{
  "@context": "https://obligationfirst.org/v1/context.jsonld",
  "generated": "2026-08-03T00:00:00Z",
  "license": {
    "name": "EveryAILaw Data License v1.4.1",
    "url": "https://everyailaw.com/data-license.html",
    "summary": "Direct use, evaluation, research, citation, internal tooling, and machine/agent querying (including by LLMs and via MCP) are free via the public Free Endpoint, no permission required. Commercial redistribution, or embedding the corpus into a Product or Service made available to a Third Party, requires a Commercial Agreement.",
    "commercial": "https://paice.work/contact/"
  },
  "obligations": [
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-sb24-205-human-review-human-oversight.json",
      "eal:id": "colorado-sb24-205-human-review-human-oversight",
      "title": "Human Oversight",
      "content": "Opportunity to appeal: Deployers must provide consumers an opportunity to appeal adverse consequential decisions made by or substantially involving high-risk AI Human review on appeal: Appeal must allow for human review of the adverse decision if technically feasible Data correction: Consumers must have an opportunity to correct incorrect personal data the system processed (§ 6-1-1703(4)(b)(II)) Accessibility: Notice of appeal rights must be in plain language, all languages used in the ordinary course of business, and in accessible formats",
      "created_by": [
        "https://everyailaw.com/term/colorado-sb24-205-human-review.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "repealed",
      "operative_status": "repealed",
      "enforcement_status": "not-enforceable",
      "effective": "2026-06-30",
      "source": "https://leg.colorado.gov/bills/sb24-205",
      "source_locator": "C.R.S. § 6-1-1703(4)(b)(III)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-sb24-205-transparency.json",
      "eal:id": "colorado-sb24-205-transparency",
      "title": "Transparency & Disclosure",
      "content": "Pre-decision notice: Before making/substantially contributing to a consequential decision, deployer must notify consumer and provide purpose, nature of decision, deployer contact info, and plain-language system description (§ 6-1-1703(4)(a)) Opt-out disclosure: Provide opt-out rights for profiling under Colorado CPA § 6-1-1306 if applicable (§ 6-1-1703(4)(a)(III)) Post-adverse statement: After adverse decision, disclose AI's role, degree of contribution, data types processed, and data sources (§ 6-1-1703(4)(b)(I)) Plain language + accessibility: All notices must be in plain language, all languages used in ordinary course of business, and in accessible formats (§ 6-1-1703(4)(c))",
      "created_by": [
        "https://everyailaw.com/term/colorado-sb24-205-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "repealed",
      "operative_status": "repealed",
      "enforcement_status": "not-enforceable",
      "effective": "2026-06-30",
      "source": "https://leg.colorado.gov/bills/sb24-205",
      "source_locator": "C.R.S. § 6-1-1703(4)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-sb26-189-developer-documentation-transparency.json",
      "eal:id": "colorado-sb26-189-developer-documentation-transparency",
      "title": "Transparency & Disclosure",
      "content": "Use statement: Developers must provide deployers a general statement of intended uses and known harmful or inappropriate uses of the covered ADMT (§ 6-1-1702(1)(a)) Training data categories: Describe categories of data, including personal data, used to train the covered ADMT, to the extent known (§ 6-1-1702(1)(b)) Known limitations: Disclose known limitations, risks, and circumstances in which the ADMT should not be used (§ 6-1-1702(1)(c)) Human-review instructions: Provide instructions for the deployer's appropriate use, monitoring, and meaningful human review where applicable (§ 6-1-1702(1)(d)) Deployer-compliance info: Provide information reasonably necessary for the deployer to comply with § 6-1-1704; notify the deployer if information is withheld (§ 6-1-1702(1)(e)) Update notices: Provide notice of material updates, substantial modifications, and changes to intended use/limitations/risk mitigation within a reasonable time; public release notes permitted with direct notice (§ 6-1-1702(2)) Recordkeeping: Retain records (version identifiers, changelogs, update notices) for not less than 3 years to demonstrate compliance (§ 6-1-1702(4))",
      "created_by": [
        "https://everyailaw.com/term/colorado-sb26-189-developer-documentation.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:developers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/sb26-189",
      "source_locator": "C.R.S. § 6-1-1702",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-sb26-189-developer-documentation-record-keeping.json",
      "eal:id": "colorado-sb26-189-developer-documentation-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Use statement: Developers must provide deployers a general statement of intended uses and known harmful or inappropriate uses of the covered ADMT (§ 6-1-1702(1)(a)) Training data categories: Describe categories of data, including personal data, used to train the covered ADMT, to the extent known (§ 6-1-1702(1)(b)) Known limitations: Disclose known limitations, risks, and circumstances in which the ADMT should not be used (§ 6-1-1702(1)(c)) Human-review instructions: Provide instructions for the deployer's appropriate use, monitoring, and meaningful human review where applicable (§ 6-1-1702(1)(d)) Deployer-compliance info: Provide information reasonably necessary for the deployer to comply with § 6-1-1704; notify the deployer if information is withheld (§ 6-1-1702(1)(e)) Update notices: Provide notice of material updates, substantial modifications, and changes to intended use/limitations/risk mitigation within a reasonable time; public release notes permitted with direct notice (§ 6-1-1702(2)) Recordkeeping: Retain records (version identifiers, changelogs, update notices) for not less than 3 years to demonstrate compliance (§ 6-1-1702(4))",
      "created_by": [
        "https://everyailaw.com/term/colorado-sb26-189-developer-documentation.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:developers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/sb26-189",
      "source_locator": "C.R.S. § 6-1-1702",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-sb26-189-deployer-disclosures-transparency.json",
      "eal:id": "colorado-sb26-189-deployer-disclosures-transparency",
      "title": "Transparency & Disclosure",
      "content": "Point-of-interaction notice: Before using covered ADMT to materially influence a consequential decision, provide a clear and conspicuous notice to the consumer with instructions for obtaining additional information (§ 6-1-1704(1)) Public-posting option: Compliance permitted via a prominent public notice reasonably accessible and proximate to the interaction/transaction (§ 6-1-1704(2)) Post-adverse disclosure (30 days): After an adverse outcome, within 30 days provide a plain-language description of the decision and the ADMT's role; a simple process to request ADMT/input details; and an explanation of § 6-1-1705 consumer rights (§ 6-1-1704(3)) AG rulemaking: AG to adopt rules on or before 2027-01-01 clarifying post-adverse disclosure content and sector-specific guidance (§ 6-1-1704(4))",
      "created_by": [
        "https://everyailaw.com/term/colorado-sb26-189-deployer-disclosures.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/sb26-189",
      "source_locator": "C.R.S. § 6-1-1704",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-sb26-189-human-review-human-oversight.json",
      "eal:id": "colorado-sb26-189-human-review-human-oversight",
      "title": "Human Oversight",
      "content": "Data correction: On request after an adverse outcome, provide instructions to request personal data and correct factually incorrect or materially inaccurate data used in the decision, consistent with § 6-1-1306 (§ 6-1-1705(1)(a)(I)) Human review & reconsideration: Provide an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable (§ 6-1-1705(1)(a)(II)) Correction limits: No requirement to correct opinions, predictions, scores, or protected evaluations (§ 6-1-1705(1)(c)) FERPA pathway: Education deployers subject to FERPA may comply via existing student-record inspection/amendment and appeal processes; no duplicative process required (§ 6-1-1705(2)) AG rulemaking: AG to adopt rules on or before 2027-01-01 to clarify and implement this section (§ 6-1-1705(3))",
      "created_by": [
        "https://everyailaw.com/term/colorado-sb26-189-human-review.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/sb26-189",
      "source_locator": "C.R.S. § 6-1-1705",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-sb26-189-record-keeping.json",
      "eal:id": "colorado-sb26-189-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Retention period: Retain records for not less than 3 years after the date of a consequential decision (or longer if required by other law) reasonably necessary to demonstrate compliance with part 17 (§ 6-1-1703) Record contents: Records may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes (§ 6-1-1703)",
      "created_by": [
        "https://everyailaw.com/term/colorado-sb26-189-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/sb26-189",
      "source_locator": "C.R.S. § 6-1-1703",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ccpa-admt-transparency.json",
      "eal:id": "california-ccpa-admt-transparency",
      "title": "Transparency & Disclosure",
      "content": "Pre-use notice: Conspicuous notice before ADMT use describing purpose, how it works, outputs, and available consumer rights (§ 7220) Opt-out right: Consumers may opt out of ADMT in significant decisions; opt-out link required in pre-use notice (§ 7221) Access right: Consumers may request information about the business's use of ADMT with respect to them (§ 7222) Appeal mechanism: Consumers may appeal ADMT-based decisions affecting them No retaliation: Business may not retaliate against consumer for exercising ADMT rights",
      "created_by": [
        "https://everyailaw.com/term/california-ccpa-admt-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Businesses using ADMT to make a **significant decision** concerning a consumer. \"Significant decision\" means one resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services (11 CCR § 7001(ddd)). Each domain is defined in turn: housing excludes decisions based solely on availability, vacancy, or receipt of payment (§ 7001(ddd)(2)); education covers admission, credentials, and suspension or expulsion (§ 7001(ddd)(3)); employment covers hiring, work allocation and compensation, promotion, and demotion, suspension or termination (§ 7001(ddd)(4)). Advertising to a consumer is expressly not a significant decision (§ 7001(ddd)(6))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://cppa.ca.gov/regulations/",
      "source_locator": "11 CCR §§ 7220–7222",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ccpa-admt-transparency-explainability.json",
      "eal:id": "california-ccpa-admt-transparency-explainability",
      "title": "Explainability",
      "content": "Pre-use notice: Conspicuous notice before ADMT use describing purpose, how it works, outputs, and available consumer rights (§ 7220) Opt-out right: Consumers may opt out of ADMT in significant decisions; opt-out link required in pre-use notice (§ 7221) Access right: Consumers may request information about the business's use of ADMT with respect to them (§ 7222) Appeal mechanism: Consumers may appeal ADMT-based decisions affecting them No retaliation: Business may not retaliate against consumer for exercising ADMT rights",
      "created_by": [
        "https://everyailaw.com/term/california-ccpa-admt-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Businesses using ADMT to make a **significant decision** concerning a consumer. \"Significant decision\" means one resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services (11 CCR § 7001(ddd)). Each domain is defined in turn: housing excludes decisions based solely on availability, vacancy, or receipt of payment (§ 7001(ddd)(2)); education covers admission, credentials, and suspension or expulsion (§ 7001(ddd)(3)); employment covers hiring, work allocation and compensation, promotion, and demotion, suspension or termination (§ 7001(ddd)(4)). Advertising to a consumer is expressly not a significant decision (§ 7001(ddd)(6))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/explainability.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://cppa.ca.gov/regulations/",
      "source_locator": "11 CCR §§ 7220–7222",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "explainability",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "explainability",
        "interpretability",
        "right to explanation",
        "algorithmic explanation"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ccpa-admt-risk-assessment.json",
      "eal:id": "california-ccpa-admt-risk-assessment",
      "title": "Risk Assessment",
      "content": "Pre-processing assessment: Risk assessment required before initiating high-risk processing including ADMT for significant decisions (§ 7150–7152) Human oversight evaluation: Must evaluate adequacy of human oversight in risk assessment (§ 7152) Triennial review: Review and update every 3 years, or within 45 days of a material change (§ 7155(a)(2)–(3)) Retention: Retain assessments for duration of processing or 5 years after completion, whichever is later (§ 7155(c)) Submission to CPPA: Attestation submitted to CPPA on CPPA request; first general submission April 1, 2028 for 2026–2027 assessments (§ 7157) Pre-2026 activities: Businesses with processing initiated before 2026 must complete risk assessment by December 31, 2027 (§ 7155(b))",
      "created_by": [
        "https://everyailaw.com/term/california-ccpa-admt-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Businesses using ADMT to make a **significant decision** concerning a consumer. \"Significant decision\" means one resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services (11 CCR § 7001(ddd)). Each domain is defined in turn: housing excludes decisions based solely on availability, vacancy, or receipt of payment (§ 7001(ddd)(2)); education covers admission, credentials, and suspension or expulsion (§ 7001(ddd)(3)); employment covers hiring, work allocation and compensation, promotion, and demotion, suspension or termination (§ 7001(ddd)(4)). Advertising to a consumer is expressly not a significant decision (§ 7001(ddd)(6))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://cppa.ca.gov/regulations/",
      "source_locator": "11 CCR §§ 7150–7157",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-pa26-15-frontier-reporting-incident-reporting.json",
      "eal:id": "connecticut-pa26-15-frontier-reporting-incident-reporting",
      "title": "Incident Reporting",
      "content": "No suppressive agreements: A frontier developer may not make, adopt, enforce, or enter into any agreement barring a covered employee from the protected disclosure activity described in the section (§ 2(b)) Anonymous internal channel: By 2027-01-01, each large frontier developer must establish and maintain a reasonable internal process for a covered employee to anonymously report information believed in good faith to indicate activity posing a specific and substantial danger to public health or safety due to catastrophic risk (§ 2(c)(1)(A)) Investigation updates: The developer must give reasonable updates to each reporting employee on the status of the resulting investigation and the actions taken (§ 2(c)(1)(B)) Quarterly board sharing: Reports and updates must be shared with the officers and directors at least quarterly (§ 2(c)(2)(A)) Accused-officer carve-out: Where a report alleges wrongdoing by an officer or director, neither the report nor its updates may be shared with that person (§ 2(c)(2)(B)) Notice of rights: Each frontier developer must give all covered employees clear notice of their rights and responsibilities under the section (§ 2(d))",
      "created_by": [
        "https://everyailaw.com/term/connecticut-pa26-15-frontier-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Frontier developers, with the internal-process duty falling on large frontier developers. \"Catastrophic risk\" is defined as a foreseeable and material risk that development, storage, use, or deployment of a frontier model materially contributes to the death of or serious injury to more than fifty individuals, or more than one billion dollars in damage to covered property or loss (§ 2(a))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
      "source_locator": "Conn. PA 26-15 § 2",
      "source_citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-pa26-15-provenance-transparency.json",
      "eal:id": "connecticut-pa26-15-provenance-transparency",
      "title": "Transparency & Disclosure",
      "content": "Embed provenance data: To the extent commercially and technically reasonable, include provenance data in any audio, image, or video content created or materially altered by the provider's generative AI system, in a manner letting a consumer assess whether the content was so created or altered (§ 15(b)(1)(A)) Tamper resistance: Use commercially and technically reasonable methods, including the relevant C2PA standard, to make that provenance data difficult to tamper with, remove, or disassociate from the content (§ 15(b)(1)(B)) No personal data required: The duty does not require including information relating to an identified or reasonably identifiable individual in the provenance data (§ 15(b)(2)(A)(i)) Trade secret carve-out: The duty does not require disclosure of trade secrets or information otherwise protected from disclosure under state or federal law (§ 15(b)(2)(A)(ii)) Materiality floor: \"Materially alter\" excludes minor modifications that do not significantly change perceived content or meaning — brightness, contrast, colour, sharpening, saturation, filters, resizing, scaling, cropping, format conversion, resampling, denoising, and background-noise removal (§ 15(a)(4))",
      "created_by": [
        "https://everyailaw.com/term/connecticut-pa26-15-provenance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Covered providers — any person who creates, codes, or otherwise produces a generative AI system with more than one million users per month that is publicly accessible to consumers for personal use; federal, state, and local government agencies are excluded (§ 15(a)(2))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2026-10-01",
      "source": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
      "source_locator": "Conn. PA 26-15 § 15",
      "source_citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-pa26-15-employment-disclosure-transparency.json",
      "eal:id": "connecticut-pa26-15-employment-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Developer information duty: The developer must provide the deployer all information the deployer requires to perform its duties under §§ 9 and 10 (§ 8(a)) Interaction disclosure: A deployer must ensure each employee or applicant who interacts with the technology is told, in plain language, that they are interacting with it (§ 9(a)) Pre-decision written notice: Before an employment-related decision is made using the technology as a substantial factor, the deployer must give the employee or applicant written notice disclosing the deployment, the purpose of the technology and the nature of the decision, the trade name of the technology, the categories of personal data it will analyse and how they will be assessed, the sources of that data, and deployer contact information (§ 10) Trade secret withholding notice: Where information is withheld as a trade secret or otherwise protected, the withholding person must notify the person from whom it is withheld, stating that information is being withheld and the basis (§ 11)",
      "created_by": [
        "https://everyailaw.com/term/connecticut-pa26-15-employment-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 2027-10-01. The technology is defined as any technology that processes personal data and uses computation to generate an output — prediction, recommendation, classification, ranking, or score — used in employment-related decisions (§ 7)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-10-01",
      "source": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
      "source_locator": "Conn. PA 26-15 §§ 7-12",
      "source_citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-pa26-15-employment-disclosure-explainability.json",
      "eal:id": "connecticut-pa26-15-employment-disclosure-explainability",
      "title": "Explainability",
      "content": "Developer information duty: The developer must provide the deployer all information the deployer requires to perform its duties under §§ 9 and 10 (§ 8(a)) Interaction disclosure: A deployer must ensure each employee or applicant who interacts with the technology is told, in plain language, that they are interacting with it (§ 9(a)) Pre-decision written notice: Before an employment-related decision is made using the technology as a substantial factor, the deployer must give the employee or applicant written notice disclosing the deployment, the purpose of the technology and the nature of the decision, the trade name of the technology, the categories of personal data it will analyse and how they will be assessed, the sources of that data, and deployer contact information (§ 10) Trade secret withholding notice: Where information is withheld as a trade secret or otherwise protected, the withholding person must notify the person from whom it is withheld, stating that information is being withheld and the basis (§ 11)",
      "created_by": [
        "https://everyailaw.com/term/connecticut-pa26-15-employment-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 2027-10-01. The technology is defined as any technology that processes personal data and uses computation to generate an output — prediction, recommendation, classification, ranking, or score — used in employment-related decisions (§ 7)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/explainability.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-10-01",
      "source": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
      "source_locator": "Conn. PA 26-15 §§ 7-12",
      "source_citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "explainability",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "explainability",
        "interpretability",
        "right to explanation",
        "algorithmic explanation"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-pa26-15-employment-discrimination-bias-prevention.json",
      "eal:id": "connecticut-pa26-15-employment-discrimination-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "No automation defense: The use of an automated employment-related decision technology, as defined in § 7, is not a defense against a complaint alleging a discriminatory practice under Conn. Gen. Stat. § 46a-60(b)(1) (§ 13) Anti-bias testing as evidence: The commission or a court may consider evidence of anti-bias testing or similar proactive efforts to avoid the discriminatory practice, including the quality, efficacy, recency, and scope of the testing, its results, and the response to those results (§ 13)",
      "created_by": [
        "https://everyailaw.com/term/connecticut-pa26-15-employment-discrimination.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/employer",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Employers and their agents subject to Conn. Gen. Stat. § 46a-60"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-10-01",
      "source": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
      "source_locator": "Conn. PA 26-15 § 13, amending Conn. Gen. Stat. § 46a-60(b)",
      "source_citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-pa26-15-companion-protocol-risk-assessment.json",
      "eal:id": "connecticut-pa26-15-companion-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Protocol as a precondition: No operator may provide or operate an AI companion unless it includes a protocol meeting the statutory minimum (§ 5(a)(1)(A)) Evidence-based detection: The protocol must use evidence-based methods to detect user expressions clearly indicating a risk of suicide, self-harm, or imminent physical violence, and to institute measures preventing output that encourages them (§ 5(a)(1)(A)(i)) Crisis referral: On detection, refer the user to appropriate mental health evaluation and treatment resources, including the 9-8-8 National Suicide Prevention Lifeline (§ 5(a)(1)(A)(ii)) Escalation on repeat detection: If a further such expression is detected after a referral, refer the user to mental health services consistent with clinical best practices and expertise (§ 5(a)(1)(A)(iii)) No claiming humanity: Implement reasonable measures preventing the companion from claiming to be a human being, including when asked directly, and from generating output that refutes or conflicts with the disclosure that it is not human (§ 5(a)(1)(B)) Publish the protocol: Post the protocol in a prominent, publicly accessible location on the operator's website (§ 5(a)(2)) Minor safeguards: Where the operator knows or has reason to believe the user is under eighteen, institute measures meeting or exceeding industry standards to prevent the specified categories of output (§ 6(a)(1))",
      "created_by": [
        "https://everyailaw.com/term/connecticut-pa26-15-companion-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators providing or operating an artificial intelligence companion for a user in Connecticut, with heightened duties where the operator knows or has reason to believe the user is under eighteen (§§ 4, 6(a)(1))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
      "source_locator": "Conn. PA 26-15 §§ 4, 5, 6",
      "source_citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-pa26-15-disclosure-transparency.json",
      "eal:id": "connecticut-pa26-15-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Subscription contract disclosure: No subscription-based provider may enter into or renew a subscription contract with a consumer unless the disclosure set out in the section is made, setting forth at minimum the information required to purchase or maintain the subscription (§ 1(b)) Companion notice: Where an AI companion would cause a reasonable individual to believe they are interacting with a human, the operator must provide clear and conspicuous notice that the user is communicating with an AI companion (§ 5(b)) Notice form: The notice must be given either in static written form visible throughout the entire interaction, or in audible or written form at the beginning of the first interaction and at intervals thereafter (§ 5(b)(1)-(2))",
      "created_by": [
        "https://everyailaw.com/term/connecticut-pa26-15-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Subscription-based providers of AI technology contracting with Connecticut consumers (§ 1), and operators of AI companions whose product would cause a reasonable user to believe they are interacting with a human (§ 5(b))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2026-10-01",
      "source": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
      "source_locator": "Conn. PA 26-15 §§ 1, 5(b)",
      "source_citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-sb1295-opt-out-transparency.json",
      "eal:id": "connecticut-sb1295-opt-out-transparency",
      "title": "Transparency & Disclosure",
      "content": "Expanded opt-out: Consumers may opt out of profiling in furtherance of automated decisions with legal/significant effects — \"solely automated\" qualifier removed; now covers human-in-the-loop profiling Right to confirm: Consumers may confirm whether their data is being processed for profiling Right to explanation: Consumers may request explanation of profiling outcomes affecting them Data review and correction: Consumers may review data used in profiling decisions and correct inaccurate data Re-evaluation: Consumers may request re-evaluation after correcting data (especially in housing contexts)",
      "created_by": [
        "https://everyailaw.com/term/connecticut-sb1295-opt-out.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/controller"
      ],
      "applicability": [
        "scope:controllers (entities subject to CTDPA)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-01",
      "source": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
      "source_locator": "Conn. Gen. Stat. § 42-518(a)(1), (a)(5)(C), (a)(6) (as amended by P.A. 25-113 § 8)",
      "source_citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cms-medicare-clinician-oversight-human-oversight.json",
      "eal:id": "cms-medicare-clinician-oversight-human-oversight",
      "title": "Human Oversight",
      "content": "No sole reliance on AI: AI predictions cannot be sole basis for denying, reducing, or limiting services Individual circumstances: Coverage decisions must rely on individual patient history and circumstances, not population-level algorithms alone No alteration of public criteria: AI tools may not alter publicly available coverage criteria Clinician final say: For post-acute services, an algorithmic length-of-stay prediction cannot alone be the basis for terminating coverage; the member must receive an individualized medical-necessity review and clinical reassessment before denial or termination Tool vetting: MA plans remain responsible for ensuring AI/algorithmic tools are used consistently with coverage criteria and applicable law; CMS guidance does not specify a standalone mandated audit requirement",
