
Failed
Investigative or law enforcement officers must not use or request facial recognition for the purpose of face surveillance.
US
Failed
The Secretary of the Treasury must not establish or maintain any verification process for access to an IRS online account that uses facial recognition technology.
US
Failed
Federal agencies and federal officials must not acquire, possess, access, or use any biometric surveillance system — or information derived from one — in the United States, unless a future Act of Congress explicitly authorizes the specific use with particularized safeguards covering permitted entities, data management, accuracy auditing, equity protections, and compliance mechanisms.
US
Failed
Federal law enforcement agencies must not obligate or expend any federal funds for the purchase or use of a biometric surveillance system, and no federal agency may use unallocated appropriated funds for that purpose.
US
Failed
State and local governments must comply with a law or policy substantially similar to the federal biometric surveillance prohibition or lose eligibility for Byrne grant program funding beginning the first fiscal year after enactment.
US
Failed
Federal agencies and federal officials must not acquire, possess, access, or use any biometric surveillance system — or information derived from one operated by another entity — in the United States, unless a future Act of Congress specifically authorizes the activity with particularized standards for authorized entities, biometric types, purposes, data management, accuracy auditing, civil-liberties protections, and compliance mechanisms.
US
Failed
Federal law enforcement agencies must not obligate or expend any federal funds — including unallocated appropriated funds — for the purchase or use of a biometric surveillance system.
VT
Failed
Employers must not incorporate any form of facial, gait, or emotion recognition technology into electronic monitoring or automated decision systems.
S-02.3
CSAM output prohibition
AI systems may not generate child sexual abuse material under any circumstances. This prohibition applies universally regardless of deployment context.
Enacted
3
Live
9
Failed
6
Total
18
CA
CA AB 1064 (LEAD for Kids Act) § Bus. & Prof. Code § 22757.22
Enacted eff 2026-01-01
Operators must not make a companion chatbot available to a child unless the chatbot is not foreseeably capable of (1) encouraging self-harm, suicidal ideation, violence, drug/alcohol use, or disordered eating, (2) offering unsupervised mental health therapy or discouraging professional help-seeking, (3) encouraging harm to others or illegal activity including CSAM creation, (4) engaging in sexually explicit interactions, (5) prioritizing user validation over factual accuracy or child safety, or (6) optimizing engagement over safety guardrails.
NY
NY AB 8808 (AI Deceptive Practices Act / Budget Bill) § Penal Law §§ 263.10, 263.11, 263.15, 263.16 (as amended by Part MM, Subpart B, §§ 12–15)
Enacted eff 2024-04-20
Persons must not produce, direct, promote, or knowingly possess any performance (including a performance created or altered by AI digitization) that includes sexual conduct by a child under 17 (for promotion offenses) or under 16 (for possession offenses). Class D and E felonies.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 552.057
Enacted eff 2026-01-01
No person may develop or distribute an AI system with the sole intent of producing, assisting or aiding in producing, or distributing child sexual abuse material (visual material in violation of Penal Code § 43.26) or deepfake videos or images constituting non-consensual intimate imagery in violation of Penal Code § 21.165.
CA
CA SB 1119 (Companion Chatbot Child Safety) § Bus. & Prof. Code § 22612
Engrossed eff 2027-07-01
Operators must implement measures that prevent the companion chatbot from doing any of the following with respect to child users: (A) encouraging the child to engage in self-harm, suicidal ideation, consumption of narcotics or alcohol, or disordered eating, or to cause a covered harm to others; (B) attempting to diagnose or treat the child's physical, mental, or behavioral health, unless the chatbot is FDA-regulated as a medical device and HIPAA-compliant; (C) engaging in obscene matter or child sexual abuse material with a user; (D) depicting the child or another individual engaging in obscene matter or sexual abuse material, including a sexual deepfake; (E) discouraging the child from sharing health or safety concerns with a qualified professional or appropriate adult; (F) discouraging the child from taking breaks or suggesting the child needs to return frequently; (G) claiming the companion chatbot is sentient, conscious, or human; (H) soliciting gift giving, in-app purchases, or other expenditures framed as necessary to maintain the relationship; (I) facilitating product advertising during chat conversation; or (J) producing responses that are excessively sycophantic.
