Federal
US · Federal
◆Binding
Binds Anyone publishing non-consensual intimate imagery; covered online platforms (notice-and-removal). Bans non-consensual intimate imagery incl. AI deepfakes; covered platforms must remove within 48h (notice-and-removal duty live 19 May 2026).
Stated maximum penalty — FTC enforcement; criminal penalties
US · Federal
▲Proposed
Binds AI system developers meeting both: $100M+ training compute and $500M+ annual gross AI revenue. Frontier AI developers meeting dual thresholds ($100M dev compute, $500M annual AI revenue) must implement kill-switch capability; 15-day DHS incident reporting; DHS/CISA authority to compel emergency shutdown.
Introduced Jul 23, 2026 by Reps. Lieu (D) and Moran (R) as H.R. 9917; referred to the House Committee on Homeland Security same day; triggered by OpenAI/Hugging Face hack incident. 119th Congress.
Stated maximum penalty — Up to $2M/day (general); up to $20M/day (defying shutdown order)
State — AL
US · AL
◆Binding
Binds Health insurers using AI in coverage determinations in Alabama. AI may not be sole basis for coverage denial; health insurers must disclose AI use and file annual certification with Alabama DOI.
Annual certification to Alabama DOI required.
Stated maximum penalty — Alabama DOI disciplinary action (license revocation/suspension)
State — CA
US · CA
◆Binding
Binds Operators of companion-chatbot platforms available in California. AI-status disclosure + self-harm protocols.
Stated maximum penalty — Private right of action
US · CA
◆Binding
Binds Frontier AI developers (>1e26 training ops); large frontier developers (>$500M revenue). Safety frameworks + critical-incident reporting to Cal OES for frontier developers.
Stated maximum penalty — Up to $1M per violation
US · CA
◆Binding
Binds Developers of generative AI systems made available to Californians. Public dataset-summary disclosure for generative AI offered to Californians.
Stated maximum penalty — Civil enforcement
US · CA
◆Binding
Binds Covered GenAI providers with >1M monthly users accessible in California. AI-detection tool + content provenance for >1M-user providers.
Stated maximum penalty — Civil penalties per violation/day
US · CA
◆Binding
Binds Large online platforms and device manufacturers with >1M monthly users/visitors in California. Extends SB 942 AI-detection & watermarking duties to large platforms and device manufacturers; Phase 2 obligations (1M+ users) from Jan 1, 2027.
Phase 1 (Aug 2, 2026): AI detection tools & manifest disclosures. Phase 2 (Jan 1, 2027): additional large-platform obligations.
Stated maximum penalty — $5,000/day per violation
US · CA
◆Binding
Binds California K-12 public school districts, county offices of education, and charter schools engaging employees or contractors. Requires that all K-12 public school employees and independent contractors performing employee-equivalent functions be natural persons; prohibits schools from contracting with AI systems to fill legally recognized employee or contractor roles. Does NOT ban AI tools in classrooms — lesson planning, grading support, translation, tutoring/student practice tools, and other AI-assisted instruction remain permitted.
Chaptered June 30 2026 as Ch. 45, Stats. 2026; adds Education Code §98; effective 2027-01-01.
Stated maximum penalty — Not specified in bill text; subject to existing Education Code enforcement mechanisms
State — CO
US · CO
◆Binding
Binds Regulated psychotherapy professionals in Colorado using AI; any entity misrepresenting AI as professional-equivalent. AI cannot deliver psychotherapy without licensed professional's real-time involvement; disclosure and written consent required.
Stated maximum penalty — Unfair trade practice (CO Consumer Protection Act; AG enforcement)
US · CO
◆Binding
Binds Developers & deployers of automated decision-making tech in consequential decisions. ADMT documentation, consumer notice & appeal rights.
Stated maximum penalty — AG enforcement; per violation
US · CO
◆Binding
Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.
Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01.
Stated maximum penalty — CO AG enforcement
US · CO
◆Binding
Binds Health insurers, pharmacy benefit managers, and managed care entities using AI for utilization review in Colorado. Health insurers and managed care entities using AI for coverage determinations must require human clinician review before denying coverage; AI decisions must be individualized and non-discriminatory; periodic audits required.
Signed June 2, 2026; effective January 1, 2027.