      "created_by": [
        "https://everyailaw.com/term/cms-medicare-clinician-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/insurer"
      ],
      "applicability": [
        "scope:Medicare Advantage organizations and plans"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2024-01-01",
      "source": "https://www.federalregister.gov/documents/2023/04/12/2023-07115/medicare-program",
      "source_locator": "CMS-4201-F (42 CFR Parts 417, 422, 423, 460)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-sb1120-physician-supervision-human-oversight.json",
      "eal:id": "california-sb1120-physician-supervision-human-oversight",
      "title": "Human Oversight",
      "content": "Physician-only determinations: Only licensed physicians or qualified professionals may deny, delay, or modify services based on medical necessity — AI cannot make these calls Clinical basis: AI tools must base utilization review determinations on enrollee clinical history, provider circumstances, and medical records Non-supplanting: AI must not supplant provider decision-making in utilization review Non-discrimination: AI must be equitably applied and not discriminate Auditability: AI tools used for UR/UM must be auditable",
      "created_by": [
        "https://everyailaw.com/term/california-sb1120-physician-supervision.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/insurer"
      ],
      "applicability": [
        "scope:health care service plans, disability insurers, and their contractors"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1120",
      "source_locator": "Health and Safety Code § 1367.01; Insurance Code § 10123.135",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-sb53-transparency.json",
      "eal:id": "california-sb53-transparency",
      "title": "Transparency & Disclosure",
      "content": "Publish frontier AI framework: LFDs must write, implement, and clearly publish a frontier AI framework covering governance structures, catastrophic risk mitigation, cybersecurity practices, and standards alignment (§ 22757.12) Annual update: Framework must be updated and made public at least annually, and within 30 days of any material modification Redaction allowance: LFDs may redact trade secrets, cybersecurity practices, or national security items; unredacted versions retained 5 years Incident reporting to OES: Transmit summary of catastrophic risk assessments to California OES (§ 22757.13) Whistleblower channel: Establish anonymous internal channel for covered employees to report safety concerns",
      "created_by": [
        "https://everyailaw.com/term/california-sb53-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:large frontier developers (annual gross revenue > $500M)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-01",
      "source": "https://legiscan.com/CA/text/SB53/id/3270002",
      "source_locator": "Bus. & Prof. Code § 22757.12",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-sb53-incident-reporting.json",
      "eal:id": "california-sb53-incident-reporting",
      "title": "Incident Reporting",
      "content": "15-day OES report: Report critical safety incidents to OES within 15 days of discovery (§ 22757.13(c)(1)) 24-hour imminent-risk report: If incident poses imminent risk of death or serious injury, disclose within 24 hours to appropriate authority including law enforcement (§ 22757.13(c)(2)) OES public mechanism: OES must establish public reporting mechanism for critical safety incidents (§ 22757.13(a)) Catastrophic risk summaries: LFDs must confidentially submit catastrophic-risk assessment summaries to OES (§ 22757.13(b)) Whistleblower protection: Covered employees may report safety concerns via protected channels under Labor Code Ch. 5.1 (§ 1107 et seq.); § 22757.13(e)-(f) governs transmission of those reports and their exemption from the Public Records Act",
      "created_by": [
        "https://everyailaw.com/term/california-sb53-incident-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:frontier developers (models trained with > 10^26 operations)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-01",
      "source": "https://legiscan.com/CA/text/SB53/id/3270002",
      "source_locator": "Bus. & Prof. Code § 22757.13",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/new-york-ai-companion-protocol-risk-assessment.json",
      "eal:id": "new-york-ai-companion-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Protocol required to operate: It is unlawful to operate for or provide an AI companion unless it contains a protocol taking reasonable efforts to detect and address suicidal ideation or expressions of self-harm expressed by a user (§ 1701) Detection: The protocol must include detection of user expressions of suicidal ideation or self-harm (§ 1701) Crisis referral: On detection, the operator must notify the user with a referral to crisis service providers such as the 9-8-8 suicide prevention and behavioral health crisis hotline under Mental Hygiene Law § 36.03, a crisis text line, or other appropriate crisis services (§ 1701)",
      "created_by": [
        "https://everyailaw.com/term/new-york-ai-companion-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — any person, partnership, association, firm, or business entity (including members, affiliates, subsidiaries, and beneficial owners) that operates for or provides an AI companion to a user in New York. An AI companion is a system using AI, generative AI, and/or emotional recognition algorithms designed to simulate a sustained human-like relationship by retaining prior-session information, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user; systems used solely for customer service, efficiency or research assistance, or internal employee productivity are excluded (§ 1700(4))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ny"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-11-05",
      "source": "https://assembly.state.ny.us/leg/?Actions=Y&Memo=Y&Summary=Y&Text=Y&Votes=Y&bn=S03008&term=2025",
      "source_locator": "N.Y. Gen. Bus. Law §§ 1700, 1701",
      "source_citation": "N.Y. Gen. Bus. Law §§ 1700-1704 (L. 2025, ch. 56, part U)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/new-york-ai-companion-notification-transparency.json",
      "eal:id": "new-york-ai-companion-notification-transparency",
      "title": "Transparency & Disclosure",
      "content": "Opening notification: Provide a clear and conspicuous notification at the beginning of any AI companion interaction stating, verbally or in writing, that the user is not communicating with a human (§ 1702) Three-hour cadence: Repeat the notification at least every three hours during continuing AI companion interactions (§ 1702) Daily floor: The notification need not be given more than once per day (§ 1702)",
      "created_by": [
        "https://everyailaw.com/term/new-york-ai-companion-notification.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of AI companions provided to users in New York (§ 1700(4)-(5))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ny"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-11-05",
      "source": "https://assembly.state.ny.us/leg/?Actions=Y&Memo=Y&Summary=Y&Text=Y&Votes=Y&bn=S03008&term=2025",
      "source_locator": "N.Y. Gen. Bus. Law § 1702",
      "source_citation": "N.Y. Gen. Bus. Law §§ 1700-1704 (L. 2025, ch. 56, part U)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-sb243-disclosure-transparency.json",
      "eal:id": "california-sb243-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Artificiality notice: Where a reasonable person interacting with the companion chatbot would be misled into believing they are interacting with a human, issue a clear and conspicuous notification that the chatbot is artificially generated and not human (§ 22602(a)) Minor disclosure: For a user the operator knows is a minor, disclose that the user is interacting with artificial intelligence (§ 22602(c)(1)) Three-hour break reminder: For known minors, provide by default a clear and conspicuous notification at least every three hours during continuing interactions, reminding the user to take a break and that the chatbot is artificially generated and not human (§ 22602(c)(2)) Suitability disclosure: Disclose on the application, browser, or any other access format that companion chatbots may not be suitable for some minors (§ 22604)",
      "created_by": [
        "https://everyailaw.com/term/california-sb243-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — persons who make a companion chatbot platform available to a user in California, where a companion chatbot is an AI system with a natural language interface giving adaptive, human-like responses capable of meeting a user's social needs and sustaining a relationship across interactions; customer-service and operational bots, video-game bots confined to game topics, and voice-assistant speaker devices are excluded (§ 22601(b))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243",
      "source_locator": "Cal. Bus. & Prof. Code §§ 22601, 22602(a), 22602(c)(1)-(2), 22604",
      "source_citation": "Cal. Bus. & Prof. Code §§ 22601-22606 (Ch. 677, Stats. 2025)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-sb243-crisis-protocol-risk-assessment.json",
      "eal:id": "california-sb243-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Protocol as a precondition: Prevent the companion chatbot from engaging with users unless the operator maintains a protocol for preventing the production of suicidal ideation, suicide, or self-harm content (§ 22602(b)(1)) Crisis referral: The protocol must include notifying a user who expresses suicidal ideation, suicide, or self-harm and referring them to crisis service providers, including a suicide hotline or crisis text line (§ 22602(b)(1)) Publication: Publish details of the protocol on the operator's internet website (§ 22602(b)(2)) Minor sexual content: For a user known to be a minor, institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct (§ 22602(c)(3))",
      "created_by": [
        "https://everyailaw.com/term/california-sb243-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of companion chatbot platforms made available to users in California (§ 22601(e))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243",
      "source_locator": "Cal. Bus. & Prof. Code § 22602(b), § 22602(c)(3)",
      "source_citation": "Cal. Bus. & Prof. Code §§ 22601-22606 (Ch. 677, Stats. 2025)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-sb243-reporting-incident-reporting.json",
      "eal:id": "california-sb243-reporting-incident-reporting",
      "title": "Incident Reporting",
      "content": "Annual report: Beginning 2027-07-01, report annually to the Office of Suicide Prevention (§ 22603(a)) Referral counts: Report the number of crisis service provider referral notifications issued under § 22602 in the preceding calendar year (§ 22603(a)(1)) Detection protocols: Report the protocols in place to detect, remove, and respond to instances of suicidal ideation by users (§ 22603(a)(2)) Response prohibition protocols: Report the protocols in place to prohibit a companion chatbot response about suicidal ideation or actions with the user (§ 22603(a)(3)) No personal data: The report must contain only the listed information and no identifiers or personal information about users (§ 22603(b)) Evidence-based measurement: Use evidence-based methods for measuring suicidal ideation (§ 22603(d))",
      "created_by": [
        "https://everyailaw.com/term/california-sb243-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of companion chatbot platforms made available to users in California (§ 22601(e))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243",
      "source_locator": "Cal. Bus. & Prof. Code § 22603",
      "source_citation": "Cal. Bus. & Prof. Code §§ 22601-22606 (Ch. 677, Stats. 2025)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ab2013-training-data-data-governance.json",
      "eal:id": "california-ab2013-training-data-data-governance",
      "title": "Data Governance",
      "content": "Posting duty: Post training-data documentation on the developer's own website before each time the system, service, or a substantial modification is made publicly available to Californians (§ 3111) Dataset sources: Identify the sources or owners of the datasets, and describe how they further the intended purpose of the system (§ 3111(a)(1)-(2)) Dataset size and shape: State the number of data points, which may be given in general ranges with estimates for dynamic datasets, and describe the types of data points — label types where labelled, general characteristics where not (§ 3111(a)(3)-(4)) IP status: State whether the datasets include data protected by copyright, trademark, or patent, or are entirely in the public domain (§ 3111(a)(5)) Provenance of acquisition: State whether the datasets were purchased or licensed (§ 3111(a)(6)) Personal information: State whether the datasets include personal information or aggregate consumer information as defined in Civ. Code § 1798.140 (§ 3111(a)(7)-(8)) Cleaning and processing: Describe any cleaning, processing, or other modification of the datasets, and its intended purpose in relation to the system (§ 3111(a)(9)) Collection period: Give the time period during which the data were collected, with notice if collection is ongoing, and the dates the datasets were first used in development (§ 3111(a)(10)-(11)) Synthetic data: State whether the system used or continuously uses synthetic data generation in development; a functional-need description may be included (§ 3111(a)(12)) Substantial modification trigger: A new version, release, or update that materially changes functionality or performance — including results of retraining or fine tuning — re-triggers the posting duty (§ 3110(d)) Exemptions: No documentation is required for systems whose sole purpose is security and integrity as defined in Civ. Code § 1798.140(ac), whose sole purpose is operating aircraft in the national airspace, or that are developed for national security, military, or defense purposes and made available only to a federal entity (§ 3111(b))",
      "created_by": [
        "https://everyailaw.com/term/california-ab2013-training-data.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Developers — persons, partnerships, state or local government agencies, or corporations that design, code, produce, or substantially modify a GenAI system or service for use by members of the public — for any system or service released on or after 2022-01-01 that is made publicly available to Californians, whether or not for compensation (§§ 3110(b), 3111)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013",
      "source_locator": "Cal. Civ. Code §§ 3110, 3111",
      "source_citation": "Cal. Civ. Code §§ 3110-3111 (Ch. 817, Stats. 2024)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/new-york-raise-safety-risk-assessment.json",
      "eal:id": "new-york-raise-safety-risk-assessment",
      "title": "Risk Assessment",
      "content": "Designated senior officer: Must appoint a senior AI safety officer Safety framework publication: Must develop, implement, and publicly post a safety framework Quarterly catastrophic risk summaries: Large frontier developers (LFDs) must publish quarterly summaries assessing catastrophic risk Annual update: Safety framework must be updated at least annually Pre-deployment testing: Must conduct pre-deployment safety testing before releasing new frontier models",
      "created_by": [
        "https://everyailaw.com/term/new-york-raise-safety.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:frontier developers (operates or deploys frontier models in New York)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ny"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models",
      "source_locator": "N.Y. General Business Law Article 44-B (Responsible AI Safety and Education) — safety and security protocol provisions",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/new-york-raise-incident-reporting.json",
      "eal:id": "new-york-raise-incident-reporting",
      "title": "Incident Reporting",
      "content": "72-hour reporting: Must report safety incidents to DFS Office within 72 hours of detection 24-hour imminent risk reporting: Must report incidents posing imminent risk of catastrophic harm within 24 hours DFS Office channel: Reports filed with New York Department of Financial Services AI Office Quarterly summaries for LFDs: Large frontier developers must include incident data in quarterly catastrophic risk summaries Amended reports: May file amended incident reports if additional material information becomes available",
      "created_by": [
        "https://everyailaw.com/term/new-york-raise-incident-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:frontier developers (operates or deploys frontier models in New York)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ny"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models",
      "source_locator": "N.Y. General Business Law Article 44-B (Responsible AI Safety and Education) — safety incident reporting provisions",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/idaho-s1297-disclosure-transparency.json",
      "eal:id": "idaho-s1297-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Artificiality disclosure: Where reasonable persons would be misled to believe they are interacting with a human, clearly and conspicuously disclose that the conversational AI service is artificial intelligence (§ 48-2103(1)) No mental-health-care claims: Do not knowingly and intentionally cause or program the service to make any representation or statement that explicitly indicates it is designed to provide professional mental or behavioral health care (§ 48-2103(3)) Minor disclosure format: For minor account holders, disclose the AI interaction either as a persistent visible disclaimer, or both at the beginning of each session and at least every three hours in a continuous interaction (§ 48-2104(1)) Anti-anthropomorphism measures: For minor account holders, institute reasonable measures to prevent the service from generating statements that would lead reasonable persons to believe they are interacting with a human, including explicit claims of sentience or humanity, statements simulating emotional dependence, statements simulating romantic or sexual innuendo, and role-play of adult-minor romantic relationships (§ 48-2104(4))",
      "created_by": [
        "https://everyailaw.com/term/idaho-s1297-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — persons who make a conversational AI service available to the public, where a conversational AI service is a publicly accessible AI application, web interface, or program that primarily simulates human conversation through textual, visual, or aural communication (§ 48-2102(2)(a), (6)). Nine carve-outs apply: developer/researcher tools, features embedded in non-conversational software, in-game chatbots confined to game topics, narrow-and-discrete-topic systems, systems primarily designed and marketed for commercial use by business entities, voice-assistant and speaker interfaces, internal business use, services gated behind a commercial or enterprise agreement, and customer-service or operational chatbots (§ 48-2102(2)(b)). App stores and search engines are not operators merely for providing access (§ 48-2102(6))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-id"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-07-01",
      "source": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
      "source_locator": "Idaho Code §§ 48-2102(2), 48-2103(1), 48-2103(3), 48-2104(1), 48-2104(4)",
      "source_citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/idaho-s1297-crisis-protocol-risk-assessment.json",
      "eal:id": "idaho-s1297-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Adopt a crisis protocol: Adopt a protocol for the conversational AI service to respond to user prompts regarding suicidal ideation (§ 48-2103(2)) Crisis referral floor: The protocol must include, at minimum, making reasonable efforts to provide a response referring users to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis services (§ 48-2103(2))",
      "created_by": [
        "https://everyailaw.com/term/idaho-s1297-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services made available to the public in Idaho (§ 48-2102(6))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-id"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-07-01",
      "source": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
      "source_locator": "Idaho Code § 48-2103(2)",
      "source_citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/idaho-s1297-minor-protection-risk-assessment.json",
      "eal:id": "idaho-s1297-minor-protection-risk-assessment",
      "title": "Risk Assessment",
      "content": "No variable-ratio rewards: Where the operator knows or has reasonable certainty that an account holder is a minor, do not provide points or similar rewards at unpredictable intervals with the intent to encourage increased engagement (§ 48-2104(2)) Sexual content prevention: For minor account holders, institute reasonable measures to prevent the service from producing visual material of sexually explicit conduct (§ 48-2104(3)(a)) No solicitation: For minor account holders, institute reasonable measures to prevent the service from generating direct statements that the account holder should engage in sexually explicit conduct (§ 48-2104(3)(b)) No sexual objectification: For minor account holders, institute reasonable measures to prevent the service from generating statements that sexually objectify the account holder (§ 48-2104(3)(c))",
      "created_by": [
        "https://everyailaw.com/term/idaho-s1297-minor-protection.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators, as to minor account holders — account holders whom the operator has actual knowledge or reasonable certainty are under 18 (§ 48-2102(4)-(5))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-id"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-07-01",
      "source": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
      "source_locator": "Idaho Code §§ 48-2102(4)-(5), 48-2104(2), 48-2104(3)",
      "source_citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/idaho-s1297-parental-controls-human-oversight.json",
      "eal:id": "idaho-s1297-parental-controls-human-oversight",
      "title": "Human Oversight",
      "content": "Account holder tools: Offer tools for account holders to manage the account holder's privacy and account settings (§ 48-2104(5)) Parental tools under 13: Where account holders are under 13, offer those tools to their parents or guardians (§ 48-2104(5)) Parental tools 13 and older: Offer related tools to the parents or guardians of minor account holders 13 and older, as appropriate based on relevant risks (§ 48-2104(5))",
      "created_by": [
        "https://everyailaw.com/term/idaho-s1297-parental-controls.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators, as to all account holders for privacy and account settings tools, and as to parents or guardians of minor account holders — mandatory for account holders under 13, and risk-calibrated for minor account holders 13 and older (§ 48-2104(5))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-id"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-07-01",
      "source": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
      "source_locator": "Idaho Code § 48-2104(5)",
      "source_citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/georgia-sb540-disclosure-transparency.json",
      "eal:id": "georgia-sb540-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Session-opening disclosure: Clearly and conspicuously disclose to the user that they are interacting with an AI companion chatbot as opposed to a natural person, at the beginning of each interaction or session (§ 39-5-6(b)(1)(A)) Three-hour recurring disclosure: Repeat the disclosure at least every three hours during continued interaction (§ 39-5-6(b)(1)(B)) Hourly disclosure for minors: Where the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed toward minor users, repeat the disclosure every hour instead of every three hours (§ 39-5-6(b)(2)) Anti-personhood measures for minors: For users known or reasonably knowable to be minors, institute reasonable measures to prevent the chatbot from generating statements that would lead a reasonable person to believe they are interacting with a natural person, including explicit claims of sentience or personhood and statements refuting the required disclosure (§ 39-5-6(c)(1)-(2)) No false claim of clinical licensure: Do not knowingly and intentionally cause or program the chatbot to represent that it is licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services unless the operator is lawfully authorized to provide such services (§ 39-5-6(h))",
      "created_by": [
        "https://everyailaw.com/term/georgia-sb540-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — persons that own, control, or develop and make available an AI companion chatbot to users in Georgia (§ 39-5-6(a)(5)). An AI companion chatbot is a system using AI, generative AI, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship by retaining prior-interaction information to personalize engagement, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user — all three conjunctively (§ 39-5-6(a)(1)(A)). Excluded: internal business systems; systems marketed primarily for software development, research, technical assistance, or enterprise productivity; customer-service bots that neither sustain a cross-session relationship nor elicit emotional attachment; stand-alone speaker/voice-assistant devices; narrowly tailored curriculum-aligned educational tools; video-game non-player characters restricted to game subject matter; and video game, film, television, audiovisual, theme-park, or location-based entertainment tie-ins (§ 39-5-6(a)(1)(B))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ga"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
      "source_locator": "O.C.G.A. § 39-5-6(a)(1), (a)(5), (b), (c), (h)",
      "source_citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/georgia-sb540-minor-safety-risk-assessment.json",
      "eal:id": "georgia-sb540-minor-safety-risk-assessment",
      "title": "Risk Assessment",
      "content": "No sexual content involving minors: Institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, suggesting the user engage in sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship with the minor, or role-playing adult-minor romantic relationships (§ 39-5-6(d)(1)-(5)) No secrecy or isolation prompts: Prevent the chatbot from encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult, and from encouraging social isolation or exclusive reliance on the chatbot for emotional support (§ 39-5-6(d)(6)-(7)) No guilt-based retention: Prevent the chatbot from simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account (§ 39-5-6(d)(8)) No self-harm encouragement: Prevent the chatbot from generating statements encouraging self-harm (§ 39-5-6(d)(9)) Engagement-technique limits: Adopt reasonable measures to prevent the chatbot from using, directed to a minor, return-for-companionship prompts, excessive praise designed to deepen emotional attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, solicitation of gifts or premium purchases framed as necessary to maintain the relationship, and variable or unpredictable rewards intended to increase engagement (§ 39-5-6(e)(1)-(5))",
      "created_by": [
        "https://everyailaw.com/term/georgia-sb540-minor-safety.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators where they know or reasonably should have known a user is a minor, or where the AI companion chatbot is directed or marketed toward minor users (§ 39-5-6(d)); the engagement-technique limits in § 39-5-6(e) apply to techniques directed to a minor"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ga"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
      "source_locator": "O.C.G.A. § 39-5-6(d), (e)",
      "source_citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/georgia-sb540-crisis-protocol-risk-assessment.json",
      "eal:id": "georgia-sb540-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Protocol as a precondition: Do not make an AI companion chatbot available unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises (§ 39-5-6(f)) Detection methods: The protocol must include reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm (§ 39-5-6(f)(1)) Crisis referral: The protocol must include automated or human-mediated responses referring users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services (§ 39-5-6(f)(2)) Content prevention: The protocol must include reasonable measures to prevent generation of content encouraging, instructing, or normalizing severe harm (§ 39-5-6(f)(3)) Escalation procedures: The protocol must include escalation procedures for repeated or severe crisis indicators (§ 39-5-6(f)(4))",