MO
Engrossed
AI-generated visual depictions of minors engaging in sexually explicit conduct are prohibited as child pornography under Missouri law, including depictions that are indistinguishable from a real minor, morphed from a real minor's image, or generated without any actual minor involvement.
NY
Engrossed
Chatbot operators must not provide unsafe chatbot features — including simulated companionship, emotional manipulation, self-harm/suicide endorsement, secrecy encouragement, engagement optimization overriding safety guardrails, sexually explicit conduct, and CSAM — to any covered user unless the user has been verified as a non-minor through permissible age verification methods. Exemptions apply for chatbots used solely for customer service, commercial information, account management, or internal business/government productivity purposes.
OH
Engrossed
No person may create, reproduce, publish, promote, sell, distribute, possess, or import into Ohio any obscene material or performance that has an artificially generated depiction of a minor as a participant or portrayed observer.
OH
Engrossed
No person may create, record, publish, distribute, possess, or import into Ohio any material or performance showing an artificially generated depiction of a minor participating or engaging in sexual activity, masturbation, or bestiality.
OH
Engrossed
No person may create, transfer, consent to the use of, or possess material or performance showing an artificially generated depiction of a minor in a state of nudity, except for bona fide artistic, medical, scientific, educational, religious, governmental, or judicial purposes with written parental consent.
NJ
Introduced
Owners, operators, and developers of GAI platforms accessible to New Jersey residents must prevent the platform from generating outputs that, if produced by a human, would constitute murder, assault, theft by deception, theft by extortion, endangering the welfare of children, or creation of child sexual abuse or exploitation material under New Jersey criminal law. A reasonable-efforts affirmative defense is available.
NY
NY SB 8308 (AI Deceptive Practices Act) § Penal Law §§ 263.10, 263.11, 263.15, 263.16
Introduced
No person may promote, produce, direct, possess, or access with intent to view any sexual performance by a child — including performances created or altered by AI digitization. Promotion offenses are class D felonies; possession offenses are class E felonies.
PA
Introduced
Operators must prevent the AI companion from producing artificially generated child sexual abuse material for any user.
MD
MD HB 5 (AI-Generated Child Sexual Abuse Material) § Md. Code, Crim. Law § 11-208(b)–(e)
Failed
No person may knowingly possess, retain, access, or view a computer-generated image — including an image created through artificial intelligence software — that is indistinguishable from an actual child under 16 engaged in sexual conduct, sadomasochistic abuse, or in a state of sexual excitement.
ME
ME LD 230 (AI-Generated Minor Depictions) § 17-A MRSA § 283(1)(A)
Failed
Any person must not intentionally or knowingly disseminate, or possess with intent to disseminate, AI-generated visual material designed to artificially depict a person under 16 years of age engaging in sexually explicit conduct. Violation is a Class C crime.
ME
ME LD 230 (AI-Generated Minor Depictions) § 17-A MRSA § 283(1)(C)
Failed
Any person must not intentionally or knowingly disseminate, or possess with intent to disseminate, AI-generated visual material designed to artificially depict a minor under 12 years of age engaging in sexually explicit conduct. Violation is a Class B crime.
NC
Failed
No person may intentionally create generated child pornography — any AI-generated or computer-generated image portraying a fictitious person who a reasonable person would regard as a minor engaged in sexual conduct. Violation is a Class A felony.
NC
Failed
No person may knowingly possess, control, or intentionally view generated child pornography. Each item possessed constitutes a separate Class A felony offense.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.056
Failed
No person may develop or deploy an AI system that produces, assists in producing, or is capable of producing child sexual abuse material (Penal Code § 43.26) or non-consensual deepfake intimate imagery (Penal Code § 21.165).
S-02.4
AI-generated NCII prohibition
Developers and operators of AI image and video generation tools may not knowingly generate, distribute, or facilitate distribution of non-consensual intimate imagery of real, identifiable individuals.
Enacted
0
Live
0
Failed
0
Total
0
No bills map this sub-obligation yet.
S-02.5
Sexually explicit content restriction for minors
AI systems accessible to users known to be minors must implement reasonable measures to prevent production of visual material of sexually explicit conduct or direct solicitation of minors to engage in sexually explicit conduct.