Stated maximum penalty — State insurance enforcement; penalty amount not specified in primary source
State — CT
US · CT
◆Binding
Binds Subscription AI providers, frontier developers, AI companion operators, AEDT deployers, and social media platforms serving Connecticut users. Tiered AI obligations: subscription AI disclosures (Oct 2026), companion AI safeguards (Jan 2027), AEDT pre-decision notices (Oct 2027), social media minor restrictions (Jan 2028).
Multiple tiers: subscription AI disclosures 2026-10-01; AI companion 2027-01-01; AEDT disclosures 2027-10-01; social media minor restrictions 2028-01-01.
Stated maximum penalty — CT AG enforcement (unfair/deceptive trade practices)
State — GA
US · GA
◆Binding
Binds Health insurers and utilization review entities in Georgia. AI prohibited from issuing adverse prior-authorization determinations without licensed clinical peer review.
Stated maximum penalty — Georgia Insurance Commissioner enforcement
US · GA
◆Binding
Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.
Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)
State — HI
US · HI
◆Binding
Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.
Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.
Stated maximum penalty — $1,000/violation up to $1,000,000/operator
US · HI
◆Binding
Binds Anyone who knowingly publishes realistic AI-generated imitations of identifiable persons without consent; advertisers using synthetic performers in a materially deceptive manner. Two-part law: (1) prohibits publishing unauthorized AI-generated realistic imitations of identifiable persons for use in advertising, fraud, harassment, defamation, or election interference — victims may sue for up to $25,000 per piece or actual damages; (2) requires conspicuous disclosure when synthetic performers (AI-fabricated human assets not recognizable as any real individual) appear in advertising in a materially deceptive manner.
Stated maximum penalty — Up to $25,000 per piece of content or actual damages, plus punitive damages and attorneys fees (Part I — private civil action + AG); $1,000 first violation / $5,000 subsequent violations (Part II — AG enforcement)
State — IA
US · IA
◆Binding
Binds Operators of conversational AI services serving Iowa consumers. Disclosure and safeguard obligations for conversational AI operators serving Iowa users; compliance applicable 2027-07-01.
Law in force 2026-07-01; compliance obligations applicable from July 1, 2027.
Stated maximum penalty — Civil enforcement by Iowa AG (amount TBD)
US · IA
◆Binding
Binds Health carriers and utilization review organizations operating in Iowa. AI cannot be sole basis for denying medically necessary services; human clinical review required for adverse determinations.
Electronic prior authorization required from 2027-07-01.
Stated maximum penalty — Iowa Insurance Division enforcement
State — ID
US · ID
◆Binding
Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.
Modeled on Nebraska LB 525. Signed 2026-04-01.
Stated maximum penalty — Idaho AG enforcement (amount TBD)
State — IL
US · IL
◆Binding
Binds Employers & employment agencies using AI in employment decisions. Bars discriminatory AI use in hiring; notice required.
Stated maximum penalty — IDHR enforcement
US · IL
◆Binding
Binds Large frontier AI developers (>$500M revenue, trained on massive compute) operating in Illinois. Large frontier AI developers must publish safety frameworks, annual third-party audits, and report critical incidents within 72 hours.
Signed 2026-07-06.
Stated maximum penalty — Up to $1M first offense; up to $3M subsequent violations
US · IL
◆Binding
Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.
Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.
Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified
US · IL
◆Binding
Binds Health insurance issuers and managed care organizations in Illinois (excludes self-insured ERISA plans and workers' compensation). Prohibits health insurers and managed care organizations from using algorithms or automated tools to downcode medical claims without comprehensive human review; requires AMA CPT coding guideline-compliant physician review of all downcoding determinations; bans discriminatory targeting of providers treating complex/chronic patients.
Signed 2026-07-10 by Governor Pritzker; effective 2028-01-01.
Stated maximum penalty — Fines, restitution, or license suspension (IL Department of Insurance enforcement)
US · IL
▲Proposed
Binds Landlords of residential units in Illinois and third-party algorithmic pricing service providers who facilitate rental price coordination. Amends the Illinois Antitrust Act to prohibit landlords and third-party services from using AI algorithms to coordinate residential rental pricing; specifically targets algorithmic platforms (e.g., RealPage) used by competing landlords to fix or stabilize rents.
The AI rental-pricing language no longer exists in this bill vehicle. Senate Floor Amendment No. 1 (adopted 2026-05-21) had added the algorithmic rental-price-coordination ban described above, but House Committee Amendment No. 1 (filed 2026-05-28, adopted 2026-05-29) replaced that content entirely with unrelated Cook County / Calumet City eminent-domain (quick-take) provisions for economic development. Governor Pritzker signed the bill on 2026-08-07 as Public Act 104-0805; the enacted text contains no AI or algorithmic-pricing provisions.