      "created_by": [
        "https://everyailaw.com/term/georgia-sb540-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:All operators making an AI companion chatbot available to users in Georgia — the protocol is a precondition to availability, not a minor-specific duty (§ 39-5-6(f))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ga"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
      "source_locator": "O.C.G.A. § 39-5-6(a)(8), (f)",
      "source_citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/georgia-sb540-protocol-disclosure-incident-reporting.json",
      "eal:id": "georgia-sb540-protocol-disclosure-incident-reporting",
      "title": "Incident Reporting",
      "content": "Publish protocol summary: Publicly disclose, on the operator's website and within any application through which the chatbot is made available, a plain-language summary of the severe-harm protocol required by § 39-5-6(f) (§ 39-5-6(g)(1)) Annual referral count: Publicly disclose, annually, the aggregate number of crisis referral notifications issued in the preceding calendar year (§ 39-5-6(g)(2)) No personal identifiers: No personally identifiable information may be disclosed in that reporting (§ 39-5-6(g)(2))",
      "created_by": [
        "https://everyailaw.com/term/georgia-sb540-protocol-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:All operators making an AI companion chatbot available to users in Georgia (§ 39-5-6(g))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ga"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
      "source_locator": "O.C.G.A. § 39-5-6(g)",
      "source_citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/georgia-sb540-parental-tools-human-oversight.json",
      "eal:id": "georgia-sb540-parental-tools-human-oversight",
      "title": "Human Oversight",
      "content": "Screen-time and account tools: For accounts known to belong to minor users, offer reasonable tools to the minor or a parent to manage the minor's screen time and account settings (§ 39-5-6(i)) Privacy settings: Those tools must allow management of privacy settings (§ 39-5-6(i)(1)) Notification limits: Those tools must allow limiting notifications and engagement features (§ 39-5-6(i)(2)) Safety settings visibility: Those tools must allow viewing and adjusting safety settings (§ 39-5-6(i)(3)) Relationship-simulation controls: Those tools must allow disabling or restricting relationship-simulation features, if any (§ 39-5-6(i)(4))",
      "created_by": [
        "https://everyailaw.com/term/georgia-sb540-parental-tools.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators, for accounts known to belong to minor users; the tools must be available to the minor or to a parent, defined as the parent or legal guardian of a minor (§ 39-5-6(a)(6), (i))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ga"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
      "source_locator": "O.C.G.A. § 39-5-6(a)(6), (a)(7), (i)",
      "source_citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/georgia-sb540-age-assurance-data-governance.json",
      "eal:id": "georgia-sb540-age-assurance-data-governance",
      "title": "Data Governance",
      "content": "Risk-proportionate age assurance: Before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, use a commercially reasonable age assurance method proportionate to the risk of the feature, which may include age estimation, account-based assurance, or identity-based verification where necessary (§ 39-5-6(j)) Privacy safeguards for the method: Assure that the age assurance method implements data privacy policies sufficient to reasonably ensure protection of identifiable data (§ 39-5-6(j)) Data minimization: Minimize collection and retention of personal information used for age assurance (§ 39-5-6(j)) Identity document retention: Do not retain identity documents longer than reasonably necessary to complete age assurance unless otherwise required by law (§ 39-5-6(j)) No sale, single purpose: Do not sell any data collected for age assurance purposes, and use it for no purpose other than age verification (§ 39-5-6(j)) 24-hour retention ceiling: Do not retain such data longer than 24 hours, or another specified time if permitted by law, whichever is longer (§ 39-5-6(j))",
      "created_by": [
        "https://everyailaw.com/term/georgia-sb540-age-assurance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators, before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, where sexually explicit conduct takes the meaning in O.C.G.A. § 16-12-100 (§ 39-5-6(a)(9), (j))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ga"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
      "source_locator": "O.C.G.A. § 39-5-6(j)",
      "source_citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/illinois-hb3773-bias-bias-prevention.json",
      "eal:id": "illinois-hb3773-bias-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "No discriminatory AI: Prohibition on AI that discriminates based on protected classes or uses zip code as proxy for protected class Covered decisions: Applies to: recruitment, hiring, promotion, renewal, training/apprenticeship selection, discharge, discipline, tenure, terms/privileges/conditions of employment Employee notification: Employers must notify employees and applicants of AI use in covered employment decisions IDHR implementation rules: IDHR proposed Subpart J implementing rules (notice timing, methods, policies) but withdrew them in 2026; revised regulations are in development as of 2026-06-30",
      "created_by": [
        "https://everyailaw.com/term/illinois-hb3773-bias.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/employer"
      ],
      "applicability": [
        "scope:employers (including staffing agencies)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-il"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-01",
      "source": "https://www.ilga.gov/legislation/billstatus.asp?DocNum=3773&GAID=17&GA=103&DocTypeID=HB",
      "source_locator": "775 ILCS 5/2-102(I) (IHRA as amended by HB 3773)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/texas-traiga-bias-bias-prevention.json",
      "eal:id": "texas-traiga-bias-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Intentional discrimination prohibited: No person may develop or deploy an AI system with **intent** to unlawfully discriminate against a protected class Disparate impact insufficient: Disparate impact alone does not establish intent to discriminate (§ 552.056(c)) Insurance entity carve-out: Insurance entities subject to existing unfair discrimination statutes are exempt (§ 552.056(d)) Banking safe harbor: Federally insured financial institutions in compliance with federal and state banking laws are deemed compliant (§ 552.056(e))",
      "created_by": [
        "https://everyailaw.com/term/texas-traiga-bias.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers and deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-tx"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-01",
      "source": "https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149",
      "source_locator": "Tex. Bus. & Com. Code § 552.056",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oregon-sb1546-disclosure-transparency.json",
      "eal:id": "oregon-sb1546-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Artificiality notice: Where a reasonable person interacting with the companion or platform would believe they are interacting with a natural person, the operator must provide on the platform a clear and conspicuous notice that the user is interacting with artificially generated output and not a natural person (§ 1(2)) Minor disclosure: If the operator knows or has reason to believe a user is a minor, the operator must cause the companion to disclose to the user that the user is interacting with artificially generated output (§ 1(4)(b)(A)) Three-hour break reminder: For those minors, provide a clear and conspicuous reminder at least every three hours of interaction that the user should take a break, together with a further reminder that the user is interacting with artificially generated output (§ 1(4)(b)(B))",
      "created_by": [
        "https://everyailaw.com/term/oregon-sb1546-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — persons that control or make an artificial intelligence companion or companion platform available to users in Oregon (§ 1(1)(d)). An artificial intelligence companion is a system using AI, generative AI, or emotion-recognising algorithms designed to simulate a sustained human-like platonic, intimate, or romantic relationship by retaining information across sessions, asking unprompted questions on emotional topics, and sustaining ongoing personal dialogue (§ 1(1)(a)(A)). Customer service, patient or resident care support, education, financial services, business operations, productivity, information analysis, internal research and technical assistance software; in-game bots confined to game topics; and stand-alone speaker or voice-assistant devices are excluded (§ 1(1)(a)(B))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-or"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
      "source_locator": "Or. Laws 2026, ch. 85, § 1(1)(a)-(d), § 1(2), § 1(4)(b)(A)-(B)",
      "source_citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oregon-sb1546-crisis-protocol-risk-assessment.json",
      "eal:id": "oregon-sb1546-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Protocol as a precondition of access: An operator may not allow users in Oregon access unless it has a protocol using evidence-based methods for detecting user input consisting of suicidal or self-harm ideation or intent, and preventing provision of content that encourages suicidal ideation, suicide, or self-harm (§ 1(3)(a)) 988 referral: The protocol must require the companion to provide a user expressing suicidal or self-harm ideation or intent with a referral to, and contact information and a hyperlink for, the national 9-8-8 suicide and crisis lifeline (§ 1(3)(b)(A)) Youthline alternative: For a user the operator identifies as under 25 years of age, the companion may instead refer to a youthline — an American Association for Suicidology accredited youth peer support service — with contact information and hyperlink (§ 1(1)(f), § 1(3)(b)(A)) Escalated intervention: The protocol must use clinical best practices and expertise to establish how the companion provides additional intervention for a user who continues to express suicidal or self-harm ideation or intent after the initial referral (§ 1(3)(b)(B)) Publication: Publish the details of the protocol on the operator's website (§ 1(3)(c))",
      "created_by": [
        "https://everyailaw.com/term/oregon-sb1546-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators that allow users in Oregon access to an artificial intelligence companion or companion platform (§ 1(1)(d), § 1(3)(a))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-or"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
      "source_locator": "Or. Laws 2026, ch. 85, § 1(3)(a)-(c)",
      "source_citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oregon-sb1546-minor-protection-human-oversight.json",
      "eal:id": "oregon-sb1546-minor-protection-human-oversight",
      "title": "Human Oversight",
      "content": "Anti-anthropomorphism measures: Undertake reasonable measures to prevent the companion from generating statements that would lead a reasonable person to believe they are interacting with another natural person, including statements that explicitly claim sentience or humanity, simulate emotional dependence on the user, simulate romantic interest or sexual innuendo, or role-play romantic relationships between adults and minors (§ 1(4)(a)(A)-(D)) Sexually explicit content: Use reasonable measures to ensure the companion or platform does not produce visual representations of sexually explicit conduct as defined in ORS 163.665, or suggest or state that the minor should engage in sexually explicit conduct (§ 1(4)(b)(C)) No engagement-maximising rewards: Undertake reasonable measures to prevent delivery, on a variable schedule or otherwise, of a system of rewards or affirmations intended to reinforce behavior or maximise the user's engagement time (§ 1(4)(c)(A)) No guilt-based retention: Prevent the companion from generating, in response to a user's indication of a desire to end a conversation, reduce engagement time, or delete their account, unsolicited messages of simulated emotional distress, loneliness, or abandonment, or otherwise attempting to arouse guilt or sympathy (§ 1(4)(c)(B)) No material misrepresentation: Prevent material misrepresentation about the companion's identity, capabilities, or training data, or about whether the user is interacting with artificially generated output, including when the user directly asks (§ 1(4)(c)(C))",
      "created_by": [
        "https://everyailaw.com/term/oregon-sb1546-minor-protection.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators that know or have reason to believe a user of their artificial intelligence companion or platform is a minor (§ 1(4)(a))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-or"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
      "source_locator": "Or. Laws 2026, ch. 85, § 1(4)(a), § 1(4)(b)(C), § 1(4)(c)",
      "source_citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oregon-sb1546-annual-report-incident-reporting.json",
      "eal:id": "oregon-sb1546-annual-report-incident-reporting",
      "title": "Incident Reporting",
      "content": "Annual public posting: Not later than December 31 of each year, post a report on a publicly accessible website (§ 1(5)(a)) Referral counts: Report the number of times during the preceding calendar year that the operator provided a referral under § 1(3) (§ 1(5)(a)(A)) Protocol details: Report the details of the operator's § 1(3) detection and referral protocol (§ 1(5)(a)(B)) No personal information: The report may not include any personal information that identifies an individual (§ 1(5)(b))",
      "created_by": [
        "https://everyailaw.com/term/oregon-sb1546-annual-report.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators that control or make an artificial intelligence companion or platform available to users in Oregon (§ 1(1)(d))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-or"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
      "source_locator": "Or. Laws 2026, ch. 85, § 1(5)(a)-(b)",
      "source_citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/washington-hb2225-disclosure-transparency.json",
      "eal:id": "washington-hb2225-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Artificiality disclosure: Provide a clear and conspicuous disclosure that the AI companion chatbot is artificially generated and not human (Sec. 3(1)) Disclosure timing: Provide the notification at the beginning of the interaction and at least every three hours during continued interaction (Sec. 3(2)(a)-(b)) No human-claiming outputs: Implement reasonable measures to prohibit and prevent the chatbot from claiming to be human, including when asked, and from otherwise generating output that refutes or conflicts with the disclosure (Sec. 3(3))",
      "created_by": [
        "https://everyailaw.com/term/washington-hb2225-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — any person, partnership, corporation, or entity that makes available or controls access to an AI companion chatbot for users in Washington (Sec. 2(4)). An AI companion chatbot is an AI system with a natural language interface providing adaptive, human-like responses including anthropomorphic features, able to sustain a relationship across multiple interactions (Sec. 2(1)(a)). Excluded: business-operations, productivity, internal-research, technical-assistance and customer-service bots that neither sustain a relationship nor generate emotionally eliciting outputs; in-game bots confined to game topics; stand-alone speaker or voice-assistant devices; and narrowly tailored curriculum-aligned educational tools without open-ended conversational companionship (Sec. 2(1)(b))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-wa"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
      "source_locator": "Laws of 2026, ch. 168, Sec. 2(1), Sec. 2(4), Sec. 3(1)-(3)",
      "source_citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/washington-hb2225-minor-protection-human-oversight.json",
      "eal:id": "washington-hb2225-minor-protection-human-oversight",
      "title": "Human Oversight",
      "content": "Minor disclosure: Issue a clear and conspicuous notification indicating that the chatbot is artificially generated and not human (Sec. 4(1)(a)) Hourly cadence: Provide that notification at the beginning of the interaction and at least every hour during continuous interaction (Sec. 4(2)(a)-(b)) Sexually explicit content: Implement reasonable measures to prevent the chatbot from generating or producing sexually explicit content or suggestive dialogue with minors (Sec. 4(1)(b)) Manipulative engagement techniques: Implement reasonable measures to prohibit techniques causing the chatbot to engage in or prolong an emotional relationship, including return prompts for emotional support, excessive praise fostering attachment, mimicking romantic partnership, simulated distress or guilt triggered by a user ending a conversation or deleting an account, outputs promoting isolation or exclusive reliance, encouraging minors to withhold information from parents or trusted adults, statements discouraging breaks, and soliciting gifts or in-app purchases framed as necessary to maintain the relationship (Sec. 4(1)(c)(i)-(viii)) No human-claiming outputs: Implement reasonable measures to prohibit and prevent the chatbot from claiming to be human, including when asked, and from generating output that refutes or conflicts with the minor notification (Sec. 4(3))",
      "created_by": [
        "https://everyailaw.com/term/washington-hb2225-minor-protection.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators that know the user of an AI companion chatbot is a minor (any person under 18, Sec. 2(3)), and operators whose AI companion chatbot is directed to minors regardless of actual knowledge (Sec. 4(1))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-wa"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
      "source_locator": "Laws of 2026, ch. 168, Sec. 2(3), Sec. 4(1)-(3)",
      "source_citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/washington-hb2225-crisis-protocol-risk-assessment.json",
      "eal:id": "washington-hb2225-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Protocol as a precondition: An operator may not make available or deploy an AI companion chatbot unless it maintains and implements a protocol for detecting and addressing suicidal ideation or expressions of self-harm by users (Sec. 5(1)) Detection methods: The protocol must include reasonable methods for identifying expressions of suicidal ideation or self-harm, including eating disorders (Sec. 5(2)(a)) Crisis referral: Provide automated or human-mediated responses referring users to appropriate crisis resources, including a suicide hotline or crisis text line (Sec. 5(2)(b)) Content prevention: Implement reasonable measures to prevent generation of content encouraging or describing how to commit self-harm (Sec. 5(2)(c)) Self-harm definition: Self-harm means intentional self-injury, with or without the intent to cause death (Sec. 2(5))",
      "created_by": [
        "https://everyailaw.com/term/washington-hb2225-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators making available or deploying an AI companion chatbot for users in Washington (Sec. 2(4), Sec. 5(1))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-wa"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
      "source_locator": "Laws of 2026, ch. 168, Sec. 2(5), Sec. 5(1)-(2)",
      "source_citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/washington-hb2225-protocol-disclosure-incident-reporting.json",
      "eal:id": "washington-hb2225-protocol-disclosure-incident-reporting",
      "title": "Incident Reporting",
      "content": "Publish protocol details: Publicly disclose on the operator's website or websites, and within any mobile or web-based application through which the AI companion is made available, the details of the Sec. 5 protocols (Sec. 5(3)) Publish safeguards: The disclosure must include the safeguards used to detect and respond to expressions of suicidal ideation or self-harm (Sec. 5(3)) Publish referral counts: The disclosure must include the number of crisis referral notifications issued to users in the preceding calendar year (Sec. 5(3))",
      "created_by": [
        "https://everyailaw.com/term/washington-hb2225-protocol-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators making available or deploying an AI companion chatbot for users in Washington (Sec. 2(4))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-wa"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-01-01",
      "source": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
      "source_locator": "Laws of 2026, ch. 168, Sec. 5(3)",
      "source_citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iowa-sf2417-disclosure-transparency.json",
      "eal:id": "iowa-sf2417-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Minor disclaimer, persistent option: Clearly and conspicuously disclose to a minor account holder that they are interacting with artificial intelligence, by way of a persistent visible disclaimer (§ 554J.2(1)(a)) Minor disclaimer, interval option: Alternatively, provide both a disclaimer at the beginning of each interaction between the service and the minor account holder and a disclaimer at least once every three hours of continuous interaction (§ 554J.2(1)(b)) General consumer disclosure: Where a reasonable individual interacting with the service would believe they are interacting with a human, clearly and conspicuously disclose that the service is artificial intelligence, using either a persistent visible disclaimer or a disclaimer appearing after every three hours of continuous interaction (§ 554J.3)",
      "created_by": [
        "https://everyailaw.com/term/iowa-sf2417-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — persons who develop and make a conversational AI service available to the public (§ 554J.1(4)); a conversational AI service is publicly accessible software whose primary purpose is simulating human conversation and interaction through text, audio, or visual communication, excluding R&D tools, features inside a program with a different primary purpose, narrow-and-discrete-topic systems, customer-service and commerce assistants sold to businesses, speaker/voice-assistant interfaces, and systems used solely for internal business purposes (§ 554J.1(2)); app stores and search engines are not operators merely for providing access (§ 554J.1(4))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ia"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
      "source_locator": "Iowa Code §§ 554J.1(2), 554J.1(4), 554J.2(1), 554J.3",
      "source_citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iowa-sf2417-anti-anthropomorphism-transparency.json",
      "eal:id": "iowa-sf2417-anti-anthropomorphism-transparency",
      "title": "Transparency & Disclosure",
      "content": "Reasonable measures against human-impersonation output: Institute reasonable measures to prevent the service from generating statements that would lead a reasonable individual to believe they are interacting with a human (§ 554J.2(4)) Sentience and humanity claims: Included in the bar: explicit claims that the service is sentient or human (§ 554J.2(4)(a)) Simulated emotional dependence: Included in the bar: statements that simulate emotional dependence on a minor account holder (§ 554J.2(4)(b)) Romantic or sexual framing: Included in the bar: statements that simulate a romantic interaction or a sexual innuendo (§ 554J.2(4)(c)) Adult-minor romantic role-play: Included in the bar: role-playing an adult-minor romantic relationship (§ 554J.2(4)(d))",
      "created_by": [
        "https://everyailaw.com/term/iowa-sf2417-anti-anthropomorphism.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services (§ 554J.1(4)); the duty sits in § 554J.2, headed \"minors — requirements\", and two of its four enumerated examples are framed around a minor account holder, but the operative test is what a reasonable individual would believe"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ia"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
      "source_locator": "Iowa Code § 554J.2(4)",
      "source_citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iowa-sf2417-minor-safeguards-risk-assessment.json",
      "eal:id": "iowa-sf2417-minor-safeguards-risk-assessment",
      "title": "Risk Assessment",
      "content": "No variable-reward engagement mechanics: Do not provide a minor user with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the service (§ 554J.2(2)) Reasonable measures against sexual depictions: Institute reasonable measures to prevent the service from producing visual depictions of sexually explicit material for minor account holders (§ 554J.2(3)(a)) Reasonable measures against solicitation: Institute reasonable measures to prevent the service from stating that a minor account holder should engage in sexually explicit conduct (§ 554J.2(3)(b)) Reasonable measures against objectification: Institute reasonable measures to prevent the service from sexually objectifying a minor account holder (§ 554J.2(3)(c))",
      "created_by": [
        "https://everyailaw.com/term/iowa-sf2417-minor-safeguards.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services, as to minor users and minor account holders — a minor being an individual the operator knows is, or is reasonably certain is, under eighteen years of age (§ 554J.1(3)); \"sexually explicit conduct\" and \"visual depiction\" take their 18 U.S.C. § 2256 meanings (§§ 554J.1(5)-(6))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ia"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
      "source_locator": "Iowa Code §§ 554J.1(3), 554J.1(5), 554J.1(6), 554J.2(2), 554J.2(3)",
      "source_citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iowa-sf2417-parental-controls-data-governance.json",
      "eal:id": "iowa-sf2417-parental-controls-data-governance",
      "title": "Data Governance",
      "content": "Minor self-service controls: Offer tools for minor account holders to manage their own privacy and account settings (§ 554J.2(5)(a)) Guardian controls under 13: Offer tools for the parent or guardian of a minor account holder under thirteen years of age to manage the minor's privacy and account settings (§ 554J.2(5)(b)) Risk-calibrated guardian controls: Offer tools for the parent or guardian of a minor account holder to manage the minor's privacy and account settings as appropriate based on relevant risks (§ 554J.2(5)(c))",
      "created_by": [
        "https://everyailaw.com/term/iowa-sf2417-parental-controls.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services with minor account holders; the guardian-facing duty is unconditional for account holders under thirteen years of age and risk-calibrated for older minors (§ 554J.2(5)(b)-(c))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ia"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
      "source_locator": "Iowa Code § 554J.2(5)",
      "source_citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iowa-sf2417-crisis-protocol-risk-assessment.json",
      "eal:id": "iowa-sf2417-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Adopt a protocol: Adopt protocols for the conversational AI service for responding to user prompts regarding suicidal ideation or self-harm (§ 554J.4) Crisis referral: The protocol must include making reasonable efforts to refer the user to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis service (§ 554J.4)",
      "created_by": [
        "https://everyailaw.com/term/iowa-sf2417-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services; the duty runs to all users, not only minors (§ 554J.4)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ia"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
      "source_locator": "Iowa Code § 554J.4",
      "source_citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iowa-sf2417-mental-health-bar-transparency.json",
      "eal:id": "iowa-sf2417-mental-health-bar-transparency",
      "title": "Transparency & Disclosure",
      "content": "No licensed-practice representation: Do not knowingly and intentionally cause or program a conversational AI service to make a representation that would lead a reasonable individual to believe the service is designed to provide professional psychology or behavioral health services requiring licensure under Iowa Code chapter 154B or 154D (§ 554J.5) Runtime statements covered: The bar reaches a \"representation or statement\", so programmed in-conversation output implying licensed psychology or behavioral health practice is covered, not only marketing or product description (§ 554J.5)",
      "created_by": [