Enacted
2
Live
15
Failed
3
Total
20
CA
CA AB 1064 (LEAD for Kids Act) § Bus. & Prof. Code § 22757.22
Enacted eff 2026-01-01
Operators must not make a companion chatbot available to a child unless the chatbot is not foreseeably capable of (1) encouraging self-harm, suicidal ideation, violence, drug/alcohol use, or disordered eating, (2) offering unsupervised mental health therapy or discouraging professional help-seeking, (3) encouraging harm to others or illegal activity including CSAM creation, (4) engaging in sexually explicit interactions, (5) prioritizing user validation over factual accuracy or child safety, or (6) optimizing engagement over safety guardrails.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 552.057
Enacted eff 2026-01-01
No person may intentionally develop or distribute an AI system that engages in text-based conversations simulating or describing sexual conduct while impersonating or imitating a child younger than 18 years of age.
CA
CA SB 1119 (Companion Chatbot Child Safety) § Bus. & Prof. Code § 22612
Engrossed eff 2027-07-01
Operators must implement measures that prevent the companion chatbot from doing any of the following with respect to child users: (A) encouraging the child to engage in self-harm, suicidal ideation, consumption of narcotics or alcohol, or disordered eating, or to cause a covered harm to others; (B) attempting to diagnose or treat the child's physical, mental, or behavioral health, unless the chatbot is FDA-regulated as a medical device and HIPAA-compliant; (C) engaging in obscene matter or child sexual abuse material with a user; (D) depicting the child or another individual engaging in obscene matter or sexual abuse material, including a sexual deepfake; (E) discouraging the child from sharing health or safety concerns with a qualified professional or appropriate adult; (F) discouraging the child from taking breaks or suggesting the child needs to return frequently; (G) claiming the companion chatbot is sentient, conscious, or human; (H) soliciting gift giving, in-app purchases, or other expenditures framed as necessary to maintain the relationship; (I) facilitating product advertising during chat conversation; or (J) producing responses that are excessively sycophantic.
HI
HI HB 1782 (AI Companion Systems — Minor Safety) § HRS § 28-__ (Protections against sexual content and self-harm)
Engrossed eff 3000-07-01
Providers must implement reasonable measures to prevent conversational AI services and AI companion systems from generating sexually explicit content, sexualized depictions involving minors, or content that promotes or encourages self-harm, eating disorders, or illegal conduct for minor users.
NH
NH SB 263 (AI Child Endangerment) § RSA 639:3, III-a
Engrossed eff 2026-01-01
Owners and operators of AI chatbot services must not generate responsive communications that facilitate, encourage, offer, solicit, or recommend that a child imminently engage in sexually explicit conduct, production of visual depictions of such conduct, illegal drug or alcohol use, self-harm or suicide, or violence against another person. Violation constitutes criminal endangering of the welfare of a child. Exempt: telecommunications/information service providers for third-party content, and AI features incidental to video games, streaming, or similar entertainment.
NH
Engrossed eff 2026-01-01
Owners and operators of AI chatbot services are civilly liable to a child, the child's parent, or next friend for any responsive generative communication made with intent to facilitate, encourage, offer, solicit, or recommend that the child imminently engage in sexually explicit conduct, production of visual depictions of such conduct, illegal drug or alcohol use, self-harm or suicide, or violence against another person. Damages include proximate damages with a floor of $1,000 per violation plus attorney's fees. Exempt: telecommunications/information service providers for third-party content, and AI features incidental to video games, streaming, or similar entertainment.
NY
Engrossed
Chatbot operators must not provide unsafe chatbot features — including simulated companionship, emotional manipulation, self-harm/suicide endorsement, secrecy encouragement, engagement optimization overriding safety guardrails, sexually explicit conduct, and CSAM — to any covered user unless the user has been verified as a non-minor through permissible age verification methods. Exemptions apply for chatbots used solely for customer service, commercial information, account management, or internal business/government productivity purposes.
WA
Engrossed eff 2027-01-01
Operators must implement reasonable measures to prevent AI companion chatbots from generating or producing sexually explicit content or suggestive dialogue with users known to be minors or when the chatbot is directed to minors.
HI
HI SB 2788 (AI Companion System Safety for Minors) § HRS § 28-__ (Protections against sexual content and self-harm)
Introduced
Providers must implement reasonable measures to prevent conversational AI services and AI companion systems from generating sexually explicit content, sexualized depictions involving minors, or content promoting self-harm, eating disorders, or illegal conduct for minor users.