Stated maximum penalty — Illinois Antitrust Act — civil penalties (enforcement by Illinois AG)
State — IN
US · IN
◆Binding
Binds Health insurers and health benefit providers in Indiana. AI cannot be sole basis for claim downcoding; insurers must disclose AI use in adverse determinations.
Stated maximum penalty — Indiana DOI enforcement
State — MD
US · MD
◆Binding
Binds Health insurance carriers, PBMs, and private review agents conducting utilization review in Maryland. AI tools in health-care utilization review must base decisions on individual clinical information; AI subject to quarterly MIA audit.
Quarterly review of AI utilization tools for effectiveness, accuracy, and fairness required.
Stated maximum penalty — Maryland Insurance Administration (MIA) enforcement
US · MD
◆Binding
Binds Any person who uses AI or deepfake representations with fraudulent intent to harm, harass, intimidate, or threaten individuals in Maryland. Criminalises creation and distribution of AI/deepfake representations used for identity fraud; expands existing identity-fraud statute.
Signed May 12, 2026 by Governor Wes Moore; effective October 1, 2026.
Stated maximum penalty — Up to 5 years imprisonment and/or $10,000 fine (single victim); up to 10 years and/or $15,000 (two or more victims)
US · MD
▲Proposed
Binds Food retail stores ≥15,000 sq ft selling tax-exempt food, and third-party delivery service providers arranging delivery from such stores, operating in Maryland. First US state law banning AI-driven personalised (surveillance) pricing in food retail and delivery; prohibits setting prices based on individual consumer personal data.
EXCLUDED FROM ACTIVE COVERAGE — CEO ruling AIL-136 (2026-08-03): all AI/algorithm language was deliberately struck from HB 895 before enactment. The enacted Ch. 154 prohibits personalized data-driven pricing for tax-exempt food (retailers ≥15,000 sq ft + food delivery); no AI definition, no near-real-time AI dynamic-pricing clause, no §13-322 algorithmic-pricing disclosure. Enacted operative line is personal data, not AI. Narrow food scope, regulatory-only, no private right of action. Fails coverage prong (a): AI is not load-bearing in enacted text. REVERSAL TRIGGER: re-escalate to CEO if AI/algorithm language is re-introduced in a future MD legislative session, or if personalized/surveillance pricing becomes an AI-governance flashpoint with AI-specific statutory language.
Stated maximum penalty — Up to $10,000 per violation; up to $25,000 per violation for repeat offenders (Maryland AG enforcement)
State — NE
US · NE
◆Binding
Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.
Signed April 14, 2026; operative July 1, 2027 (sections 12–18).
Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only
State — NJ
US · NJ
◆Binding
Binds Residential rental property owners and algorithmic revenue management software coordinators operating in New Jersey. Prohibits residential landlords and algorithmic revenue-management software coordinators from using algorithms that share competing landlords' nonpublic pricing data to recommend rents; bans parallel pricing coordination via software.
Signed 2026-07-20 by Gov. Mikie Sherrill; effective first day of the twelfth month following enactment (2027-07-01).
Stated maximum penalty — NJ Antitrust Act enforcement (P.L.1970, c.73); AG complaint portal required; penalty as provided under NJ Antitrust Act
State — NY
US · NY
◆Binding
Binds Operators of AI companion models serving New York users (excludes customer-service / internal-productivity-only systems). AI-identity disclosure at session start + every 3h and suicide/self-harm crisis referral (988) for AI companion operators; NY AG enforces.
Stated maximum penalty — Up to $15,000/day per violation (AG only; no private right of action)
US · NY
◆Binding
Binds Any person or entity using a deceased NY-domiciled performer's AI-generated digital replica in covered audiovisual, recorded, or live musical works without written consent from rights holders. Requires prior written consent from heirs, executors, or assigns before using a deceased New York-domiciled performer's or personality's AI-generated digital replica in audiovisual works, sound recordings, or live musical performances. Amends NY Civil Rights Law §50-f to introduce an AI-specific 'digital replica' definition (highly realistic, readily identifiable, computer-generated representation) and removes the prior 'likely to deceive' threshold. Covers 40 years post-mortem. Private right of action: statutory damages ≥$2,000 or actual damages plus profits and punitive damages.