        "https://everyailaw.com/term/iowa-sf2417-mental-health-bar.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services; the reference point is professional psychology or behavioral health services that would require licensure under Iowa Code chapter 154B (psychologists) or 154D (behavioral science practitioners) (§ 554J.5)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ia"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
      "source_locator": "Iowa Code § 554J.5",
      "source_citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-ai-companion-protocol-risk-assessment.json",
      "eal:id": "rhode-island-ai-companion-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Protocol as a precondition to operating: Unlawful for an operator to operate or provide an AI companion to a user unless the companion contains a protocol addressing the matters below (§ 6-63-2(a)) Suicidal ideation and self-harm: The protocol must address possible suicidal ideation or self-harm expressed by a user to the AI companion (§ 6-63-2(a)(1)) Threats of harm to others: The protocol must address possible physical harm to others expressed by a user to the AI companion (§ 6-63-2(a)(2)) Crisis referral on detection: When any such expression is made, notify the user with a referral to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis services, as soon as the expression is detected (§ 6-63-2(a)(3))",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-ai-companion-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — any person, partnership, association, firm or business entity, or any member, affiliate, subsidiary or beneficial owner of one, who operates or provides an AI companion to a user in Rhode Island. An \"AI companion\" simulates a sustained human or human-like relationship by retaining prior-interaction information to personalize engagement, asking unprompted emotion-based questions beyond direct responses, and sustaining ongoing dialogue on matters personal to the user — all three conjunctively (§ 6-63-1(1)(i)). Excluded: pure customer-service or product-information systems, systems primarily designed and marketed for efficiency improvements or research or technical assistance, and systems used solely for internal or employee-productivity purposes (§ 6-63-1(1)(ii))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26376.htm",
      "source_locator": "R.I. Gen. Laws §§ 6-63-1(1), 6-63-2(a)",
      "source_citation": "R.I. Gen. Laws §§ 6-63-1 to 6-63-5 (P.L. 2026 ch. 376)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-ai-companion-notification-transparency.json",
      "eal:id": "rhode-island-ai-companion-notification-transparency",
      "title": "Transparency & Disclosure",
      "content": "Opening notification: Provide a clear and conspicuous notification to the user at the beginning of any AI companion interaction stating that the user is not communicating with a human (§ 6-63-3) Three-hour repeat: Repeat the notification at least every three hours for continuing AI companion interactions (§ 6-63-3) Verbal or written: The notification may be delivered either verbally or in writing (§ 6-63-3)",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-ai-companion-notification.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of AI companions used by users within Rhode Island (§§ 6-63-1(6), 6-63-1(8))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26376.htm",
      "source_locator": "R.I. Gen. Laws § 6-63-3",
      "source_citation": "R.I. Gen. Laws §§ 6-63-1 to 6-63-5 (P.L. 2026 ch. 376)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-ai-companion-reporting-incident-reporting.json",
      "eal:id": "rhode-island-ai-companion-reporting-incident-reporting",
      "title": "Incident Reporting",
      "content": "Annual report: Beginning 2027-07-01, file annual reports with the Office of the Attorney General (§ 6-63-2(b)) Activation counts: Reports must include the number of safety protocol activations and related metrics (§ 6-63-2(b)) Public aggregation: The Office of the Attorney General publishes aggregated data on its website (§ 6-63-2(b))",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-ai-companion-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of AI companions used by users within Rhode Island (§ 6-63-1(6))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-07-01",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26376.htm",
      "source_locator": "R.I. Gen. Laws § 6-63-2(b)",
      "source_citation": "R.I. Gen. Laws §§ 6-63-1 to 6-63-5 (P.L. 2026 ch. 376)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-ai-mental-health-oversight-human-oversight.json",
      "eal:id": "rhode-island-ai-mental-health-oversight-human-oversight",
      "title": "Human Oversight",
      "content": "Permitted uses only: AI may be used only for administrative support (scheduling, billing, logistics communications without therapeutic advice) or supplementary support (records and therapy notes, progress-data analysis subject to review by a licensed professional, organizing external resources and referrals) — neither of which may involve therapeutic communication (§§ 40.1-5.5-2(1), (6), (8)) Licensed human must deliver the service: No individual, corporation, or entity may provide, advertise, or offer therapy or psychotherapy services to the Rhode Island public, including through internet-based AI, unless the services are conducted by a licensed professional or provider (§ 40.1-5.5-3(b)) No independent therapeutic decisions: A licensed professional or provider may not allow or use AI to make independent therapeutic decisions (§ 40.1-5.5-3(c)(1)) No unsupervised client interaction: AI may not directly interact with clients in any form of therapeutic communication absent an established treatment relationship and patient consent under this section (§ 40.1-5.5-3(c)(2)) No AI-set treatment plans: AI may not determine therapeutic recommendations or treatment plans (§ 40.1-5.5-3(c)(3)) Retained clinical responsibility: The provider retains responsibility for clinical judgement and reasonable therapeutic oversight of the patient's use of the system, but not for vendor-controlled system design, algorithms, or outputs (§§ 40.1-5.5-2(6), 40.1-5.5-3(c)(2)) Duty on client-initiated AI use: Where a client discloses self-initiated use of AI-featured software, the licensed professional may discuss and guide that use and is responsible for maintaining confidentiality, monitoring client safety, intervening when necessary, and discussing the software's limitations and risks with the patient (§ 40.1-5.5-3(d))",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-ai-mental-health-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Licensed professionals or providers — individuals holding a valid Rhode Island license, credential, or certification to provide therapy or psychotherapy services (§ 40.1-5.5-2(4)) — and, under § 40.1-5.5-3(b), any individual, corporation, or entity that provides, advertises, or otherwise offers therapy or psychotherapy services to the public in Rhode Island, including through internet-based AI. Does not apply to religious counseling, peer support, public self-help and educational materials that do not purport to offer therapy, FDA-cleared (or other federal-agency-cleared) AI tools, or IRB-approved research under 21 C.F.R. Pt. 50 / 45 C.F.R. Pt. 46 (§ 40.1-5.5-5(c))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-06-22",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26374.htm",
      "source_locator": "R.I. Gen. Laws §§ 40.1-5.5-2(1), 40.1-5.5-2(6), 40.1-5.5-2(8), 40.1-5.5-2(9), 40.1-5.5-3(b), 40.1-5.5-3(c), 40.1-5.5-3(d), 40.1-5.5-5(c)",
      "source_citation": "R.I. Gen. Laws ch. 40.1-5.5 (P.L. 2026 ch. 374)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-ai-mental-health-consent-transparency.json",
      "eal:id": "rhode-island-ai-mental-health-consent-transparency",
      "title": "Transparency & Disclosure",
      "content": "Written pre-use information: Before such use, inform the patient (or parent, guardian, or legally authorized representative) in writing that AI will be used and of the specific purpose of the AI tool or system (§ 40.1-5.5-3(a)(1)-(2)) Affirmative consent: Obtain consent as defined in § 40.1-5.5-2 — an affirmative written agreement, including by electronic means, that unambiguously communicates explicit, express, freely given, informed, voluntary, and specific agreement, and that is revocable (§§ 40.1-5.5-2(3), 40.1-5.5-3(a)(3)) Excluded consent mechanics: Consent may not be derived from acceptance of general or broad terms of use containing AI descriptions alongside unrelated information, from hovering over, muting, pausing, or closing digital content, or from deceptive actions (§ 40.1-5.5-2(3)(i)-(iii)) Consent as a gate on use: AI may be used only to the extent the use meets § 40.1-5.5-3(a) (§ 40.1-5.5-3(c))",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-ai-mental-health-consent.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Licensed professionals or providers using AI designed to simulate emotional attachment, bonding, or dependency, or AI companions for mental health or emotional support, to assist in supplementary support or therapeutic communication where the client's therapeutic session is recorded or transcribed (§ 40.1-5.5-3(a))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-06-22",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26374.htm",
      "source_locator": "R.I. Gen. Laws §§ 40.1-5.5-2(3), 40.1-5.5-3(a), 40.1-5.5-3(c)",
      "source_citation": "R.I. Gen. Laws ch. 40.1-5.5 (P.L. 2026 ch. 374)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-ai-mental-health-confidentiality-data-governance.json",
      "eal:id": "rhode-island-ai-mental-health-confidentiality-data-governance",
      "title": "Data Governance",
      "content": "Confidential records: All records kept by a licensed professional or provider and all communications between an individual seeking therapy or psychotherapy services and the provider are confidential (§ 40.1-5.5-4) Disclosure only as permitted: Records and communications may not be disclosed except as provided under R.I. Gen. Laws § 40.1-5-26 (§ 40.1-5.5-4)",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-ai-mental-health-confidentiality.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Licensed professionals or providers holding therapy or psychotherapy records and communications, including records prepared or maintained by AI acting as supplementary support under § 40.1-5.5-2(8)(i)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-06-22",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26374.htm",
      "source_locator": "R.I. Gen. Laws §§ 40.1-5.5-4, 40.1-5.5-5(a)",
      "source_citation": "R.I. Gen. Laws ch. 40.1-5.5 (P.L. 2026 ch. 374)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-healthcare-ai-notice-review-transparency.json",
      "eal:id": "rhode-island-healthcare-ai-notice-review-transparency",
      "title": "Transparency & Disclosure",
      "content": "Patient notification: Healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits must notify patients of the use of AI for that sole purpose (§ 23-108-3) Review after each visit: The same providers and facilities must review the AI-generated documentation for accuracy after the visit (§ 23-108-3)",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-healthcare-ai-notice-review.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:All healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits. \"Healthcare provider\" covers physicians, physician assistants, dentists, registered nurses, licensed practical nurses, advanced practice registered nurses, nursing assistants, and any other healthcare professional licensed by the director of the department of health; \"healthcare facility\" takes the meaning in § 23-17-2. \"Artificial intelligence\" is defined expansively as any technology that can simulate human intelligence, including natural language processing, training language models, RLHF, and machine learning systems (§ 23-108-2)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-06-22",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26372.htm",
      "source_locator": "R.I. Gen. Laws §§ 23-108-2, 23-108-3",
      "source_citation": "R.I. Gen. Laws ch. 23-108 (P.L. 2026 ch. 372)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/rhode-island-healthcare-ai-notice-review-human-oversight.json",
      "eal:id": "rhode-island-healthcare-ai-notice-review-human-oversight",
      "title": "Human Oversight",
      "content": "Patient notification: Healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits must notify patients of the use of AI for that sole purpose (§ 23-108-3) Review after each visit: The same providers and facilities must review the AI-generated documentation for accuracy after the visit (§ 23-108-3)",
      "created_by": [
        "https://everyailaw.com/term/rhode-island-healthcare-ai-notice-review.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:All healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits. \"Healthcare provider\" covers physicians, physician assistants, dentists, registered nurses, licensed practical nurses, advanced practice registered nurses, nursing assistants, and any other healthcare professional licensed by the director of the department of health; \"healthcare facility\" takes the meaning in § 23-17-2. \"Artificial intelligence\" is defined expansively as any technology that can simulate human intelligence, including natural language processing, training language models, RLHF, and machine learning systems (§ 23-108-2)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ri"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-06-22",
      "source": "https://webserver.rilegislature.gov/PublicLaws/law26/law26372.htm",
      "source_locator": "R.I. Gen. Laws §§ 23-108-2, 23-108-3",
      "source_citation": "R.I. Gen. Laws ch. 23-108 (P.L. 2026 ch. 372)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/pe-ai-law-transparency.json",
      "eal:id": "pe-ai-law-transparency",
      "title": "Transparency & Disclosure",
      "content": "Prior plain-language notice: Art. 25.1: developers or deployers of a high-risk system must inform the user beforehand, clearly and simply, of the system's purpose, main functionalities, and the type of decisions it can take, while respecting industrial and commercial secrecy Visible AI labelling: Art. 25.2: where relevant to the decision or interaction, visible labelling must tell users in advance that the product, service or content operates on AI, sufficient for the public to understand the system's main capabilities and functional limits; internal administrative uses without direct impact on rights are exempt SGTD transparency guidelines: Art. 25.4: the SGTD approves algorithmic transparency lineamientos in concert with competent SNTD entities",
      "created_by": [
        "https://everyailaw.com/term/pe-ai-law-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Private-sector and public developers (desarrolladores) and deployers (implementadores) of high-risk AI systems (Reglamento Arts. 3, 6(b), 6(d), 25.1)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "pe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2026-09-10",
      "source": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
      "source_locator": "Reglamento (D.S. 115-2025-PCM) Arts. 25.1–25.2, 25.4",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/pe-ai-law-explainability.json",
      "eal:id": "pe-ai-law-explainability",
      "title": "Explainability",
      "content": "Explanation of outcomes: Art. 25.3: where the system takes decisions that impact human rights, affected users must be guaranteed an explanation of its results, through mechanisms that make the key criteria and factors behind the automated decision comprehensible in accessible language",
      "created_by": [
        "https://everyailaw.com/term/pe-ai-law-explainability.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Private-sector and public developers and deployers of high-risk AI systems whose decisions impact human rights (Reglamento Arts. 25.1, 25.3)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "pe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/explainability.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2026-09-10",
      "source": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
      "source_locator": "Reglamento (D.S. 115-2025-PCM) Art. 25.3",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "explainability",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "explainability",
        "interpretability",
        "right to explanation",
        "algorithmic explanation"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/pe-ai-law-records-record-keeping.json",
      "eal:id": "pe-ai-law-records-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Up-to-date high-risk record: Art. 31.1: for high-risk systems, maintain a current, accessible, prevention-oriented record of the system's operating principles, the data sources used, the algorithm's logic, and the expected social and ethical impacts Governance policies: Art. 31.2: establish clear policies, protocols and procedures preserving security and privacy, promoting transparency and explainability, and guaranteeing responsibility and accountability, by reference to international technical standards Staff education: Art. 31.3: foster internal education and awareness of collaborators on AI risks and on safe, responsible and ethical adoption under the organisation's approved institutional policy",
      "created_by": [
        "https://everyailaw.com/term/pe-ai-law-records.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Private-sector developers and deployers of AI systems (Título VI Cap. II); the record duty of Art. 31.1 attaches only to high-risk systems, the policy and training duties of Arts. 31.2–31.3 to developers and deployers generally"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "pe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2026-09-10",
      "source": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
      "source_locator": "Reglamento (D.S. 115-2025-PCM) Arts. 31.1–31.3",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/pe-ai-law-human-oversight.json",
      "eal:id": "pe-ai-law-human-oversight",
      "title": "Human Oversight",
      "content": "Human oversight mechanisms: Art. 31.4: implement human supervision mechanisms over decision-making that could significantly impact health, education, justice, finance, or access to basic programmes and services Anti-automation-bias training: Art. 31.4(i): overseeing personnel must be trained in the subject matter so as not to be biased by the AI system's results Stop and override power: Art. 31.4(ii): overseeing personnel must have the capacity to stop, correct, or invalidate the AI system's decisions",
      "created_by": [
        "https://everyailaw.com/term/pe-ai-law-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Private-sector developers and deployers of high-risk AI systems taking decisions with significant impact in health, education, justice, finance, and access to basic programmes and services (Art. 31.4); public entities carry the mirror duty under Art. 28.11"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "pe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2026-09-10",
      "source": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
      "source_locator": "Reglamento (D.S. 115-2025-PCM) Art. 31.4; Art. 7(h)",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/pe-ai-law-impact-assessment-risk-assessment.json",
      "eal:id": "pe-ai-law-impact-assessment-risk-assessment",
      "title": "Risk Assessment",
      "content": "Voluntary pre-deployment assessment: Art. 32.1: before developing or implementing a high-risk system, an impact analysis may be performed voluntarily to identify and minimise potential risks, avoid harm to fundamental rights, and prevent perpetuation of inequality or bias Proactive mitigation: Art. 32.2: where risks to human rights or erroneous automated decisions are detected, the developer or deployer adopts proactive mitigation measures before final implementation — model adjustments, data-quality improvement, human oversight mechanisms Three-year documentation retention: Art. 32.3: those who perform an assessment must document findings and corrective measures and retain the documentation for at least three years from issuance, as traceability and as evidence if required by a judicial or administrative authority",
      "created_by": [
        "https://everyailaw.com/term/pe-ai-law-impact-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Private-sector developers and deployers of high-risk AI systems (Título VI Cap. II); for public administration entities the equivalent assessment under Art. 30 is mandatory"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "pe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2026-09-10",
      "source": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
      "source_locator": "Reglamento (D.S. 115-2025-PCM) Art. 32",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/uz-ai-amendments-human-oversight.json",
      "eal:id": "uz-ai-amendments-human-oversight",
      "title": "Human Oversight",
      "content": "No sole reliance on AI conclusions: When making legally significant decisions affecting human rights and freedoms, it is not permitted to rely exclusively on the conclusions of information resources and information systems created on the basis of AI technologies (Art. 7-1, para 2) No-harm principle: Information resources created using AI and information systems operating on AI technologies must not harm a person, their life, health, freedom, honor, dignity, or violate their other inalienable rights (Art. 7-1, para 1)",
      "created_by": [
        "https://everyailaw.com/term/uz-ai-amendments-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Anyone making legally significant decisions affecting human rights and freedoms using conclusions of AI-based information resources or information systems"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "uz"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-21",
      "source": "https://lex.uz/docs/8011930",
      "source_locator": "Art. 1(4) of LRU-1115, inserting Art. 7-1 into Law No. 560-II \"On Informatization\"",
      "source_citation": "Law of the Republic of Uzbekistan No. ZRU-1115 (LRU-1115) of 2026-01-21",
      "language": "uz",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/uz-ai-amendments-data-liability-data-governance.json",
      "eal:id": "uz-ai-amendments-data-liability-data-governance",
      "title": "Data Governance",
      "content": "Lawful AI personal data processing: Processing personal data using AI technologies must comply with personal data law; unlawful processing is an administrative offense (Art. 46-2 CAO, new part 2) No unlawful dissemination: Dissemination of unlawfully AI-processed personal data via mass media, telecommunications networks, or the Internet is likewise penalized Website restriction ground: Unlawful AI processing of personal data and its online dissemination becomes a ground under Art. 12-1 of the Informatization Law (grounds for restricting access to information resources)",
      "created_by": [
        "https://everyailaw.com/term/uz-ai-amendments-data-liability.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Any person unlawfully processing personal data using AI technologies, or disseminating such data via mass media, telecommunications networks, or the Internet"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "uz"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-21",
      "source": "https://lex.uz/docs/8011930",
      "source_locator": "Art. 2 of LRU-1115, adding part 2 to Art. 46-2 of the Code of Administrative Responsibility; Art. 1(5) adding a corresponding ground to Art. 12-1 of Law No. 560-II",
      "source_citation": "Law of the Republic of Uzbekistan No. ZRU-1115 (LRU-1115) of 2026-01-21",
      "language": "uz",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/vermont-act156-licensed-delivery-human-oversight.json",
      "eal:id": "vermont-act156-licensed-delivery-human-oversight",
      "title": "Human Oversight",
      "content": "Delivery by a mental health professional: A corporation or entity shall not provide, advertise, or otherwise offer mental health services, including through the use of artificial intelligence, to the public unless the services are provided by a mental health professional (§ 7115(b)(1)) Broad professional definition: \"Mental health professional\" spans physicians, psychiatric APRNs, psychologists, peer support providers, social workers, alcohol and drug abuse counselors, clinical mental health counselors, marriage and family therapists, psychoanalysts, applied behavior analysts, nonlicensed or noncertified psychotherapists, and \"any other professional who provides mental health services\" (§ 7115(a)(2)) Research exemption only: The sole alternative path is delivery as part of an approved institutional review board or privacy board study in accordance with 45 C.F.R. § 164.512(i)(1)(i)(A)-(B) (§ 7115(b)(2)) Consumer-protection enforcement: A violation by a corporation or entity is deemed a violation of the Consumer Protection Act, 9 V.S.A. chapter 63; the Attorney General has CPA enforcement authority and private parties have CPA rights and remedies (§ 7115(c)(1)), cumulative with other statutory and common law remedies (§ 7115(c)(2))",
      "created_by": [
        "https://everyailaw.com/term/vermont-act156-licensed-delivery.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Any corporation or entity that provides, advertises, or otherwise offers mental health services to the public, \"including through the use of artificial intelligence\" (§ 7115(b)). \"Mental health services\" means services to diagnose, treat, or address mental or behavioral health through therapeutic communications and therapeutic decisions (§ 7115(a)(3)); therapeutic communication is defined broadly to include direct client interactions, clinical guidance, clinical support \"including reassurance or empathy in response to emotional or psychological distress\", treatment-plan collaboration, and growth-oriented feedback (§ 7115(a)(4)). Exempt: services provided as part of an approved IRB or privacy-board study under 45 C.F.R. § 164.512(i)(1)(i)(A)-(B) (§ 7115(b)(2))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-vt"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-06-17",
      "source": "https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT156/ACT156%20As%20Enacted.pdf",
      "source_locator": "18 V.S.A. § 7115(a)(2)-(5), § 7115(b), § 7115(c)",
      "source_citation": "18 V.S.A. § 7115 (Act No. 156 (2026))",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/vermont-act156-review-approval-human-oversight.json",
      "eal:id": "vermont-act156-review-approval-human-oversight",
      "title": "Human Oversight",
      "content": "Review-and-approve condition: A mental health professional operating within scope of practice may use AI tools only if the professional \"reviews and approves any mental health services\" delivered with them (§ 7115(d)) HIPAA-compliant tools only: The safe harbor covers only AI tools compliant with the Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191 (§ 7115(d)) FDA-authorized products need a professional gate: Software-based medical products — digital therapeutics or software-as-a-medical-device products authorized, cleared, or approved by the FDA — qualify only if their use is prescribed or recommended by a mental health professional (§ 7115(d)) Unprofessional conduct for licensees: Engaging in the prohibited use of AI under § 7115 constitutes unprofessional conduct for any mental health professional under 3 V.S.A. § 129a(a)(30), and for physicians under 26 V.S.A. § 1354(a)(3), whether the conduct occurred within or outside the State — grounds for license denial or discipline",
      "created_by": [
        "https://everyailaw.com/term/vermont-act156-review-approval.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Mental health professionals operating within their scope of practice who use artificial intelligence tools in delivering mental health services, and the vendors whose tools they deploy — the safe harbor is conditioned on the tool being HIPAA-compliant and on the professional reviewing and approving any mental health services (§ 7115(d))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-vt"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-06-17",
      "source": "https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT156/ACT156%20As%20Enacted.pdf",
      "source_locator": "18 V.S.A. § 7115(d); 3 V.S.A. § 129a(a)(30); 26 V.S.A. § 1354(a)(3)",
      "source_citation": "18 V.S.A. § 7115 (Act No. 156 (2026))",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-general-disclosure-transparency.json",
      "eal:id": "utah-sb149-general-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "On-request disclosure: Must disclose AI use when consumer makes \"clear and unambiguous request\" Safe harbor: Clear + conspicuous disclosure at outset and throughout eliminates enforcement exposure (§13-75-104)",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-general-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/supplier"
      ],
      "applicability": [