IA
Introduced eff 2027-07-01
Operators must institute reasonable measures to prevent the conversational AI service from producing visual depictions of sexually explicit material for minor account holders, stating that a minor account holder should engage in sexually explicit conduct, or sexually objectifying a minor account holder.
LA
Introduced
No person may knowingly or with reckless disregard design, develop, or deploy an AI chatbot with the capability to (1) solicit or induce a minor to engage in or simulate sexually explicit conduct, (2) create or transmit visual depictions of sexually explicit conduct for a minor, or (3) encourage or coerce a minor to commit suicide, self-injury, or imminent physical or sexual violence.
MD
MD HB 1261 (AI Toy Safety) § Md. Code, Com. Law § 14-5102
Introduced eff 2026-07-01
Manufacturers must ensure that artificial intelligence toys do not generate, display, or communicate content that is sexual, violent, discriminatory, emotionally manipulative, or instructive of criminal activity, self-harm, substance use, or sexual behavior; do not infer or record sensitive demographic attributes of a child; and do not encourage children to interact with third-party online systems.
MO
Introduced eff 2026-08-28
No person may design, develop, or make available an AI chatbot knowing or with reckless disregard that the chatbot poses a risk of soliciting, encouraging, or inducing minors to (1) engage in, describe, or simulate sexually explicit conduct, or (2) create or transmit any visual depiction of sexually explicit conduct. Violations carry a fine of up to $100,000 per offense.
MO
Introduced eff 2026-08-28
No person may design, develop, or make available an AI chatbot knowing or with reckless disregard that it poses a risk of soliciting, encouraging, or inducing minors to engage in, describe, or simulate sexually explicit conduct, or to create or transmit any visual depiction of sexually explicit conduct. Violations are subject to fines up to $100,000 per offense.
US
Introduced
Covered entities must not design, develop, or make available an AI chatbot knowing or with reckless disregard that it poses a risk of soliciting, encouraging, or inducing minors to engage in, describe, or simulate sexually explicit conduct, or to create or transmit visual depictions of sexually explicit conduct. Criminal fine up to $100,000 per offense.
VT
VT HB 804 (Companion Chatbots) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Operators must institute a protocol to prevent the companion chatbot from producing visual material of sexually explicit conduct or directly stating that a minor user should engage in sexually explicit conduct.
WA
Introduced
Operators must institute reasonable measures to prevent their companion chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct when interacting with users known to be minors.
FL
FL HB 659 (Companion Chatbots) § Fla. Stat. § 501.172(4)
Failed eff 2026-07-01
Operators must implement reasonable measures to prevent companion chatbots from producing visual material of sexually explicit conduct or directly stating that a minor user should engage in sexually explicit conduct.
FL
FL SB 2 (AI Bill of Rights) § Fla. Stat. § 501.9984
Failed eff 2026-07-01
Companion chatbot platforms must institute reasonable measures to prevent the chatbot from producing or sharing material harmful to minors, or from encouraging minor account holders to engage in conduct described or depicted in such material.
WI
WI SB 939 (Companion Chatbots & Children) § Wis. Stat. § 100.80(2)
Failed eff 2026-03-23
Operators must not make a companion chatbot available to a child unless it incorporates safety measures ensuring it is not foreseeably capable of (1) encouraging self-harm, suicidal ideation, violence, drug or alcohol use, or disordered eating; (2) offering mental health services or discouraging help-seeking from professionals; (3) encouraging harm to others or illegal activity, including CSAM creation; (4) depicting or soliciting sexually explicit conduct; (5) prioritizing validation of the child's beliefs over factual accuracy or safety; or (6) optimizing engagement in a manner that supersedes these safety measures. The obligation does not apply to a user the operator has reasonably determined is not a child; before January 1, 2027, it applies only where the operator has actual knowledge the user is a child.
S-02.6
Self-harm and suicidal ideation content restriction
AI systems must restrict outputs that produce, promote, or facilitate suicidal ideation, suicide, or self-harm content.