Stated maximum penalty — ≥$2,000 statutory damages or actual damages + profits + punitive damages (private right of action)
US · NY
◆Binding
Binds Persons, firms, or corporations engaged in commerce who produce or create advertisements using synthetic performers with actual knowledge of their use in New York. Requires conspicuous disclosure when AI-generated synthetic performers (digitally created human assets not recognizable as any identifiable real person) appear in advertisements in any medium — newspapers, magazines, radio, TV, streaming, billboards, and transit. Advertisers must have actual knowledge of synthetic performer use. Exempts expressive works, audio-only ads, and language-translation uses.
Stated maximum penalty — $1,000 first violation; $5,000 subsequent violations (civil penalties)
US · NY
◆Binding
Binds Large frontier developers (>1e26 ops, >$500M revenue) operating in New York. Safety/security protocols + 72h critical-incident reporting to NYDFS; AG enforces civil penalties.
Stated maximum penalty — Up to $1M / $3M
State — NYC
US · NYC
◆Binding
Binds NYC employers & agencies using automated employment decision tools (AEDTs). Annual bias audit + published summary + candidate notice.
Stated maximum penalty — $500–$1,500 per violation/day
State — OR
US · OR
◆Binding
Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.
Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees
State — RI
US · RI
◆Binding
Binds Any individual or business providing therapy or psychotherapy services in Rhode Island. Prohibits providing therapy or psychotherapy services in Rhode Island unless conducted by a licensed professional; effectively bans AI-only therapy chatbots.
Signed by Governor McKee June 22, 2026; effective upon passage.
Stated maximum penalty — RI licensing enforcement
US · RI
◆Binding
Binds Healthcare providers and facilities using AI transcription in Rhode Island. Healthcare providers using AI transcription for clinical visits must document and notify patients.
Signed 22 June 2026 (R.I. Gen. Laws ch. 23-106); effective upon passage.
Stated maximum penalty — RI healthcare licensing enforcement
US · RI
◆Binding
Binds Chatbot and companion AI operators serving Rhode Island users. Chatbot/companion AI operators must include suicidal-ideation protocols and crisis referrals; annual reporting to AG from 2027-07-01.
Signed 2026-06-22 by Governor McKee; general effective date 2027-01-01. Annual reports to RI AG beginning July 1, 2027.
Stated maximum penalty — RI AG enforcement
State — TN
US · TN
◆Binding
Binds Any person creating or deploying AI systems available in Tennessee. Prohibits AI systems from claiming to function as qualified mental health professionals.
Stated maximum penalty — $5,000 per violation (Consumer Protection Act)
US · TN
◆Binding
Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.
Signed 2026-05-22 by Governor Lee as Public Chapter 1082. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.
Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators
State — TX
US · TX
◆Binding
Binds Persons developing/deploying AI in Texas or serving Texas residents; state agencies. Bans manipulative/discriminatory AI; AG-enforced.
Stated maximum penalty — Up to $200k/violation; $40k/day
State — UT
US · UT
◆Binding
Binds Health insurers operating in Utah for prior authorization processes. Insurers must disclose AI use in prior authorization reviews; adverse determinations must reflect independent medical judgment.
Stated maximum penalty — Disclosure to Utah Insurance Department required
State — WA
US · WA
◆Binding
Binds Private health carriers and public employee health plans using AI in prior authorization in Washington. AI cannot be sole basis for denying health care services; human clinical review required for AI-generated denials.
Annual reporting to OIC on AI-generated prior auth statistics required.
Stated maximum penalty — OIC enforcement (civil penalties; license actions)
US · WA
◆Binding
Binds Any person creating, distributing, or facilitating AI-generated/manipulated likenesses of Washington residents. Prohibits creating or using AI-generated forged digital likenesses without consent; amends WA Personality Rights Act.
Stated maximum penalty — $3,000/violation + noneconomic damages; private right of action
US · WA
◆Binding
Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.
Disclosures every 3 hours (all users) or 1 hour (minor users).
Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)
US · WA
◆Binding
Binds AI content creators and operators serving Washington users. Operators/creators must inform users when content is developed or modified through AI.
Signed 2026-03-24; codified as Chapter 167, Laws of 2026. Enforced exclusively by the WA Attorney General under the Consumer Protection Act (ch. 19.86 RCW).
Stated maximum penalty — Civil penalty up to $100,000 per covered provider (WA Consumer Protection Act, ch. 19.86 RCW; AG enforcement only)