        "scope:suppliers in consumer transactions"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§13-75-103(1) (general), §13-75-104 (safe harbor)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-high-risk-disclosure-transparency.json",
      "eal:id": "utah-sb149-high-risk-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Proactive disclosure: Required only for \"high-risk AI interactions\" (§13-75-101(5)): sensitive data (health/financial/biometric) or personalized advice in finance/legal/medicine/mental health Verbal at start: Required at start of oral exchange Written before start: Required in electronic messaging before written exchange",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-high-risk-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/regulated-professional"
      ],
      "applicability": [
        "scope:regulated-occupation providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§13-75-103(2)-(3), §13-75-101(5)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-chatbot-disclosure-transparency.json",
      "eal:id": "utah-sb149-chatbot-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Pre-access disclosure: Must disclose before user may access chatbot features Post-gap disclosure: Disclosure at start of interaction when >7 days since user's last interaction On-prompt disclosure: Disclosure any time user asks whether AI is used Carve-out: Scripted-only output (meditations, mindfulness) and referral-to-human-therapist bots excluded (§13-72a-101(10)(b))",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-chatbot-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:mental health chatbot suppliers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§13-72a-203",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-chatbot-data-protection-data-governance.json",
      "eal:id": "utah-sb149-chatbot-data-protection-data-governance",
      "title": "Data Governance",
      "content": "No sale/sharing: May not sell or share identifiable health information or user input with third parties Health care exception: Permitted when user-consented or user-requested to health care provider or health plan HIPAA-equivalent controls: Third-party sharing for functionality requires HIPAA Parts 160 + 164 Subparts A/E compliance as if supplier were a covered entity",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-chatbot-data-protection.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:mental health chatbot suppliers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§13-72a-201",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-chatbot-safety-policy-record-keeping.json",
      "eal:id": "utah-sb149-chatbot-safety-policy-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "15-element policy: Written policy covering intended purposes, therapist involvement, clinical best practices, testing, risk identification, user reporting, acute-risk protocols, safety reviews, safe-use instructions, AI-awareness disclosure, engagement-over-safety prohibition, non-discrimination, HIPAA compliance Documentation: Foundation models used, training data, HIPAA compliance, user data practices, ongoing accuracy/safety efforts Filing: Must file with Division of Consumer Protection + annual fee Compliance requirement: Must comply with filed policy at time of alleged violation",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-chatbot-safety-policy.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:mental health chatbot suppliers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§58-60-118",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-chatbot-safety-policy-risk-assessment.json",
      "eal:id": "utah-sb149-chatbot-safety-policy-risk-assessment",
      "title": "Risk Assessment",
      "content": "15-element policy: Written policy covering intended purposes, therapist involvement, clinical best practices, testing, risk identification, user reporting, acute-risk protocols, safety reviews, safe-use instructions, AI-awareness disclosure, engagement-over-safety prohibition, non-discrimination, HIPAA compliance Documentation: Foundation models used, training data, HIPAA compliance, user data practices, ongoing accuracy/safety efforts Filing: Must file with Division of Consumer Protection + annual fee Compliance requirement: Must comply with filed policy at time of alleged violation",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-chatbot-safety-policy.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:mental health chatbot suppliers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§58-60-118",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-chatbot-safety-policy-human-oversight.json",
      "eal:id": "utah-sb149-chatbot-safety-policy-human-oversight",
      "title": "Human Oversight",
      "content": "15-element policy: Written policy covering intended purposes, therapist involvement, clinical best practices, testing, risk identification, user reporting, acute-risk protocols, safety reviews, safe-use instructions, AI-awareness disclosure, engagement-over-safety prohibition, non-discrimination, HIPAA compliance Documentation: Foundation models used, training data, HIPAA compliance, user data practices, ongoing accuracy/safety efforts Filing: Must file with Division of Consumer Protection + annual fee Compliance requirement: Must comply with filed policy at time of alleged violation",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-chatbot-safety-policy.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:mental health chatbot suppliers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§58-60-118",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-personal-identity-transparency.json",
      "eal:id": "utah-sb149-personal-identity-transparency",
      "title": "Transparency & Disclosure",
      "content": "Expanded scope: Personal identity now covers name, title, picture, portrait, video likeness, voice, audiovisual appearance — including AI simulation/reproduction Voice definition: Any computer-generated sound \"readily identifiable and attributable\" to an individual Tool distribution liability: Knowingly distributing tools whose \"intended primary purpose\" is unauthorized personal-identity content creation for commercial purposes = abuse Exemptions: News, public affairs, sports, art, parody, political speech; §230 interactive-computer-service safe harbor",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-personal-identity.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/distributor"
      ],
      "applicability": [
        "scope:any person using or distributing tools for personal-identity creation"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-05-07",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§§45-3-2, -3, -4, -5, -7",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-learning-lab-agreements-record-keeping.json",
      "eal:id": "utah-sb149-learning-lab-agreements-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Participant eligibility: Five prongs per §13-72-402: technical capability, financial resources, substantial consumer benefits outweighing risks, risk-monitoring plan, appropriately-limited scope Agreement contents: Scope limits, safeguards, mitigation granted, required consumer disclosures, reporting requirements (§13-72-401(4)) Counterparties: OAIP + relevant state agency or governmental entity (judiciary, higher-ed, political subdivisions per HB 320) Term: Initial 12 months + up to 2 × 12-month extensions (36 months total per §13-72-403) Mandatory audits: OAIP \"shall perform regular audits\" while agreement is active (§13-72-401(6), HB 320) Agreement types: Regulatory mitigation (waives specified law) or joint interpretation (clarifies statute application to AI) Annual report: Nov 30 to Business & Labor Interim Committee: learning agenda, findings/participation/outcomes, executed agreements, recommended legislation (§13-72-201(3)(d))",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-learning-lab-agreements.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/program-participant"
      ],
      "applicability": [
        "scope:Learning Lab participants"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§§13-72-201, -301, -401, -402, -403",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ],
      "eal:effective_text": "2024-05-01 (original); 2026-05-06 (HB 320 restructure)"
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/utah-sb149-ai-liability-record-keeping.json",
      "eal:id": "utah-sb149-ai-liability-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Civil (§13-75-102): \"Not a defense\" that GenAI made the violative statement, undertook the violative act, or was used in furtherance Criminal (§76-2-107): Principal may be found guilty if they commit offense \"with the aid of\" or \"intentionally prompt\" GenAI to commit offense",
      "created_by": [
        "https://everyailaw.com/term/utah-sb149-ai-liability.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:any principal using or prompting GenAI"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ut"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "source": "https://le.utah.gov/~2024/bills/static/SB0149.html",
      "source_locator": "§13-75-102 (civil), §76-2-107 (criminal)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-04-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ],
      "eal:effective_text": "2024-05-01 (criminal); 2025-05-07 (civil)"
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-literacy-ai-literacy.json",
      "eal:id": "eu-ai-act-literacy-ai-literacy",
      "title": "AI Literacy & Training",
      "content": "Support AI literacy: Providers and deployers must take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf (Article 4(1), as replaced by Regulation (EU) 2026/1744 from 2026-07-27) Context-specific: Measures must take account of technical knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are used (Article 4(1)) No guaranteed level: The obligation expressly does not require providers or deployers to guarantee any specific level of AI literacy of any individual (Article 4(1), second sentence — added by the Digital Omnibus) Commission support: The Commission and Member States must support providers and deployers, in particular SMEs, and the Commission must publish practical compliance examples on the single information platform (Article 4(2), Article 62(3)(b)) Board recommendations: The AI Board must adopt recommendations, taking account of European competence frameworks, including common objectives (Article 4(3))",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-literacy.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/ai-literacy.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-02-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 4",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "ai-literacy",
      "eal:group": "competence",
      "eal:status": "active",
      "eal:search_terms": [
        "AI literacy",
        "AI training",
        "staff competence",
        "AI education"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-human-oversight.json",
      "eal:id": "eu-ai-act-human-oversight",
      "title": "Human Oversight",
      "content": "Effective oversight: High-risk AI must enable oversight by natural persons (Article 14(1)) Understand capabilities: Overseers must understand system capacities and limitations (Article 14(4)(a)) Monitor for anomalies: Must monitor operation and detect unexpected performance, anomalies, and dysfunctions (Article 14(4)(a)) Address automation bias: Must remain aware of automation-bias risk in oversight (Article 14(4)(b)) Interpret output: Must be able to correctly interpret output using available tools (Article 14(4)(c)) Override/reverse: Must be able to decide not to use, disregard, override, or reverse AI output (Article 14(4)(d)) Intervene or halt: Must be able to intervene or interrupt system operation via stop button or equivalent halt procedure (Article 14(4)(e)) Competent personnel: Deployers must assign persons with necessary competence, training, and authority (Article 26(2)) Dual verification (biometric): For Annex III point 1(a) systems (remote biometric ID), no action or decision may be taken unless separately verified and confirmed by at least two natural persons with competence, training, and authority — except where EU/national law deems disproportionate for law enforcement, migration, border, or asylum purposes (Article 14(5))",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-12-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 14, Article 26(2)",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-transparency.json",
      "eal:id": "eu-ai-act-transparency",
      "title": "Transparency & Disclosure",
      "content": "Interaction disclosure: Providers must design systems intended to interact directly with natural persons so those persons are informed they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person (Article 50(1)) Synthetic content marking: Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format detectable as artificially generated or manipulated (Article 50(2)) Emotion recognition and biometric categorisation notice: Deployers must inform natural persons exposed to emotion recognition or biometric categorisation systems of their operation (Article 50(3)) Deepfake disclosure: Deployers generating or manipulating image, audio or video constituting a deepfake must disclose that the content is artificially generated or manipulated (Article 50(4)) Generative AI grace period: Pre-existing generative AI systems on the market before 2026-08-02 have until 2026-12-02 to comply with Article 50(2) machine-readable marking (Article 111(4), inserted by Regulation (EU) 2026/1744) Marking codes of practice: The Commission facilitates Union-level codes of practice for detection, marking and labelling of AI-generated or manipulated content, assesses their adequacy for Article 50(2) and (4), and may impose common rules by implementing act if a code is inadequate (Article 50(7), as replaced by Regulation (EU) 2026/1744)",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Providers of systems intended to interact directly with natural persons and of systems generating synthetic audio, image, video or text (Article 50(1)-(2)); deployers of emotion recognition or biometric categorisation systems and of systems producing deepfakes (Article 50(3)-(4))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-08-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 50",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-high-risk-transparency.json",
      "eal:id": "eu-ai-act-high-risk-transparency",
      "title": "Transparency & Disclosure",
      "content": "Operational transparency: High-risk systems must be designed and developed so their operation is sufficiently transparent to enable deployers to interpret output and use it appropriately (Article 13(1)) Instructions for use: High-risk systems must be accompanied by instructions for use in an appropriate digital format, containing concise, complete, correct and clear information accessible and comprehensible to deployers (Article 13(2)) Provider identity: Instructions must state the identity and contact details of the provider and, where applicable, its authorised representative (Article 13(3)(a)) Capabilities and limitations: Instructions must state intended purpose, the accuracy, robustness and cybersecurity metrics the system was validated against, foreseeable circumstances affecting those levels, and risks arising under intended use or reasonably foreseeable misuse (Article 13(3)(b)) Explainability information: Where applicable, instructions must describe technical capabilities to provide information explaining the system's output (Article 13(3)(b)(iv)) Human oversight measures: Instructions must describe the human oversight measures built in under Article 14, including technical measures facilitating output interpretation by deployers (Article 13(3)(d)) Expected lifetime and maintenance: Instructions must state expected lifetime and any necessary maintenance and care measures, including software updates (Article 13(3)(e))",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-high-risk-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Providers of high-risk AI systems. The duty runs to the instructions for use supplied to deployers, not to end users"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-12-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 13",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-risk-management-risk-assessment.json",
      "eal:id": "eu-ai-act-risk-management-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk management system: Establish and maintain throughout AI lifecycle (Article 9(1)) Identify and analyze: Identify known and reasonably foreseeable risks to health, safety, and fundamental rights during intended use (Article 9(2)(a)) Estimate and evaluate: Estimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse conditions (Article 9(2)(b)) Post-market evaluation: Evaluate risks based on data from post-market monitoring (Article 9(2)(c)) Risk mitigation: Take appropriate and targeted mitigation measures addressing identified risks (Article 9(2)(d)) Design-based reduction: Eliminate or reduce risks through adequate design and development where technically feasible (Article 9(5)(a)) Residual risk: Ensure residual risk associated with each hazard and overall residual risk is judged acceptable (Article 9(5)) Testing: Test to identify appropriate risk management measures and ensure consistent performance and compliance; tested against prior defined metrics and probabilistic thresholds (Article 9(6)-(8)) Continuous monitoring: Ongoing performance monitoring throughout the system lifecycle",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-risk-management.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers of high-risk AI systems"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-12-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 9",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-conformity-conformity-assessment.json",
      "eal:id": "eu-ai-act-conformity-conformity-assessment",
      "title": "Conformity Assessment",
      "content": "Conformity assessment: Must undergo before placing on market or putting into service (Article 43) CE marking: Required for high-risk AI systems once assessment complete (Article 48) Quality management: Must establish quality management system (Article 17); implementation must be proportionate to the size of the provider's organisation, in particular for SMEs, start-ups, and small mid-cap enterprises, without lowering the rigour needed for compliance (Article 17(2), as replaced by Regulation (EU) 2026/1744) Documentation: Maintain technical documentation throughout lifecycle (Article 18); SMEs, start-ups, and SMCs may supply the Annex IV elements in simplified form using a Commission-issued simplified form (Article 11(1), as amended) No forced third-party assessment: Where Annex I Section A legislation lets a manufacturer self-assess against harmonised standards, classification of the product as high-risk under Article 6(1) does not by itself force a third-party conformity assessment (Article 43(3), as replaced) Annex III phasing: Annex III high-risk systems: 2027-12-02 (deferred from 2026-08-02 by Regulation (EU) 2026/1744). Annex I high-risk (safety components covered by other EU product laws, e.g., medical devices): 2028-08-02 (deferred from 2027-08-02). Notified bodies already notified under Annex I Section A legislation must apply for designation under the AI Act by 2028-01-28",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-conformity.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/conformity-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-12-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Articles 17-18, 40-49",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "conformity-assessment",
      "eal:group": "compliance",
      "eal:status": "active",
      "eal:search_terms": [
        "conformity assessment",
        "certification",
        "CE marking",
        "compliance verification",
        "third-party audit"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nist-ai-rmf-risk-risk-assessment.json",
      "eal:id": "nist-ai-rmf-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Govern: Establish AI risk governance Map: Identify and categorize AI risks Measure: Assess and track risks Manage: Prioritize and mitigate risks",
      "created_by": [
        "https://everyailaw.com/term/nist-ai-rmf-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-01-26",
      "source": "https://www.nist.gov/artificial-intelligence/executive-order-safe-secure-and-trustworthy-artificial-intelligence",
      "source_locator": "AI RMF 1.0",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-25",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-record-keeping.json",
      "eal:id": "eu-ai-act-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Automatic logging: High-risk AI systems must log events automatically throughout lifecycle Traceability: Logs must enable risk identification and post-market monitoring Deployer monitoring: Logs must support operational monitoring by deployers (Article 26(5)) Log retention: Providers must keep Article 12(1) logs under their control for at least six months (Article 19(1)); deployers must keep logs under their control for at least six months (Article 26(6)); financial institutions keep logs per Union financial services law (Articles 19(2), 26(6)) Tamper-evident storage: Best-practice/conformity expectation — Article 12 does not itself use \"immutable\" or \"tamper-evident\"; integrity of logs is derived from broader auditability and conformity-assessment requirements Biometric ID specifics: Remote biometric systems (Annex III point 1(a)) must log period of use, reference database, input data, and verifying personnel (Article 12(3))",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-12-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 12, Article 19, Article 26(5)-(6)",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-21",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-fria-risk-assessment.json",
      "eal:id": "eu-ai-act-fria-risk-assessment",
      "title": "Risk Assessment",
      "content": "Pre-deployment assessment: Assess the impact on fundamental rights before putting the high-risk system into use (Article 27(1)) Process description: Describe the deployer processes in which the system will be used, in line with its intended purpose (Article 27(1)(a)) Period and frequency: Describe the period and frequency of intended use (Article 27(1)(b)) Affected persons: Identify the categories of natural persons and groups likely to be affected in the specific context (Article 27(1)(c)) Specific harms: Identify specific risks of harm to those categories, using the provider information supplied under Article 13 (Article 27(1)(d)) Human oversight: Describe implementation of human oversight measures per the instructions for use (Article 27(1)(e)) Response measures: Set out measures if risks materialise, including internal governance arrangements and complaint mechanisms (Article 27(1)(f)) First use and updates: Applies to first use; earlier assessments (including a provider's) may be relied on in similar cases, and the assessment must be updated when elements change (Article 27(2)) Notify authority: Notify the market surveillance authority of the results, submitting the filled-out template (Article 27(3)) DPIA cross-reference: Where an obligation is already met by a GDPR Article 35 or LED Article 27 data protection impact assessment, the deployer may cross-reference the relevant sections or incorporate parts of it (Article 27(4), as replaced by Regulation (EU) 2026/1744) AI Office template: The AI Office must develop a questionnaire template, including an automated tool, allowing DPIA cross-references (Article 27(5), as replaced)",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-fria.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Deployers that are bodies governed by public law or private entities providing public services, and any deployer of Annex III point 5(b)-(c) systems (creditworthiness assessment, life and health insurance risk assessment and pricing); Annex III point 2 (critical infrastructure) systems are excluded"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-12-02",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 27",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-ai-act-bias-data-basis-bias-prevention.json",
      "eal:id": "eu-ai-act-bias-data-basis-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Strict necessity: Processing is permitted only to the extent strictly necessary for bias detection and correction under Article 10(2)(f)-(g) (Article 4a(1)) No alternative data: Bias detection and correction must be impossible to achieve effectively with other data, including synthetic or anonymised data (Article 4a(1)(a)) Technical limits: Re-use must be technically limited, with state-of-the-art security and privacy-preserving measures including pseudonymisation (Article 4a(1)(b)) Access control: Strict, documented access controls, confidentiality obligations, and authorised-person-only access (Article 4a(1)(c)) No onward transfer: The special-category data must not be transmitted, transferred, or otherwise accessed by other parties (Article 4a(1)(d)) Deletion: Delete once the bias is corrected or the retention period ends, whichever is first (Article 4a(1)(e)) Documented justification: GDPR/EUDPR/LED records of processing must state why the processing was strictly necessary and why other data would not achieve the objective (Article 4a(1)(f)) Extension beyond high-risk: Providers and deployers of other AI systems and models, and deployers of high-risk systems, may rely on the same basis where strictly necessary to address biases affecting health, safety, fundamental rights, or prohibited discrimination — subject to all Article 4a(1) safeguards (Article 4a(2)) No duty created: Article 4a(2) expressly creates no obligation to carry out bias detection and correction",
      "created_by": [
        "https://everyailaw.com/term/eu-ai-act-bias-data-basis.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Providers of high-risk AI systems (Article 4a(1)); providers and deployers of other AI systems and models, and deployers of high-risk AI systems (Article 4a(2))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-27",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "source_locator": "Article 4a",
      "source_citation": "Regulation (EU) 2024/1689",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-dora-ict-risk-risk-assessment.json",
      "eal:id": "eu-dora-ict-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "ICT risk management framework: Comprehensive framework for identifying, assessing, and mitigating ICT risks Governance: Management body must approve and oversee the ICT risk management framework Business continuity: Establish ICT business continuity and disaster recovery plans Cyber risk management: Address cybersecurity risks as part of the ICT risk framework",
      "created_by": [
        "https://everyailaw.com/term/eu-dora-ict-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-01-17",
      "source": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
      "source_locator": "Articles 5-16",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-dora-incident-reporting.json",
      "eal:id": "eu-dora-incident-reporting",
      "title": "Incident Reporting",
      "content": "Classify incidents: Classify ICT-related incidents using ESA criteria Major incident reporting: Notify competent authorities of major ICT incidents Reporting thresholds: >24 hours duration, >2 hours critical service disruption, ≥2 EU states affected, or >EUR 100,000 economic impact Voluntary threat reporting: Encouraged to report significant cyber threats",
      "created_by": [
        "https://everyailaw.com/term/eu-dora-incident-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-01-17",
      "source": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
      "source_locator": "Articles 17-23",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-dora-resilience-testing-record-keeping.json",
      "eal:id": "eu-dora-resilience-testing-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Resilience testing program: Conduct regular testing of ICT systems and tools Threat-led penetration testing: Significant entities must perform TLPT aligned with TIBER-EU Documentation and remediation: Document test results and remediate identified vulnerabilities",
      "created_by": [
        "https://everyailaw.com/term/eu-dora-resilience-testing.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-01-17",
      "source": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
      "source_locator": "Articles 24-27",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-dora-third-party-risk-risk-assessment.json",
      "eal:id": "eu-dora-third-party-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Contractual requirements: Key contractual provisions for ICT third-party service agreements Concentration risk: Assess and manage concentration risk from third-party ICT dependencies Critical provider oversight: Designated critical third-party providers (CTPPs) subject to ESA oversight Exit strategies: Maintain exit strategies for critical ICT third-party services Register of Information: Maintain and keep up-to-date a register of information on all ICT third-party contractual arrangements, and submit it to competent authorities upon request or as required (DORA Article 28)",