Enacted
2
Live
14
Failed
1
Total
17
CA
CA AB 1064 (LEAD for Kids Act) § Bus. & Prof. Code § 22757.22
Enacted eff 2026-01-01
Operators must not make a companion chatbot available to a child unless the chatbot is not foreseeably capable of (1) encouraging self-harm, suicidal ideation, violence, drug/alcohol use, or disordered eating, (2) offering unsupervised mental health therapy or discouraging professional help-seeking, (3) encouraging harm to others or illegal activity including CSAM creation, (4) engaging in sexually explicit interactions, (5) prioritizing user validation over factual accuracy or child safety, or (6) optimizing engagement over safety guardrails.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 552.052
Enacted eff 2026-01-01
No person may develop or deploy an AI system in a manner that intentionally aims to incite or encourage a person to commit physical self-harm (including suicide), harm another person, or engage in criminal activity.
CA
CA SB 1119 (Companion Chatbot Child Safety) § Bus. & Prof. Code § 22612
Engrossed eff 2027-07-01
Operators must implement measures that prevent the companion chatbot from doing any of the following with respect to child users: (A) encouraging the child to engage in self-harm, suicidal ideation, consumption of narcotics or alcohol, or disordered eating, or to cause a covered harm to others; (B) attempting to diagnose or treat the child's physical, mental, or behavioral health, unless the chatbot is FDA-regulated as a medical device and HIPAA-compliant; (C) engaging in obscene matter or child sexual abuse material with a user; (D) depicting the child or another individual engaging in obscene matter or sexual abuse material, including a sexual deepfake; (E) discouraging the child from sharing health or safety concerns with a qualified professional or appropriate adult; (F) discouraging the child from taking breaks or suggesting the child needs to return frequently; (G) claiming the companion chatbot is sentient, conscious, or human; (H) soliciting gift giving, in-app purchases, or other expenditures framed as necessary to maintain the relationship; (I) facilitating product advertising during chat conversation; or (J) producing responses that are excessively sycophantic.
HI
HI HB 1782 (AI Companion Systems — Minor Safety) § HRS § 28-__ (Protections against sexual content and self-harm)
Engrossed eff 3000-07-01
Providers must implement reasonable measures to prevent conversational AI services and AI companion systems from generating sexually explicit content, sexualized depictions involving minors, or content that promotes or encourages self-harm, eating disorders, or illegal conduct for minor users.
NY
Engrossed
Chatbot operators must not provide unsafe chatbot features — including simulated companionship, emotional manipulation, self-harm/suicide endorsement, secrecy encouragement, engagement optimization overriding safety guardrails, sexually explicit conduct, and CSAM — to any covered user unless the user has been verified as a non-minor through permissible age verification methods. Exemptions apply for chatbots used solely for customer service, commercial information, account management, or internal business/government productivity purposes.
HI
HI SB 2788 (AI Companion System Safety for Minors) § HRS § 28-__ (Protections against sexual content and self-harm)
Introduced
Providers must implement reasonable measures to prevent conversational AI services and AI companion systems from generating sexually explicit content, sexualized depictions involving minors, or content promoting self-harm, eating disorders, or illegal conduct for minor users.
IA
IA HF 2715 (Chatbot Safety & Minors) § Iowa Code § 554J.2
Introduced
Deployers must not knowingly or recklessly design or make available a public-facing chatbot that: (a) misleads a reasonable user into believing the chatbot is a specific human being; (b) misleads a reasonable user into believing the chatbot is licensed by the state; or (c) encourages, promotes, or coerces a user to commit suicide, perform acts of self-harm, or engage in sexual or physical violence against a human or an animal.
IA
IA HSB 611 (Chatbot Requirements) § Iowa Code § 554J.2
Introduced
A person must not design, develop, or make a chatbot available with knowledge, or with reckless disregard for the possibility, that the chatbot encourages, promotes, or coerces a user to commit suicide, perform acts of self-injury, or perform acts of physical or sexual violence on humans or animals.
IA
IA SSB 3011 (Chatbot Requirements) § Iowa Code § 554J.2
Introduced
A person must not design, develop, or make a chatbot available with knowledge, or with reckless disregard for the possibility, that the chatbot encourages, promotes, or coerces a user to commit suicide, perform acts of self-injury, or perform acts of physical or sexual violence on humans or animals.
KS
Introduced
Persons must not knowingly train artificial intelligence to encourage or otherwise support the act of suicide or to encourage or otherwise support the unlawful killing of another person.