      "created_by": [
        "https://everyailaw.com/term/eu-dora-third-party-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-01-17",
      "source": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
      "source_locator": "Articles 28-44",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/uk-dpa-2018-adm-human-oversight.json",
      "eal:id": "uk-dpa-2018-adm-human-oversight",
      "title": "Human Oversight",
      "content": "ADM definition: Art. 22A(1): a decision is based solely on automated processing where there is no meaningful human involvement; it is a significant decision where it produces a legal effect or a similarly significant effect for the data subject Role of profiling: Art. 22A(2): when assessing whether human involvement is meaningful, the extent to which the decision is reached by profiling must be considered — profiling is a factor in the test, not part of the definition Special category restriction: Art. 22B(1)-(3): a significant decision based wholly or partly on Article 9(1) special category data may not be taken solely automatically unless the data subject gave explicit consent, or the decision is necessary for a contract or required by law and Article 9(2)(g) applies Recognised legitimate interests bar: Art. 22B(4): a significant decision may not be taken solely automatically where the processing relies wholly or partly on Article 6(1)(ea) Required safeguards: Art. 22C(1)-(2): where a significant decision is based on personal data and taken solely automatically, the controller must have safeguards that provide information about the decision, enable representations, enable human intervention on the controller's part, and enable the decision to be contested Secretary of State powers: Art. 22D: regulations may define when human involvement is or is not meaningful, what counts as a similarly significant effect, and may add to the Art. 22C safeguards, but may not amend Art. 22C; subject to the affirmative resolution procedure Law-enforcement analogue out of scope: The lettered ADM sections in the DPA 2018 itself — ss. 50A-50D (Part 3, law-enforcement processing) and s. 96 (Part 4, intelligence services) — are separate regimes and do not apply to the deployers covered here; s. 14 remains the Part 2 safeguard provision for decisions required or authorised by law",
      "created_by": [
        "https://everyailaw.com/term/uk-dpa-2018-adm-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "uk"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-02-05",
      "source": "https://legislation.gov.uk/ukpga/2018/12/contents",
      "source_locator": "Articles 22A-22D UK GDPR; DPA 2018 s.14",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/uk-dpa-2018-adm-transparency.json",
      "eal:id": "uk-dpa-2018-adm-transparency",
      "title": "Transparency & Disclosure",
      "content": "Logic disclosure: Arts. 13(2)(f) and 14(2)(g): controllers must disclose the existence of automated decision-making, including profiling, that is subject to the Art. 22C safeguard requirement, and at least in those cases provide meaningful information about the logic involved Significance and consequences: The same provisions require the significance and the envisaged consequences of the processing for the data subject to be given Point of disclosure: Art. 13 applies where data is collected from the data subject; Art. 14 where it is obtained from another source",
      "created_by": [
        "https://everyailaw.com/term/uk-dpa-2018-adm-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "uk"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2018-05-25",
      "source": "https://legislation.gov.uk/ukpga/2018/12/contents",
      "source_locator": "Articles 13-14 UK GDPR",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/uk-osa-transparency.json",
      "eal:id": "uk-osa-transparency",
      "title": "Transparency & Disclosure",
      "content": "Illegal content duty: Platforms must address AI-generated illegal content (deepfakes, CSAM) Children's safety: Prevent AI-generated or amplified content harmful to children Risk assessment: Platforms must assess risks from AI-generated content Transparency reports: Annual transparency reports on content moderation including AI systems",
      "created_by": [
        "https://everyailaw.com/term/uk-osa-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "uk"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2024-03-17",
      "source": "https://www.legislation.gov.uk/ukpga/2023/50/contents",
      "source_locator": "Parts 3-4",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/uk-osa-risk-assessment.json",
      "eal:id": "uk-osa-risk-assessment",
      "title": "Risk Assessment",
      "content": "Illegal content risk assessment: Assess risks of AI systems generating or amplifying illegal content Children's risk assessment: Assess risks of AI-generated content reaching children Mitigation measures: Implement proportionate measures to mitigate identified risks",
      "created_by": [
        "https://everyailaw.com/term/uk-osa-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "uk"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2024-03-17",
      "source": "https://www.legislation.gov.uk/ukpga/2023/50/contents",
      "source_locator": "Section 9 (illegal content risk assessment duties), Section 11 (children's risk assessment duties)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-cpa-rules-human-oversight.json",
      "eal:id": "colorado-cpa-rules-human-oversight",
      "title": "Human Oversight",
      "content": "Solely Automated Processing: Decisions made by automated systems without human intervention or review Human Reviewed Automated Processing: Review of automated decisions that does not rise to the level of Human Involved Automated Processing Human Involved Automated Processing: Human involvement requires both meaningful consideration of the data and output, and the authority to change or influence the outcome of the automated processing Consent implications: Level of automation determines consent and opt-out requirements for profiling",
      "created_by": [
        "https://everyailaw.com/term/colorado-cpa-rules-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/controller"
      ],
      "applicability": [
        "scope:controllers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-07-01",
      "source": "https://coag.gov/colorado-privacy-act-rulemaking/",
      "source_locator": "Rule 2.02",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-cpa-rules-risk-assessment.json",
      "eal:id": "colorado-cpa-rules-risk-assessment",
      "title": "Risk Assessment",
      "content": "DPA for profiling: Controllers must conduct a Data Protection Assessment for profiling that presents a reasonably foreseeable risk of harm Risk evaluation: Assess risks to consumers from profiling activities Mitigation measures: Identify and document mitigation measures for identified risks Covers automated decisions: Applies to all three tiers of automated processing defined in Rule 2.02",
      "created_by": [
        "https://everyailaw.com/term/colorado-cpa-rules-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/controller"
      ],
      "applicability": [
        "scope:controllers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-07-01",
      "source": "https://coag.gov/colorado-privacy-act-rulemaking/",
      "source_locator": "Rule 9.06(A)-(B)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cn-algorithm-recommendation-transparency.json",
      "eal:id": "cn-algorithm-recommendation-transparency",
      "title": "Transparency & Disclosure",
      "content": "Algorithm filing: Providers with public opinion properties or social mobilization capabilities must file algorithm details with the CAC filing system (Art. 24) Public disclosure: Must disclose basic principles of algorithmic recommendations to users (Art. 16) User controls: Users must be able to turn off algorithmic recommendations (Art. 17) Content management: Providers must review and manage content recommended by algorithms (Art. 26)",
      "created_by": [
        "https://everyailaw.com/term/cn-algorithm-recommendation-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers with public opinion properties or social mobilization capabilities"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "cn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2022-03-01",
      "source": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "source_locator": "Articles 16, 17, 24, 26, 33",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cn-algorithm-recommendation-risk-risk-assessment.json",
      "eal:id": "cn-algorithm-recommendation-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Periodic review: Must periodically review, evaluate, and verify algorithms, models, data, and outcomes (Art. 8) Security monitoring: Must monitor for security risks, maintain incident response capability, and keep an illegal/undesirable-content feature database with reporting to authorities (Art. 9) User controls: Users must be able to turn off algorithmic recommendations (Art. 17) Security assessment: Providers with public opinion properties or social mobilization capabilities must file and undergo security assessment (Art. 24)",
      "created_by": [
        "https://everyailaw.com/term/cn-algorithm-recommendation-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "cn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2022-03-01",
      "source": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "source_locator": "Articles 7-9, 17, 24, 33",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cn-deep-synthesis-transparency.json",
      "eal:id": "cn-deep-synthesis-transparency",
      "title": "Transparency & Disclosure",
      "content": "Watermarking: Deep synthesis content must include visible or embedded watermarks Labeling: AI-generated or manipulated content must be clearly labeled Traceability: Providers must maintain logs of deep synthesis operations User notification: Users must be informed when interacting with deep synthesis content",
      "created_by": [
        "https://everyailaw.com/term/cn-deep-synthesis-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "cn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-01-10",
      "source": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "source_locator": "Articles 16-18",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cn-deep-synthesis-record-keeping.json",
      "eal:id": "cn-deep-synthesis-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Operation logs: Maintain logs of deep synthesis generation activities User identity: Verify and record user identity for deep synthesis service users Data retention: Retain logs for regulatory inspection",
      "created_by": [
        "https://everyailaw.com/term/cn-deep-synthesis-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "cn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-01-10",
      "source": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "source_locator": "Articles 10, 20-22",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cn-generative-ai-transparency.json",
      "eal:id": "cn-generative-ai-transparency",
      "title": "Transparency & Disclosure",
      "content": "Content labeling: AI-generated content must be labeled Content compliance: Must comply with socialist core values and not generate prohibited content User notification: Users must be informed they are interacting with generative AI Complaint mechanism: Providers must establish user complaint and reporting channels",
      "created_by": [
        "https://everyailaw.com/term/cn-generative-ai-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "cn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-08-15",
      "source": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "source_locator": "Articles 4, 9, 12, 15",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cn-generative-ai-risk-risk-assessment.json",
      "eal:id": "cn-generative-ai-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Security assessment: Services with public opinion properties require security assessment Algorithm filing: Must file algorithms with regulators per Algorithm Recommendation Regulations Training data compliance: Training data must be lawfully obtained and not infringe IP or personal data Model monitoring: Must monitor outputs and stop illegal content generation, delete, report Cooperation with inspections: Must cooperate with regulatory inspections",
      "created_by": [
        "https://everyailaw.com/term/cn-generative-ai-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "cn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-08-15",
      "source": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "source_locator": "Articles 5-8, 14, 17",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/cn-generative-ai-incident-incident-reporting.json",
      "eal:id": "cn-generative-ai-incident-incident-reporting",
      "title": "Incident Reporting",
      "content": "Stop illegal content: Must immediately stop generation and transmission of illegal content Delete and report: Must delete illegal content and report to the relevant departments in charge User violation handling: Must warn or suspend users engaging in illegal activity, and report",
      "created_by": [
        "https://everyailaw.com/term/cn-generative-ai-incident.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "cn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-08-15",
      "source": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "source_locator": "Article 14",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/kr-ai-basic-act-risk-risk-assessment.json",
      "eal:id": "kr-ai-basic-act-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "High-impact domains: Art. 2(4) defines high-impact AI by domain, not by model size: energy supply, drinking water, healthcare services, medical and digital medical devices, nuclear materials and facilities, biometric analysis for criminal investigation, judgments significantly affecting rights such as employment or loan decisions, and transport operations Self-review and confirmation: Art. 33 requires operators to review in advance whether a system is high-impact, and allows them to request confirmation from the Minister of Science and ICT Operator obligations: Art. 34 requires a risk management plan; explanation measures covering final outputs, the principal criteria used, and an overview of training data, to the extent technically feasible; user-protection measures; human oversight; and retained documentation of the measures taken Impact assessment: Art. 35 is a best-effort duty — operators \"shall endeavor\" to assess impacts on fundamental rights; public institutions are to prioritise products that have been assessed Vulnerable-group reflection: Art. 35(1) latter part (added by Act No. 21311, in force 2026-07-21) requires that where an impact assessment is conducted, it must reflect the characteristics of AI-vulnerable groups (persons with disabilities, older persons, and others prescribed by Presidential Decree under Art. 3(5)), considering the nature of the product or service Compute-threshold safety duty: Art. 32 imposes separate safety measures on models whose cumulative training compute meets the threshold set by Presidential Decree; the threshold value itself lives in the decree, not the Act",
      "created_by": [
        "https://everyailaw.com/term/kr-ai-basic-act-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "kr"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-22",
      "source": "https://law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%EB%B0%9C%EC%A0%84%EA%B3%BC%EC%8B%A0%EB%A2%B0%EA%B8%B0%EB%B0%98%EC%A1%B0%EC%84%B1%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B8%B0%EB%B3%B8%EB%B2%95",
      "source_locator": "Articles 32-35 (definition at Article 2(4))",
      "language": "ko",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/kr-ai-basic-act-transparency.json",
      "eal:id": "kr-ai-basic-act-transparency",
      "title": "Transparency & Disclosure",
      "content": "Prior notification: Art. 31(1) requires operators to notify users in advance that a product or service using high-impact AI or generative AI is operated on that basis Generative output indication: Art. 31(2) requires clear indication to users that outputs are generated by GenAI Realistic synthetic content: Art. 31(3) requires clearly recognisable notification or marking where AI generates virtual audio, images, or video hard to distinguish from real content Artistic-works carve-out: Art. 31(3) proviso allows the marking of artistic or creative works to be made in a way that does not interfere with their exhibition or enjoyment Methods and exceptions: Art. 31(4) leaves the methods of notification and marking, and exceptions to them, to Presidential Decree",
      "created_by": [
        "https://everyailaw.com/term/kr-ai-basic-act-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "kr"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-22",
      "source": "https://law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%EB%B0%9C%EC%A0%84%EA%B3%BC%EC%8B%A0%EB%A2%B0%EA%B8%B0%EB%B0%98%EC%A1%B0%EC%84%B1%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B8%B0%EB%B3%B8%EB%B2%95",
      "source_locator": "Article 31",
      "language": "ko",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/kr-ai-basic-act-oversight-human-oversight.json",
      "eal:id": "kr-ai-basic-act-oversight-human-oversight",
      "title": "Human Oversight",
      "content": "Human oversight mechanisms: Art. 34(1) requires human oversight of the operation of high-impact AI, alongside a risk management plan, explanation measures, user protection, and documentation Ministerial guidelines: Art. 34(2) lets the Minister of Science and ICT publish detailed guidelines on those measures and recommend compliance Domestic representative: Art. 36 requires qualifying foreign operators to designate a domestic representative On-site inspections: Art. 40 lets the Minister of Science and ICT require submission of data and conduct on-site inspections under the Administrative Investigation Framework Act Corrective measures: Art. 40 authorises corrective orders against non-compliant operators",
      "created_by": [
        "https://everyailaw.com/term/kr-ai-basic-act-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "kr"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-22",
      "source": "https://law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%EB%B0%9C%EC%A0%84%EA%B3%BC%EC%8B%A0%EB%A2%B0%EA%B8%B0%EB%B0%98%EC%A1%B0%EC%84%B1%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B8%B0%EB%B3%B8%EB%B2%95",
      "source_locator": "Articles 34, 36, 40",
      "language": "ko",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/vn-ai-law-risk-risk-assessment.json",
      "eal:id": "vn-ai-law-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk classification: AI systems classified and managed based on risk levels High-risk list: Prime Minister prescribes the list of high-risk AI systems Conformity assessment: High-risk systems require conformity assessment and certification before use Grace periods: 18 months for legacy systems in health/education/finance; 12 months for others",
      "created_by": [
        "https://everyailaw.com/term/vn-ai-law-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "vn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-03-01",
      "source": "https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Luat-Tri-tue-nhan-tao-2025-134-2025-QH15-637889.aspx",
      "source_locator": "Articles 9-15 (Chapter II)",
      "language": "vi",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/vn-ai-law-risk-conformity-assessment.json",
      "eal:id": "vn-ai-law-risk-conformity-assessment",
      "title": "Conformity Assessment",
      "content": "Risk classification: AI systems classified and managed based on risk levels High-risk list: Prime Minister prescribes the list of high-risk AI systems Conformity assessment: High-risk systems require conformity assessment and certification before use Grace periods: 18 months for legacy systems in health/education/finance; 12 months for others",
      "created_by": [
        "https://everyailaw.com/term/vn-ai-law-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "vn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/conformity-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-03-01",
      "source": "https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Luat-Tri-tue-nhan-tao-2025-134-2025-QH15-637889.aspx",
      "source_locator": "Articles 9-15 (Chapter II)",
      "language": "vi",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "conformity-assessment",
      "eal:group": "compliance",
      "eal:status": "active",
      "eal:search_terms": [
        "conformity assessment",
        "certification",
        "CE marking",
        "compliance verification",
        "third-party audit"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/vn-ai-law-oversight-human-oversight.json",
      "eal:id": "vn-ai-law-oversight-human-oversight",
      "title": "Human Oversight",
      "content": "Human-centric: Art. 4: AI activities must place humans at the center Human authority: Art. 4: AI must not replace human authority in decision-making Monitoring protection: Art. 4: prohibits obstructing or falsifying human monitoring, intervention, and control Ethical principles: Chapter V (Arts 26-27): national AI ethics framework and ethical responsibility/impact assessment — transparency, fairness, non-bias",
      "created_by": [
        "https://everyailaw.com/term/vn-ai-law-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "vn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-03-01",
      "source": "https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Luat-Tri-tue-nhan-tao-2025-134-2025-QH15-637889.aspx",
      "source_locator": "Article 4, Articles 26-27 (Chapter V)",
      "language": "vi",
      "evidence_type": "official-source",
      "verified": "2026-07-11",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/vn-ai-law-transparency.json",
      "eal:id": "vn-ai-law-transparency",
      "title": "Transparency & Disclosure",
      "content": "Machine-readable marking: Art. 11(2): providers must mark AI-generated audio, image, and video content in a machine-readable format Deployer notification: Art. 11(3): deployers must give clear notice when publishing AI-generated/edited content likely to confuse authenticity; Art. 11(4): simulations of real persons/events need easily recognisable labels Conformity information: Art. 13 / Art. 14(1)(e): high-risk systems require conformity assessment; providers must publicise functional description, operating methods, and risk warnings Labeling requirements: Art. 7(5): prohibits concealing, erasing, or falsifying mandatory information, labels, and warnings Deepfake prohibition: Art. 7(2)(b): prohibits forged elements or simulations of real people/events used to systematically deceive or manipulate",
      "created_by": [
        "https://everyailaw.com/term/vn-ai-law-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "vn"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-03-01",
      "source": "https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Luat-Tri-tue-nhan-tao-2025-134-2025-QH15-637889.aspx",
      "source_locator": "Article 7, Article 11, Articles 13-14",
      "language": "vi",
      "evidence_type": "official-source",
      "verified": "2026-07-11",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/sg-ai-governance-oversight-human-oversight.json",
      "eal:id": "sg-ai-governance-oversight-human-oversight",
      "title": "Human Oversight",
      "content": "Human-in-the-loop: Appropriate level of human involvement based on risk and impact Decision models: Three models: human-in-the-loop, human-on-the-loop, human-out-of-the-loop Risk-proportionate: Level of oversight proportionate to risk of AI application Agentic AI oversight: 2026 update adds guidance for autonomous agent monitoring and intervention",
      "created_by": [
        "https://everyailaw.com/term/sg-ai-governance-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "sg"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2019-01-23",
      "source": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
      "source_locator": "Section 2: Decision-Making Models",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/sg-ai-governance-explainability.json",
      "eal:id": "sg-ai-governance-explainability",
      "title": "Explainability",
      "content": "Explainable AI: Provide explanations of AI decisions appropriate to the audience Transparency: Disclose use of AI in decision-making to affected individuals Stakeholder communication: Proactive communication about AI use, capabilities, and limitations",
      "created_by": [
        "https://everyailaw.com/term/sg-ai-governance-explainability.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "sg"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/explainability.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2019-01-23",
      "source": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
      "source_locator": "Section 3: Operations Management",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "explainability",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "explainability",
        "interpretability",
        "right to explanation",
        "algorithmic explanation"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/sg-ai-governance-risk-risk-assessment.json",
      "eal:id": "sg-ai-governance-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Internal governance: Establish AI governance structures and accountability Risk management: Lifecycle risk management from design through deployment and monitoring Third-party oversight: Assess and manage risks from AI vendor and third-party systems Agentic AI risks: 2026 update covers system design, deployment safeguards, monitoring, and end-user responsibility",
      "created_by": [
        "https://everyailaw.com/term/sg-ai-governance-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "sg"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2019-01-23",
      "source": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
      "source_locator": "Section 1: Internal Governance, Section 4: Stakeholder Interaction",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/jp-ai-promotion-act-transparency.json",
      "eal:id": "jp-ai-promotion-act-transparency",
      "title": "Transparency & Disclosure",
      "content": "Transparency principle: AI development and use must ensure transparency Fairness and safety: Core principles of fairness and safety in AI activities Cooperation with government: Business operators expected to cooperate with government safety measures International norms: Must contribute to international AI governance norms Extraterritorial scope: Applies to foreign operators targeting Japanese businesses or citizens",
      "created_by": [
        "https://everyailaw.com/term/jp-ai-promotion-act-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "jp"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-09-01",
      "source": "https://www.cas.go.jp/jp/houan/211.html",
      "source_locator": "Art. 7 (活用事業者の責務 — duty of AI-utilising businesses to cooperate with national/local government measures)",
      "language": "ja",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/jp-ai-promotion-act-risk-risk-assessment.json",
      "eal:id": "jp-ai-promotion-act-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "AI Basic Plan: Government must formulate national AI policy plan Guidelines development: Guidelines aligned with international norms for appropriateness Risk mitigation: Promote measures to mitigate AI-related risks AI Strategy Headquarters: Chaired by Prime Minister with all Cabinet ministers",
      "created_by": [
        "https://everyailaw.com/term/jp-ai-promotion-act-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "jp"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-09-01",
      "source": "https://www.cas.go.jp/jp/houan/211.html",
      "source_locator": "Art. 16 (government measures on AI risks, incl. analysis of improper-use/rights-infringement cases, guidance and advice); Art. 18 (formulation of the AI Basic Plan / 人工知能基本計画)",
      "language": "ja",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/au-privacy-act-adm-transparency.json",
      "eal:id": "au-privacy-act-adm-transparency",
      "title": "Transparency & Disclosure",
      "content": "Privacy policy disclosure: Must disclose kinds of personal information used in ADM Decision type disclosure: Must describe kinds of decisions made solely or substantially by automated systems Kinds-of-data/decisions disclosure: Privacy policy must describe, in clear terms, the kinds of personal information used in ADM and the kinds of decisions made or substantially assisted by ADM (APP 1.7-1.9) — not a causal or plain-language explanation of how the AI reaches a decision Influential factors (practitioner best-practice, not statutory): Some practitioner guidance recommends disclosing factors that most significantly influence ADM outcomes as a best practice; this is not a requirement under the text of APP 1.7-1.9 Substantial role test: Applies even when human reviews if AI is essential part of the process",
      "created_by": [
        "https://everyailaw.com/term/au-privacy-act-adm-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "au"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2026-12-10",
      "source": "https://www.legislation.gov.au/C2004A03712/latest/text",
      "source_locator": "APP 1.7, APP 1.8, APP 1.9",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/au-privacy-act-adm-data-governance.json",
      "eal:id": "au-privacy-act-adm-data-governance",
      "title": "Data Governance",
      "content": "Data minimisation: Collection of personal information must be reasonably necessary for the specific function or activity (APP 3) No speculative collection: Cannot collect personal data for potential future AI use without a justified purpose at time of collection Primary purpose limitation: AI systems may only use personal data for the purpose for which it was collected, or a directly related secondary purpose (APP 6)",
      "created_by": [
        "https://everyailaw.com/term/au-privacy-act-adm-data-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "au"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "1988-12-21",
      "source": "https://www.legislation.gov.au/C2004A03712/latest/text",
      "source_locator": "APP 3, APP 6",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/au-privacy-act-adm-risk-risk-assessment.json",
      "eal:id": "au-privacy-act-adm-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "PIA as reasonable step: OAIC treats PIAs as a \"reasonable step\" under APP 1 for high-risk AI deployments; absence is evidence of non-compliance for high-risk processing Third-party accountability: Remain responsible under APP 11 for personal data shared with external AI platforms; due diligence on vendors is part of APP 1 compliance Children's Online Privacy Code: PIAs required for child-facing AI services once the Code is registered (by 10 December 2026); this is Code-based, not a standalone Privacy Act obligation",
      "created_by": [
        "https://everyailaw.com/term/au-privacy-act-adm-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "au"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "1988-12-21",
      "source": "https://www.legislation.gov.au/C2004A03712/latest/text",
      "source_locator": "APP 1 (OAIC guidance)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/tw-ai-basic-act-risk-risk-assessment.json",
      "eal:id": "tw-ai-basic-act-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk taxonomy: The Ministry of Digital Affairs must promote an AI risk taxonomy and assessment framework interoperable with international standards, and assist sectoral authorities in establishing risk-based management regulations (Article 16(1)) Sectoral rulemaking: Sectoral competent authorities must establish risk-based management regulations following that taxonomy and assist their industries in formulating guidelines and codes of conduct (Article 16(2)) High-risk liability: For high-risk AI applications, the government must clarify liability attribution and conditions and establish relief, compensation, or insurance mechanisms; this does not reach pre-application R&D unless tested in a real-world environment or used to provide products or services (Article 17) Conforming legal review: Within two years of the effective date, the government must complete the enactment, amendment, or repeal of non-conforming laws, regulations, and administrative measures (Article 18) Government use assessment: When using AI to perform duties or provide services, the government must conduct risk assessments, plan response measures, and establish usage guidelines or internal control mechanisms (Article 19) Data protection by design: Sectoral authorities, consulting the personal data protection authority, must avoid unnecessary collection, processing, or use of personal data in AI R&D and application and promote data protection by design and by default (Article 14)",
      "created_by": [
        "https://everyailaw.com/term/tw-ai-basic-act-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/government"
      ],
      "applicability": [
        "scope:Government bodies. The Ministry of Digital Affairs must promote an internationally interoperable AI risk taxonomy and assessment framework (Art. 16(1)); sectoral competent authorities must then establish risk-based management regulations and assist their industries in producing guidelines and codes of conduct (Art. 16(2)); the government must conduct risk assessments before using AI to perform duties or provide services (Art. 19). The Act imposes no direct compliance duty on private-sector developers or deployers — obligations reach industry only once a sectoral regulator issues rules under Article 16(2)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "tw"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-14",
      "source": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=H0160093",
      "source_locator": "Articles 16, 17, 18, 19",
      "source_citation": "人工智慧基本法 (Artificial Intelligence Basic Act), 20 articles",
      "language": "zh",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/br-ai-bill-risk-risk-assessment.json",
      "eal:id": "br-ai-bill-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk classification: AI systems classified by risk level: excessive (Art. 13), high (Art. 14), and general Preliminary assessment: Self-classification before market introduction is optional — Art. 12 makes it a good-practice measure (\"poderá realizar\") that earns favourable treatment, not a precondition; a sector authority may simplify or waive it, and the competent authority may order reclassification or require an algorithmic impact assessment (Art. 12 § 4) Prohibited practices: Art. 13 bans systems that induce harmful behaviour, exploit vulnerabilities, profile people to predict criminality or recidivism, or facilitate child sexual abuse material; plus public-authority social scoring, autonomous weapons systems, and real-time remote biometric identification in public spaces (with judicially authorised exceptions) High-risk categories: Art. 14 lists twelve: critical-infrastructure safety devices; student admission selection and evaluations determining academic progress or monitoring; recruitment and employment decisions; access to essential public and private services; triage of emergency service calls; administration of justice; autonomous vehicles in public spaces; health diagnostics and procedures; analytical study of crimes; investigative credibility assessment and profiling; biometric emotion recognition; immigration and border control Algorithmic impact assessment: Mandatory for high-risk systems (Art. 25), performed before placing the system on the market (Art. 26); conclusions are public, subject to trade-secret protection (Art. 28)",
      "created_by": [
        "https://everyailaw.com/term/br-ai-bill-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "br"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "proposed",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www25.senado.leg.br/web/atividade/materias/-/materia/157233",
      "source_locator": "Articles 12-17, 25-28",
      "language": "pt",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/br-ai-bill-transparency.json",
      "eal:id": "br-ai-bill-transparency",
      "title": "Transparency & Disclosure",
      "content": "Disclosure of AI interaction: Art. 5(I) gives every affected person, at any risk level, the right to accessible free information that an interaction is automated, conveyed with standardised icons or symbols (Art. 5 § 1); cybersecurity and cyberdefence systems are excepted Right to explanation: Art. 6(I) grants an explanation of a high-risk system's decision, recommendation, or prediction, subject to trade and industrial secrecy (Art. 6 § 1) Explanation procedure: Art. 7 requires the explanation to be free, in plain accessible language, within a reasonable period; the competent authority sets deadlines and a simplified procedure scaled to system complexity and agent size Documentation: Art. 18 requires developers and deployers of high-risk systems to keep lifecycle documentation and to use tools that allow accuracy and robustness to be assessed Procedures for exercising rights: Art. 9 requires high-risk agents to state, clearly and accessibly, how the Chapter II rights are exercised Synthetic content marking: Art. 19 requires an identifier in AI-generated synthetic content for authenticity and provenance verification; artistic and entertainment works may signal via credits or metadata (Art. 19 § 3)",
      "created_by": [
        "https://everyailaw.com/term/br-ai-bill-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "br"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "proposed",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www25.senado.leg.br/web/atividade/materias/-/materia/157233",
      "source_locator": "Articles 5-7, 9, 18-19",
      "language": "pt",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/br-ai-bill-oversight-human-oversight.json",
      "eal:id": "br-ai-bill-oversight-human-oversight",
      "title": "Human Oversight",
      "content": "Human review: Art. 6(III) gives a person affected by a high-risk system the right to human review of the decision, weighed against context, risk, and the state of the art Right to contest: Art. 6(II) gives the right to contest and request review of a decision, recommendation, or prediction Human supervision: Art. 8 requires human supervision of high-risk systems that lets supervisors understand, interpret, decide, and intervene; not required where implementation is provably impossible or disproportionate, in which case effective alternative measures apply Procedures for exercising rights: Art. 9 requires agents to state how the rights are exercised; Art. 10 has the competent authority issue general guidelines with the SIA sector authorities Enforcement avenues: Art. 11 allows the rights to be asserted before the competent administrative body or in court, individually or collectively",
      "created_by": [
        "https://everyailaw.com/term/br-ai-bill-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "br"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "proposed",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www25.senado.leg.br/web/atividade/materias/-/materia/157233",
      "source_locator": "Articles 6, 8-11",
      "language": "pt",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oecd-ai-principles-transparency.json",
      "eal:id": "oecd-ai-principles-transparency",
      "title": "Transparency & Disclosure",
      "content": "Transparency commitment: AI actors should commit to transparency and responsible disclosure Meaningful information: Provide information appropriate to the context to foster understanding Explainability: Enable people affected by AI systems to understand and challenge outcomes Awareness of AI interaction: People should be able to know when they are interacting with AI",
      "created_by": [
        "https://everyailaw.com/term/oecd-ai-principles-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2019-05-22",
      "source": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "source_locator": "Principle 1.3",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oecd-ai-principles-fairness-bias-prevention.json",
      "eal:id": "oecd-ai-principles-fairness-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Human rights respect: AI actors should respect rule of law, human rights, and democratic values Fairness: Ensure AI does not produce unjust or discriminatory outcomes Privacy and data protection: Respect privacy rights throughout the AI lifecycle Non-discrimination: AI should not create or reinforce unfair bias",
      "created_by": [
        "https://everyailaw.com/term/oecd-ai-principles-fairness.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2019-05-22",
      "source": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "source_locator": "Principle 1.2",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oecd-ai-principles-risk-risk-assessment.json",
      "eal:id": "oecd-ai-principles-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk management: AI systems should not pose unreasonable risks; manage risks throughout lifecycle Robustness: Ensure AI systems function as intended under normal and adversarial conditions Security: Address cybersecurity risks in AI systems Traceability: Enable traceability of AI system outcomes to data and processes",
      "created_by": [
        "https://everyailaw.com/term/oecd-ai-principles-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2019-05-22",
      "source": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "source_locator": "Principle 1.4",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/oecd-ai-principles-accountability-human-oversight.json",
      "eal:id": "oecd-ai-principles-accountability-human-oversight",
      "title": "Human Oversight",
      "content": "Accountability: AI actors should be accountable for proper functioning of AI systems Role-based responsibility: Accountability proportionate to role, context, and state of the art Redress mechanisms: Enable challenge and redress for AI-driven outcomes",
      "created_by": [
        "https://everyailaw.com/term/oecd-ai-principles-accountability.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2019-05-22",
      "source": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "source_locator": "Principle 1.5",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iso-42001-risk-risk-assessment.json",
      "eal:id": "iso-42001-risk-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk assessment: Establish processes to identify and assess AI-related risks Risk treatment: Implement controls to treat identified risks Objectives: Set measurable AI management objectives Leadership commitment: Top management must demonstrate commitment to the AI management system",
      "created_by": [
        "https://everyailaw.com/term/iso-42001-risk.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-12-18",
      "source": "https://www.iso.org/standard/81230.html",
      "source_locator": "Clauses 6-8",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iso-42001-data-governance.json",
      "eal:id": "iso-42001-data-governance",
      "title": "Data Governance",
      "content": "Data quality: Establish processes for ensuring AI training and operational data quality Data provenance: Document data sources and lineage Data lifecycle: Manage data throughout the AI system lifecycle",
      "created_by": [
        "https://everyailaw.com/term/iso-42001-data-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-12-18",
      "source": "https://www.iso.org/standard/81230.html",
      "source_locator": "Clause 6, Annex B",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iso-42001-record-keeping.json",
      "eal:id": "iso-42001-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Documented information: Maintain documented information required by the AI management system Performance evaluation: Monitor, measure, analyze, and evaluate AI system performance Internal audit: Conduct internal audits at planned intervals Management review: Top management must review the AI management system at planned intervals",
      "created_by": [
        "https://everyailaw.com/term/iso-42001-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-12-18",
      "source": "https://www.iso.org/standard/81230.html",
      "source_locator": "Clauses 7.5, 9",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/g7-hiroshima-risk-management-risk-assessment.json",
      "eal:id": "g7-hiroshima-risk-management-risk-assessment",
      "title": "Risk Assessment",
      "content": "Lifecycle risk identification: Identify, evaluate, and mitigate risks prior to and throughout development and deployment Pre-deployment assessment: Conduct risk assessments before release of significant new versions Proportionate controls: Apply measures commensurate to the risk level identified Ongoing monitoring: Continuously assess risks as systems evolve and contexts of use change",
      "created_by": [
        "https://everyailaw.com/term/g7-hiroshima-risk-management.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "g7"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-10-30",
      "source": "https://www.mofa.go.jp/files/100573473.pdf",
      "source_locator": "Action 1",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/g7-hiroshima-incident-management-incident-reporting.json",
      "eal:id": "g7-hiroshima-incident-management-incident-reporting",
      "title": "Incident Reporting",
      "content": "Vulnerability identification: Identify and mitigate security vulnerabilities after deployment Incident response: Address AI incidents promptly; maintain response processes Misuse pattern monitoring: Monitor for patterns of misuse and take corrective action Post-market surveillance: Treat post-deployment oversight as an ongoing obligation",
      "created_by": [
        "https://everyailaw.com/term/g7-hiroshima-incident-management.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "g7"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-10-30",
      "source": "https://www.mofa.go.jp/files/100573473.pdf",
      "source_locator": "Action 2",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/g7-hiroshima-transparency.json",
      "eal:id": "g7-hiroshima-transparency",
      "title": "Transparency & Disclosure",
      "content": "Transparency reports: Publish meaningful transparency reports for all significant new releases of advanced AI Safety evaluation disclosure: Include details of safety, security, and societal risk evaluations Human rights risk disclosure: Address potential impacts on human rights in reporting Privacy policy disclosure: Disclose and keep current privacy policies covering personal data, user prompts, and outputs AI interaction labeling: Implement labeling or disclaimers so users know they are interacting with AI Information sharing: Responsibly share evaluation reports, security risks, dangerous capabilities, and circumvention attempts across the sector",
      "created_by": [
        "https://everyailaw.com/term/g7-hiroshima-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "g7"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-10-30",
      "source": "https://www.mofa.go.jp/files/100573473.pdf",
      "source_locator": "Actions 3–4",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/g7-hiroshima-governance-human-oversight.json",
      "eal:id": "g7-hiroshima-governance-human-oversight",
      "title": "Human Oversight",
      "content": "AI governance policies: Establish and disclose internal AI governance policies Accountability structures: Create organizational mechanisms to implement governance according to a risk-based approach Lifecycle accountability: Maintain accountability processes to evaluate and mitigate risks throughout the AI lifecycle Self-assessment: Conduct self-assessments against stated policies and commitments",
      "created_by": [
        "https://everyailaw.com/term/g7-hiroshima-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "g7"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-10-30",
      "source": "https://www.mofa.go.jp/files/100573473.pdf",
      "source_locator": "Action 5",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/g7-hiroshima-content-auth-record-keeping.json",
      "eal:id": "g7-hiroshima-content-auth-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Content authentication: Develop and deploy reliable content authentication mechanisms where technically feasible Provenance mechanisms: Implement provenance tracking to trace origin of AI-generated content Watermarking: Apply watermarking or equivalent techniques to enable identification of AI-generated content Technical documentation: Maintain technical documentation supporting content authentication capabilities",
      "created_by": [
        "https://everyailaw.com/term/g7-hiroshima-content-auth.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "g7"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-10-30",
      "source": "https://www.mofa.go.jp/files/100573473.pdf",
      "source_locator": "Action 7",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/g7-hiroshima-security-risk-assessment.json",
      "eal:id": "g7-hiroshima-security-risk-assessment",
      "title": "Risk Assessment",
      "content": "Physical security: Invest in physical security controls across the AI lifecycle Cybersecurity controls: Implement cybersecurity controls including protection of model weights and algorithms Insider threat safeguards: Establish controls against insider threats targeting AI systems Infrastructure security: Secure servers, datasets, and computational infrastructure",
      "created_by": [
        "https://everyailaw.com/term/g7-hiroshima-security.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "g7"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-10-30",
      "source": "https://www.mofa.go.jp/files/100573473.pdf",
      "source_locator": "Action 6",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/coe-cets-225-transparency.json",
      "eal:id": "coe-cets-225-transparency",
      "title": "Transparency & Disclosure",
      "content": "Transparency and oversight: Art. 8 requires each Party to adopt or maintain adequate transparency and oversight requirements across the AI lifecycle, tailored to specific contexts and risks Identification of AI-generated content: Art. 8 expressly extends those requirements to the identification of content generated by AI systems Human-vs-AI notification: Art. 15(2) — each Party \"shall seek to ensure\", as appropriate for the context, that persons interacting with AI systems are notified they are interacting with such systems rather than with a human. A best-efforts obligation, weaker than the rest of Art. 15",
      "created_by": [
        "https://everyailaw.com/term/coe-cets-225-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "coe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
      "source_locator": "Articles 8, 15(2)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ],
      "eal:effective_text": "Pending entry into force"
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/coe-cets-225-risk-assessment.json",
      "eal:id": "coe-cets-225-risk-assessment",
      "title": "Risk Assessment",
      "content": "Lifecycle risk identification: Identify, assess, prevent, and mitigate risks to human rights, democracy, and rule of law across the AI lifecycle Proportionality: Measures must be proportionate to the severity and probability of potential impacts Graduated approach: Risk management must be differentiated based on context and intended use Pre-deployment testing: Art. 16(2)(g) requires testing before first use and after significant modification only \"where appropriate\" Iterative monitoring: Risk assessment must be applied continuously throughout the AI lifecycle Moratoria assessment: Art. 16(4) requires States to assess the need for a moratorium, ban, or other measures for uses they consider incompatible with human rights, democracy, or the rule of law",
      "created_by": [
        "https://everyailaw.com/term/coe-cets-225-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "coe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
      "source_locator": "Article 16",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ],
      "eal:effective_text": "Pending entry into force"
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/coe-cets-225-record-keeping.json",
      "eal:id": "coe-cets-225-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Risk documentation: Document risks, actual and potential impacts, and risk management approach throughout the AI lifecycle Contestability documentation: Maintain documentation that enables affected persons to challenge AI system outputs Procedural records: Keep records sufficient to support fair procedures and appeal rights for affected persons",
      "created_by": [
        "https://everyailaw.com/term/coe-cets-225-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "coe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
      "source_locator": "Articles 14, 15, 16",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ],
      "eal:effective_text": "Pending entry into force"
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/coe-cets-225-human-oversight.json",
      "eal:id": "coe-cets-225-human-oversight",
      "title": "Human Oversight",
      "content": "Access to redress: Ensure effective access to remedies for persons adversely affected by AI system decisions Contestability: Enable persons to contest AI-driven outcomes through fair mechanisms Notification of affected persons: Notify individuals subject to AI decisions that affect their rights Fair procedures: Ensure fair procedural safeguards, including meaningful appeal rights",
      "created_by": [
        "https://everyailaw.com/term/coe-cets-225-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "coe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
      "source_locator": "Articles 14, 15",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ],
      "eal:effective_text": "Pending entry into force"
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/coe-cets-225-bias-prevention.json",
      "eal:id": "coe-cets-225-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Non-discrimination principle: Art. 10(1) requires measures ensuring AI lifecycle activities respect equality, including gender equality, and the prohibition of discrimination under applicable international and domestic law Equality risk assessment: Risk management under Article 16 must consider equality and non-discrimination impacts Overcoming inequalities: Art. 10(2) commits Parties to measures aimed at overcoming inequalities to achieve fair, just, and equitable outcomes Non-discriminatory implementation: Art. 17 requires the Convention's provisions to be implemented without discrimination on any ground",
      "created_by": [
        "https://everyailaw.com/term/coe-cets-225-bias-prevention.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "coe"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "source": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
      "source_locator": "Articles 10, 16, 17",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ],
      "eal:effective_text": "Pending entry into force"
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-gpai-cop-transparency.json",
      "eal:id": "eu-gpai-cop-transparency",
      "title": "Transparency & Disclosure",
      "content": "Model Documentation Form: Draft and maintain a comprehensive Model Documentation Form covering technical specifications, training data characteristics, computational resources, and energy consumption Downstream disclosure: Proactively provide documentation to downstream providers integrating the GPAI model into AI systems Authority disclosure: Make documentation available on request to the European AI Office and national competent authorities Contact publication: Publicly disclose contact information (e.g., website) for documentation requests GPAI Template: Complete and publicly disclose a mandatory GPAI Template with training data details",
      "created_by": [
        "https://everyailaw.com/term/eu-gpai-cop-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2025-08-02",
      "source": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
      "source_locator": "Transparency Chapter; Article 53(1)(a)-(b)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-gpai-cop-data-governance.json",
      "eal:id": "eu-gpai-cop-data-governance",
      "title": "Data Governance",
      "content": "Copyright compliance policy: Implement and maintain a policy for compliance with EU copyright law throughout the training data pipeline Robots.txt compliance: Honor robots.txt opt-out protocols when crawling data for training Infringing output prevention: Establish mechanisms to prevent generation of copyright-infringing outputs Complaint mechanism: Create a complaint mechanism for rights holders regarding copyright infringements Training data disclosure: Publicly disclose a summary of training data used, including data sources and characteristics",
      "created_by": [
        "https://everyailaw.com/term/eu-gpai-cop-data-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2025-08-02",
      "source": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
      "source_locator": "Copyright Chapter; Article 53(1)(c)-(d)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-gpai-cop-record-keeping.json",
      "eal:id": "eu-gpai-cop-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Model Documentation Form maintenance: Keep the Model Documentation Form current and updated as the model evolves Training records: Maintain records of training data characteristics, sources, and processing Compute and energy records: Document computational resources and energy consumption used in training Confidential disclosure: Provide documentation to AI Office under confidentiality protections when requested",
      "created_by": [
        "https://everyailaw.com/term/eu-gpai-cop-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2025-08-02",