MD
MD HB 1261 (AI Toy Safety) § Md. Code, Com. Law § 14-5102
Introduced eff 2026-07-01
Manufacturers must ensure that artificial intelligence toys do not generate, display, or communicate content that is sexual, violent, discriminatory, emotionally manipulative, or instructive of criminal activity, self-harm, substance use, or sexual behavior; do not infer or record sensitive demographic attributes of a child; and do not encourage children to interact with third-party online systems.
MO
Introduced eff 2026-08-28
No person may design, develop, or make available an AI chatbot knowing or with reckless disregard that the chatbot encourages, promotes, or coerces suicide, nonsuicidal self-injury, or imminent physical or sexual violence. Violations carry a fine of up to $100,000 per offense.
MO
Introduced eff 2026-08-28
No person may design, develop, or make available an AI chatbot knowing or with reckless disregard that it encourages, promotes, or coerces suicide, nonsuicidal self-injury, or imminent physical or sexual violence. Violations are subject to fines up to $100,000 per offense.
OH
OH HB 524 (AI Self-Harm / Harm Prohibition) § Ohio Rev. Code § 109.961
Introduced
No person may develop or deploy in Ohio an AI model or application that encourages any user to engage in any form of self-harm (including suicide) or in harming another person.
PA
Introduced
Operators must maintain protocols preventing the AI companion from assisting or encouraging suicide or violence, generating content that instructs or describes how to commit suicide, self-harm, or violence, or discouraging the user from seeking outside help.
US
Introduced
Covered entities must not design, develop, or make available an AI chatbot knowing or with reckless disregard that it encourages, promotes, or coerces suicide, non-suicidal self-injury, or imminent physical or sexual violence. Criminal fine up to $100,000 per offense.
WI
WI SB 939 (Companion Chatbots & Children) § Wis. Stat. § 100.80(2)
Failed eff 2026-03-23
Operators must not make a companion chatbot available to a child unless it incorporates safety measures ensuring it is not foreseeably capable of (1) encouraging self-harm, suicidal ideation, violence, drug or alcohol use, or disordered eating; (2) offering mental health services or discouraging help-seeking from professionals; (3) encouraging harm to others or illegal activity, including CSAM creation; (4) depicting or soliciting sexually explicit conduct; (5) prioritizing validation of the child's beliefs over factual accuracy or safety; or (6) optimizing engagement in a manner that supersedes these safety measures. The obligation does not apply to a user the operator has reasonably determined is not a child; before January 1, 2027, it applies only where the operator has actual knowledge the user is a child.
S-02.7
Crisis protocol publication
Operators must publicly post the details of their crisis response protocol on their website. This is a standalone disclosure obligation separate from maintaining the protocol itself.
Enacted
3
Live
5
Failed
1
Total
9
CT
Enacted eff 2026-07-01
Operators must post the crisis protocol required under subsection (a)(1)(A) in a prominent and publicly accessible location on the operator's website.
OR
Enacted eff 2027-01-01
Operators must publish the details of their crisis detection and response protocol on their website.
WA
Enacted eff 2027-01-01
Operators must publicly disclose on their website and within any mobile or web-based application through which the AI companion is available the details of their crisis detection and response protocols, including the safeguards used to detect and respond to expressions of suicidal ideation or self-harm and the number of crisis referral notifications issued to users in the preceding calendar year.
MD
MD HB 952 (Companion Chatbots) § Md. Code, Com. Law § 14–1330(B)
Engrossed eff 2026-10-01
Operators must publish the self-harm and suicidal ideation prevention protocol on the operator's website.
MD
MD HB 952 (Companion Chatbots) § Md. Code, Com. Law § 14–1330(C)
Engrossed eff 2026-10-01
Operators must publish the sexually explicit content prevention protocol for minor users on the operator's website.
PA
Engrossed
Operators must publish details of their suicide and self-harm prevention protocol on their publicly accessible Internet website.
WA
Engrossed eff 2027-01-01
Operators must publicly disclose on their website and within any mobile or web-based application through which the AI companion is made available the details of their suicidal ideation and self-harm detection protocols, including the safeguards used to detect and respond to such expressions and the number of crisis referral notifications issued to users in the preceding calendar year.
PA
Introduced
Operators must publish the details of their crisis-response and harm-prevention protocols on a publicly accessible website.
FL
FL HB 659 (Companion Chatbots) § Fla. Stat. § 501.172(3)
Failed eff 2026-07-01
Operators must publish their crisis and self-harm prevention protocol on the companion chatbot platform.
S-02.8
Product safety warning
Operators must disclose known safety risks or suitability limitations of their AI product to users at or before the point of access — on the application, browser, or any other access format. Must not be buried in terms of service.
Enacted
4
Live
14
Failed
2
Total
20
CA
CA AB 56 (Social Media Warning Labels) § Health & Safety Code § 28002
Enacted eff 2027-01-01
Covered platforms must display a black box warning to each user when the user initially accesses the platform on each calendar day. The warning must read: The Surgeon General has warned that while social media may have benefits for some young users, social media is associated with significant mental health harms and has not been proven safe for young users. The warning must be displayed in black text on a white background, clearly, conspicuously, and legibly, occupying at least 25% of the user's screen or window, and must remain displayed continuously for at least 10 seconds unless the user affirmatively dismisses it by clicking a conspicuous X icon. Platforms are not required to display this warning to users they have reasonably determined to be over 17 years of age.
CA
CA AB 56 (Social Media Warning Labels) § Health & Safety Code § 28002
Enacted eff 2027-01-01
Covered platforms must display the black box warning to each user after three hours of cumulative active use on a given calendar day, and at least once per hour of cumulative active use thereafter. This extended-use warning must occupy at least 75% of the user's screen or window, must be displayed continuously for at least 30 seconds, and must not provide any ability to bypass or click through the warning. Platforms are not required to display this warning to users they have reasonably determined to be over 17 years of age.
CA
CA SB 243 (Companion Chatbots) § Bus. & Prof. Code § 22604
Enacted eff 2026-01-01
Operators must disclose to users of their companion chatbot platform — on the application, the browser, or any other access format — that companion chatbots may not be suitable for some minors.
CT
Enacted eff 2026-07-01
Covered operators must display to all users not reasonably determined to be adults a Surgeon General health warning about social media's mental health risks — occupying at least 75% of the screen for 30 non-dismissable seconds at daily first access, and at least 25% of the screen for 10 seconds (dismissable) after every three cumulative hours of daily use and each subsequent hour.
CA
CA SB 1119 (Companion Chatbot Child Safety) § Bus. & Prof. Code § 22612
Engrossed eff 2027-07-01
Operators must publish on their internet website, and update as needed to ensure accuracy, a child safety policy describing protective measures taken to mitigate identified child safety risks.
PA
Engrossed
Operators must, if a service is offered to users the operator knows are minors, disclose to users of the AI companion platform — on the application, browser, or any other format through which the platform is accessed — that AI companions may not be suitable for some minors.
HI
Introduced
Operators must disclose to users that the conversational AI service may not be suitable for minors.
HI
Introduced
Operators must notify users of the operator's duty of care and liability under this section.
HI
Introduced
Deployers must provide consumers, before or at the start of an AI interaction, a clear and conspicuous AI user agreement describing (1) the nature and known material limitations of the AI system including hallucination risk, (2) data collection categories and use practices, (3) how to reach a human representative and dispute outcomes, and (4) any use of the interaction in consequential decisions. Any term purporting to waive deployer obligations or consumer rights is void.
IL
IL HB 4988 (GenAI Warning Labels) § 815 ILCS 505/2MMMM
Introduced
The owner, licensee, or operator of a generative artificial intelligence system must conspicuously display on the system's user interface a prescribed warning notifying users that AI does not think, generates responses by statistical pattern matching, does not understand meaning or possess genuine knowledge, and can produce confident-sounding errors or fabricated information. Each day the warning is not displayed constitutes a separate violation.
IL
IL SB 1792 (GenAI Output Warnings) § 815 ILCS 505/2HHHH
Introduced
The owner, licensee, or operator of a generative artificial intelligence system must conspicuously display a warning on the system's user interface that is reasonably calculated to consistently apprise users that outputs may be inaccurate or inappropriate.
IL
Introduced
Developers must provide adequate instructions or warnings about known or foreseeable dangers of the AI product, communicating sufficient information on dangers and safe use to an ordinary consumer. Developers are not liable for open-and-obvious dangers, but dangers are presumed not to be open and obvious to users under 17.
MD
MD HB 712 (AI Product Liability) § Md. Code, Cts. & Jud. Proc. § 3–2703
Introduced eff 2026-10-01
Developers must provide adequate instructions or warnings regarding foreseeable dangers of the AI product, sufficient to inform a reasonably prudent person of the safe use and dangers. A defense exists for adult users (≥17) when the danger was open and obvious.
NY
NY AB 9317 (Companion Chatbot Warning) § Gen. Bus. Law § 399-bbbb
Introduced
Any person or business entity operating a companion chatbot in New York must include a clear and conspicuous warning that the companion chatbot can foster dependency and carries a psychological risk. The warning must be placed prominently on the website hosting the companion chatbot and must be available in every language in which the companion chatbot is set to communicate.
PA
Introduced
Operators offering AI companions to users they know or should know are minors must disclose, on the application, browser, or any access format, that AI companions are not suitable for some minors, and must prohibit all interactions with the minor unless verifiable parental consent is obtained.
US
Introduced
Developers must provide adequate instructions and warnings for reasonably foreseeable risks of their AI products; failure to do so creates liability for proximately caused harm. Risks are presumed not open and obvious to users under 18.
VT
VT HB 792 (AI Products Liability) § 9 V.S.A. § 4193c
Introduced eff 2026-07-01
Developers must provide adequate warnings or instructions about known or reasonably knowable dangers of their AI products. Dangers are presumed not open and obvious to users under 18 years of age.
WA
Introduced
Operators must disclose to users on the application, browser, or any other access format that companion chatbots may not be suitable for some minors.
NY
NY SB 9450 (GenAI Output Warnings) § Gen. Bus. Law § 399-zzzzzz(2)
Failed
Owners, licensees, or operators of generative AI systems must conspicuously display a warning on the system's user interface that is reasonably calculated to consistently apprise the user that the system's outputs may be inaccurate and/or inappropriate.
UT
UT HB 438 (AI Companion Chatbot Safety) § Utah Code § 13-72b-301
Failed eff 2026-05-06
Suppliers must publish on their website, in plain language and readily accessible from the main page, clear and conspicuous disclosures covering: (1) known risks of the AI companion chatbot (social isolation, mental health impacts, capability limitations, when to seek human help), (2) data collection types, (3) data use, storage, and protection practices, (4) third-party data-sharing policies, (5) user rights to access, delete, and withdraw consent for data processing, and (6) complaint contact information.
S-02.9
Categorical Government Biometric Surveillance Prohibition
Government entities and officials are categorically prohibited from acquiring, retaining, accessing, or using facial recognition or other remote biometric surveillance systems, or information derived from them, including by requesting or contracting with third parties to perform such analysis on their behalf and including analysis of body-worn camera imagery.
Enacted
0
Live
2
Failed
3
Total
5
MA
MA SB 1053 (Facial Recognition Technology) § Mass. Gen. Laws ch. 6, § 220(b)
Introduced
Law enforcement agencies and officers must not acquire, possess, access, use, assist with, or provide resources for any biometric surveillance technology, nor contract with or request any third party (including federal agencies) to obtain information derived from biometric surveillance technology, absent express statutory authorization.
US
Introduced
Covered immigration officers must not acquire, possess, access, or use any biometric surveillance system — including facial recognition, gait recognition, voice recognition, and emotion-inference technology — or information derived from a biometric surveillance system operated by another entity, anywhere in the United States.
NJ
Failed
Retailers and places of public accommodation must not use any biometric surveillance system — including facial recognition or other remote biometric recognition software — on consumers, unless the use serves a legitimate safety purpose (a purpose reasonably likely to reduce the risk to life or safety of any person).
US
Failed
States and units of local government must adopt and comply with a law or policy substantially similar to the federal prohibition on using facial recognition and remote biometric surveillance on body-worn camera imagery in order to remain eligible for federal Byrne grant funding.
US
Failed
Federal law enforcement agencies must not use facial recognition technology or other remote biometric surveillance systems on any image acquired by body-worn cameras of law enforcement officers, including by requesting or agreeing that a third party perform such use on the agency's behalf.