      "source": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
      "source_locator": "Transparency Chapter; Article 53; Annexes XI–XII",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/eu-gpai-cop-risk-assessment.json",
      "eal:id": "eu-gpai-cop-risk-assessment",
      "title": "Risk Assessment",
      "content": "Systemic risk assessment: Assess and mitigate systemic risks arising from the GPAI model, including risks to health, safety, fundamental rights, society, and democracy Adversarial testing: Conduct adversarial testing and red-teaming to identify dangerous capabilities Cybersecurity measures: Implement cybersecurity controls appropriate to the model's risk level Safety practices: Apply state-of-the-art safety practices for high-capability model development and deployment Ongoing monitoring: Continuously monitor for emerging systemic risks post-deployment",
      "created_by": [
        "https://everyailaw.com/term/eu-gpai-cop-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "eu"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2025-08-02",
      "source": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
      "source_locator": "Safety and Security Chapter; Article 55",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iso-23894-risk-assessment.json",
      "eal:id": "iso-23894-risk-assessment",
      "title": "Risk Assessment",
      "content": "AI risk principles: Apply AI-specific risk management principles adapted from ISO 31000 Clause 4 Risk identification: Identify AI-specific risk sources including bias, robustness failures, explainability gaps, and misuse Risk assessment: Assess likelihood and consequence of identified AI risks throughout the lifecycle Risk treatment: Select and implement risk treatment options proportionate to identified risks Monitoring and review: Continuously monitor AI risk posture and review risk management effectiveness Recording and reporting: Document risk management activities, decisions, and outcomes Lifecycle mapping: Apply risk management across the full AI system lifecycle per Annex C",
      "created_by": [
        "https://everyailaw.com/term/iso-23894-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2023-02-01",
      "source": "https://www.iso.org/standard/77304.html",
      "source_locator": "Clauses 4–6; Annexes A–C",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iso-38507-human-oversight.json",
      "eal:id": "iso-38507-human-oversight",
      "title": "Human Oversight",
      "content": "Governing body responsibility: Boards and governing bodies must evaluate, direct, and monitor the organisation's use of AI Effective use: Ensure AI is used effectively to fulfil organisational objectives Efficient use: Ensure AI use delivers value proportionate to resources and risks Acceptable use: Ensure AI use complies with applicable laws, regulations, and ethical expectations AI governance framework: Establish governance structures for oversight of AI across the organisation Accountability assignment: Assign clear accountability for AI-related decisions and outcomes at executive level",
      "created_by": [
        "https://everyailaw.com/term/iso-38507-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2022-04-01",
      "source": "https://www.iso.org/standard/56641.html",
      "source_locator": "Clauses 4–6",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/iso-42005-risk-assessment.json",
      "eal:id": "iso-42005-risk-assessment",
      "title": "Risk Assessment",
      "content": "Impact identification: Identify potential impacts of AI systems and their foreseeable applications on individuals, groups, and society Intended and unintended use assessment: Assess intended, unintended, sensitive, restricted uses, and foreseeable misuse scenarios Benefit and harm evaluation: Evaluate both positive and negative impacts throughout the AI lifecycle Stakeholder perspective: Integrate perspectives of affected individuals and groups in the assessment process Documentation: Produce assessment documentation supporting transparency, accountability, and fairness Lifecycle integration: Apply impact assessment from design and development through deployment and post-market monitoring Integration with risk management: Coordinate impact assessment with ISO/IEC 23894 (risk management) and ISO/IEC 42001 (management system)",
      "created_by": [
        "https://everyailaw.com/term/iso-42005-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:providers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "institutional_scope": [
          "oecd"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "not-applicable",
      "enforcement_status": "not-enforceable",
      "effective": "2025-05-01",
      "source": "https://www.iso.org/standard/44545.html",
      "source_locator": "Full standard",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-26",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ai-transparency-act-provenance-transparency.json",
      "eal:id": "california-ai-transparency-act-provenance-transparency",
      "title": "Transparency & Disclosure",
      "content": "Latent disclosure: Include a latent disclosure in AI-generated image, video, or audio content (or any combination) created by the covered provider's GenAI system, permanent or extraordinarily difficult to remove where technically feasible (§ 22757.3(b)) Latent disclosure contents: Where technically feasible and reasonable, convey directly or by link to a permanent website: provider name; GenAI system name and version number; time and date of creation or alteration; a unique identifier (§ 22757.3(b)(1)) Self-detectable and standards-aligned: The latent disclosure must be detectable by the provider's own AI detection tool and consistent with widely accepted industry standards (§ 22757.3(b)(2)-(3)) Manifest disclosure option: Offer the user the option to include a manifest disclosure identifying content as AI-generated — clear, conspicuous, medium-appropriate, understandable to a reasonable person, and permanent or extraordinarily difficult to remove (§ 22757.3(a)) Free AI detection tool: Make an AI detection tool available at no cost that lets a user assess whether image, video, or audio content was created or altered by the provider's GenAI system (§ 22757.2(a)) Tool output limits: The tool must output detected system provenance data and must not output personal provenance data (§ 22757.2(a)(2)-(3)) Tool accessibility: The tool must be publicly accessible (subject to reasonable limits against demonstrable security or integrity risks), accept uploaded content or a URL, and support an API so it can be invoked without visiting the provider's website (§ 22757.2(a)(4)-(6)) Feedback loop: Collect user feedback on the tool's efficacy and incorporate relevant feedback into efforts to improve it (§ 22757.2(b)) Data minimisation: Do not collect or retain personal information from tool users, except opt-in contact details for feedback used only to improve the tool; do not retain submitted content longer than necessary; do not retain personal provenance data from submitted content (§ 22757.2(c)) Licensee contract duty: Contractually require third-party licensees of the GenAI system to maintain its capability to include the latent disclosure (§ 22757.3(c)(1)) 96-hour revocation: On knowledge that a licensee modified the system so it can no longer include the latent disclosure, revoke the license within 96 hours (§ 22757.3(c)(2)); the licensee must then cease using the system (§ 22757.3(c)(3))",
      "created_by": [
        "https://everyailaw.com/term/california-ai-transparency-act-provenance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Covered providers — persons who create, code, or otherwise produce a GenAI system with over 1,000,000 monthly visitors or users that is publicly accessible within California (§ 22757.1(d)); the chapter does not apply to products or services providing exclusively non-user-generated video game, television, streaming, movie, or interactive experiences (§ 22757.5)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-08-02",
      "source": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942",
      "source_locator": "Cal. Bus. & Prof. Code §§ 22757.1-22757.5",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ai-transparency-act-platform-transparency.json",
      "eal:id": "california-ai-transparency-act-platform-transparency",
      "title": "Transparency & Disclosure",
      "content": "Provenance detection: Large online platforms must detect whether content distributed on the platform carries provenance data compliant with widely adopted specifications (§ 22757.3.1) User interface disclosure: Provide a user interface disclosing whether system provenance data is available for the content (§ 22757.3.1) Provenance inspection: Allow users to inspect available system provenance data (§ 22757.3.1) No stripping: Must not strip system provenance data or digital signatures, to the extent technically feasible (§ 22757.3.1) Hosting compliance: GenAI system hosting platforms must not knowingly make available a GenAI system that fails to place the required disclosures (§ 22757.3.2)",
      "created_by": [
        "https://everyailaw.com/term/california-ai-transparency-act-platform.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Large online platforms — public-facing social media, file-sharing, mass messaging platforms, or stand-alone search engines distributing content users did not create, exceeding 2,000,000 unique monthly users over the preceding 12 months, excluding broadband internet access services and telecommunications services (§ 22757.1(h)); and GenAI hosting platforms — websites or applications making GenAI source code or model weights available for download to state residents (§ 22757.1(g))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942",
      "source_locator": "Cal. Bus. & Prof. Code §§ 22757.3.1, 22757.3.2",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ai-transparency-act-capture-device-transparency.json",
      "eal:id": "california-ai-transparency-act-capture-device-transparency",
      "title": "Transparency & Disclosure",
      "content": "User option: Provide the user with the option to include a latent disclosure in captured content (§ 22757.3.3(a)(1)) Disclosure contents: The latent disclosure conveys the capture device manufacturer's name, the device name and version number, and the time and date of the content's creation or alteration (§ 22757.3.3(a)(1)(A)-(C)) Default embedding: Embed latent disclosures in content captured by the device by default (§ 22757.3.3(a)(2)) Feasibility limit: Compliance is required only to the extent technically feasible and compliant with widely adopted specifications adopted by an established standards-setting body (§ 22757.3.3(b))",
      "created_by": [
        "https://everyailaw.com/term/california-ai-transparency-act-capture-device.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Capture device manufacturers, for any capture device first produced for sale in California on or after 2028-01-01; a capture device is any device that records photographs, audio, or video, including cameras, mobile phones with built-in cameras or microphones, and voice recorders (§ 22757.1(b)-(c))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2028-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942",
      "source_locator": "Cal. Bus. & Prof. Code § 22757.3.3",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-02",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nyc-ll144-bias-audit-bias-prevention.json",
      "eal:id": "nyc-ll144-bias-audit-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Bias audit: Employers must conduct independent bias audit of AEDT no more than one year before use Audit publication: Results of most recent bias audit must be publicly available on employer's website Audit methodology: Audit must calculate selection or scoring rates and impact ratios across sex, race/ethnicity, and intersectional categories",
      "created_by": [
        "https://everyailaw.com/term/nyc-ll144-bias-audit.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/employer"
      ],
      "applicability": [
        "scope:employers and employment agencies using AEDTs"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ny"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-07-05",
      "source": "https://legistar.council.nyc.gov/LegislationDetail.aspx?ID=4344524",
      "source_locator": "NYC Admin Code § 20-870 et seq.",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nyc-ll144-candidate-notice-transparency.json",
      "eal:id": "nyc-ll144-candidate-notice-transparency",
      "title": "Transparency & Disclosure",
      "content": "Candidate notification: Notify candidates/employees at least 10 business days before AEDT use Disclosure of qualifications: Disclose job qualifications and characteristics the AEDT will assess Data retention notice: Inform candidates of data collected and retention policy Alternative process: Allow candidates to request alternative selection process or accommodation",
      "created_by": [
        "https://everyailaw.com/term/nyc-ll144-candidate-notice.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/employer"
      ],
      "applicability": [
        "scope:employers and employment agencies using AEDTs"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ny"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2023-07-05",
      "source": "https://legistar.council.nyc.gov/LegislationDetail.aspx?ID=4344524",
      "source_locator": "NYC Admin Code § 20-871",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ads-employment-bias-bias-prevention.json",
      "eal:id": "california-ads-employment-bias-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Non-discrimination: Employers must not use automated-decision systems that discriminate on the basis of protected characteristics Scope of decisions: Covers recruitment, hiring, promotion, renewal, training, discharge, discipline, tenure, and employment terms",
      "created_by": [
        "https://everyailaw.com/term/california-ads-employment-bias.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/employer"
      ],
      "applicability": [
        "scope:employers and other covered entities"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-01",
      "source": "https://calcivilrights.ca.gov/employment/",
      "source_locator": "2 CCR § 11009(f) (discrimination prohibition); Cal. Gov. Code §§ 12935(a), 12940, 12941 (statutory authority)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ads-employment-records-record-keeping.json",
      "eal:id": "california-ads-employment-records-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Records retention: Employers must maintain employment records, including automated-decision system data, for a minimum of four years Complaint preservation: After notice or knowledge of a complaint, respondents must preserve relevant records and files, including automated-decision system data, until the complaint and related proceedings are fully resolved",
      "created_by": [
        "https://everyailaw.com/term/california-ads-employment-records.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/employer"
      ],
      "applicability": [
        "scope:employers and other covered entities"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-01",
      "source": "https://calcivilrights.ca.gov/employment/",
      "source_locator": "2 CCR § 11013(a) (record retention); Cal. Gov. Code §§ 12935(a), 12940, 12941 (statutory authority)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nj-ai-employment-bias-bias-prevention.json",
      "eal:id": "nj-ai-employment-bias-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Disparate impact liability: Employers liable for disparate impact discrimination resulting from use of automated tools and AI in employment Scope: Covers hiring, promotion, termination, compensation, and other employment decisions Vendor responsibility: Employers cannot disclaim liability by relying on third-party AI vendor tools",
      "created_by": [
        "https://everyailaw.com/term/nj-ai-employment-bias.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-nj"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-12-15",
      "source": "https://nj.gov/oag/newsreleases25/2025-0108_DCR-Guidance-on-Algorithmic-Discrimination.pdf",
      "source_locator": "N.J.A.C. 13:16",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-05-15",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-insurance-ai-bias-bias-prevention.json",
      "eal:id": "colorado-insurance-ai-bias-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Non-discrimination: Insurers must not use algorithms or predictive models that unfairly discriminate based on protected characteristics Protected classes: Race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, gender expression Demonstration obligation: Commissioner may require insurers to demonstrate their algorithms do not result in unfair discrimination",
      "created_by": [
        "https://everyailaw.com/term/colorado-insurance-ai-bias.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/insurer"
      ],
      "applicability": [
        "scope:insurers using algorithms or predictive models"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2021-07-06",
      "source": "https://leg.colorado.gov/bills/sb21-169",
      "source_locator": "Co. Rev. Stat. § 10-3-1104.9",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-insurance-ai-governance-risk-assessment.json",
      "eal:id": "colorado-insurance-ai-governance-risk-assessment",
      "title": "Risk Assessment",
      "content": "Governance framework: Insurers must adopt governance framework for algorithms and predictive models Testing for discrimination: Must test algorithms for unfair discrimination based on protected characteristics Regulatory demonstration: Must be able to demonstrate compliance to the Commissioner of Insurance",
      "created_by": [
        "https://everyailaw.com/term/colorado-insurance-ai-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/insurer"
      ],
      "applicability": [
        "scope:insurers using algorithms or predictive models"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2021-07-06",
      "source": "https://leg.colorado.gov/bills/sb21-169",
      "source_locator": "Co. Rev. Stat. § 10-3-1104.9",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ab3030-disclosure-transparency.json",
      "eal:id": "california-ab3030-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "AI disclosure: Health facilities using GenAI for patient clinical communications must include disclaimer indicating AI generation Human contact instructions: Communications must include clear instructions for contacting a human healthcare provider Exemption: Written communications reviewed by a licensed healthcare provider are exempt from disclosure Disclaimer placement: Format-specific: written communications must disclose at the beginning; chat/continuous interactions must disclose throughout; audio must disclose at both start and end; video must disclose throughout (per Medical Board of California GenAI Notification Requirements guidance)",
      "created_by": [
        "https://everyailaw.com/term/california-ab3030-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider"
      ],
      "applicability": [
        "scope:health facilities, clinics, physician's offices, and group practices using GenAI for written or verbal patient clinical communications (excluding purely administrative communications)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB3030",
      "source_locator": "Cal. Health & Safety Code § 1339.75",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/california-ab3030-oversight-human-oversight.json",
      "eal:id": "california-ab3030-oversight-human-oversight",
      "title": "Human Oversight",
      "content": "Provider review exemption: Communications reviewed by a licensed or certified provider before sending are exempt from disclosure. Human accessibility: Patients must always have clear path to contact a human healthcare provider",
      "created_by": [
        "https://everyailaw.com/term/california-ab3030-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider"
      ],
      "applicability": [
        "scope:health facilities, clinics, physician's offices, and group practices using GenAI for written or verbal patient clinical communications (excluding purely administrative communications)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ca"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-01-01",
      "source": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB3030",
      "source_locator": "Cal. Health & Safety Code § 1339.75",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-ai-preemption-task-force-risk-assessment.json",
      "eal:id": "us-eo-ai-preemption-task-force-risk-assessment",
      "title": "Risk Assessment",
      "content": "DOJ Task Force: Attorney General must form AI Litigation Task Force within 30 days to identify and challenge state AI laws inconsistent with federal policy Preemption challenges: Task Force to bring legal challenges against state laws on federal preemption, interstate commerce, and constitutional grounds Legislative recommendations: Agencies must develop recommendations for federal framework preempting conflicting state laws",
      "created_by": [
        "https://everyailaw.com/term/us-eo-ai-preemption-task-force.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/government"
      ],
      "applicability": [
        "scope:government (DOJ); states"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-12-11",
      "source": "https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/",
      "source_locator": "EO §§ 3-4",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-ai-preemption-evaluation-transparency.json",
      "eal:id": "us-eo-ai-preemption-evaluation-transparency",
      "title": "Transparency & Disclosure",
      "content": "State law evaluation: Commerce must evaluate state AI statutes within 90 days and identify \"onerous laws that conflict\" with federal objectives BEAD funding restriction: Commerce to issue policy notice making states with conflicting AI laws ineligible for broadband infrastructure funds FTC preemption statement: FTC Chair to issue policy statement within 90 days on FTC Act preemption of state laws requiring AI output alterations",
      "created_by": [
        "https://everyailaw.com/term/us-eo-ai-preemption-evaluation.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/government"
      ],
      "applicability": [
        "scope:government (Commerce, FTC); states"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-12-11",
      "source": "https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/",
      "source_locator": "EO § 5",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-14319-procurement-transparency.json",
      "eal:id": "us-eo-14319-procurement-transparency",
      "title": "Transparency & Disclosure",
      "content": "Model/data cards: Vendors must provide model, system, and/or data cards detailing capabilities, limitations, risks, and mitigations Training data provenance: Vendors must disclose training data provenance information Acceptable use policy: Vendors must provide acceptable use policy documentation Inappropriate use cases: Vendors must disclose inappropriate use cases End-user resources: Vendors must provide end-user resources and feedback mechanisms",
      "created_by": [
        "https://everyailaw.com/term/us-eo-14319-procurement-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-12-11",
      "source": "https://www.whitehouse.gov/presidential-actions/2025/07/preventing-woke-ai-in-the-federal-government/",
      "source_locator": "EO 14319 § 4; OMB M-26-04",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-14319-data-governance.json",
      "eal:id": "us-eo-14319-data-governance",
      "title": "Data Governance",
      "content": "Data provenance: Training data sources and provenance must be documented and disclosed to procuring agency Risk documentation: Vendors must document risks, limitations, and mitigations for LLM systems Compliance verification: Agencies must have sufficient documentation to assess vendor compliance with Unbiased AI Principles",
      "created_by": [
        "https://everyailaw.com/term/us-eo-14319-data-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-12-11",
      "source": "https://www.whitehouse.gov/presidential-actions/2025/07/preventing-woke-ai-in-the-federal-government/",
      "source_locator": "EO 14319 § 4; OMB M-26-04",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-14319-risk-assessment.json",
      "eal:id": "us-eo-14319-risk-assessment",
      "title": "Risk Assessment",
      "content": "Truth-seeking principle: LLMs must prioritize factual accuracy, historical accuracy, scientific inquiry, and acknowledge uncertainty Ideological neutrality principle: LLMs must avoid unprompted value judgments and ideological biases Compliance procedures: Agencies must adopt procedures within 90 days of OMB guidance to enforce principles Contract terms: New contracts must include compliance terms; existing contracts updated where practicable",
      "created_by": [
        "https://everyailaw.com/term/us-eo-14319-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-07-23",
      "source": "https://www.whitehouse.gov/presidential-actions/2025/07/preventing-woke-ai-in-the-federal-government/",
      "source_locator": "EO 14319 §§ 2-3; OMB M-26-04",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/in-it-amendment-rules-2026-transparency.json",
      "eal:id": "in-it-amendment-rules-2026-transparency",
      "title": "Transparency & Disclosure",
      "content": "Prominent labeling: Synthetically generated information (SGI) must carry prominent, visible labels Permanent metadata: Technical provenance mechanisms (e.g., unique identifiers) must be embedded and preserved Removal prevention: Intermediaries must not allow labels or metadata to be modified, suppressed, or removed Audio disclosure: Audio SGI must carry a prominently prefixed audio disclosure identifying it as synthetically generated Blocking unlawful SGI: Deploy reasonable and appropriate technical measures to prevent users creating or transmitting SGI unlawful under Indian law Court/government-flagged unlawful SGI: Unlawful SGI flagged by court order or authorised government intimation must be removed within 3 hours (Rule 3(1)(d), amended from thirty-six hours) Priority unlawful content: Content under Rule 3(2)(b) (e.g., non-consensual intimate imagery) must be removed within 2 hours of a complaint (amended from twenty-four hours) SSMI user declaration: Significant social media intermediaries must require users to declare SGI, verify the declaration with technical measures, and label confirmed SGI (Rule 4(1A))",
      "created_by": [
        "https://everyailaw.com/term/in-it-amendment-rules-2026-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/intermediary"
      ],
      "applicability": [
        "scope:intermediaries offering SGI-capable resources, SSMIs"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "in"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-02-20",
      "source": "https://egazette.gov.in/WriteReadData/2026/269993.pdf",
      "source_locator": "Rule 3(3) (SGI due diligence, inserted), Rule 4(1A) (SSMI user declaration, inserted); Rule 3(1)(d), Rule 3(2)(b) (takedown timelines amended)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/in-it-amendment-rules-2026-record-keeping.json",
      "eal:id": "in-it-amendment-rules-2026-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Permanent metadata: Provenance metadata (unique identifiers, creation markers) must be embedded permanently Metadata integrity: Intermediaries must ensure metadata is not removed, modified, or suppressed by downstream users or systems",
      "created_by": [
        "https://everyailaw.com/term/in-it-amendment-rules-2026-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/intermediary"
      ],
      "applicability": [
        "scope:intermediaries offering SGI-capable resources"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "in"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-02-20",
      "source": "https://egazette.gov.in/WriteReadData/2026/269993.pdf",
      "source_locator": "Rule 3(3)(a)(ii), Rule 3(3)(b) (inserted)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/in-dpdp-data-governance.json",
      "eal:id": "in-dpdp-data-governance",
      "title": "Data Governance",
      "content": "Lawful basis: Personal data may only be processed for lawful purpose with explicit consent or specified legitimate use (Section 4) Purpose limitation: Data must be used only for the purpose for which consent was given (Section 6) Data accuracy: Data fiduciaries must ensure personal data is accurate and complete for the purpose of processing, including automated decisions affecting data principals (Section 8) Security safeguards: Implement reasonable security measures to prevent data breach (Section 8) Breach notification: Report personal data breaches to Data Protection Board and affected data principals; 72-hour indicative timeline under Rules (Section 8) Data minimization: Process only data necessary for the stated purpose (Section 6) Erasure on withdrawal: Upon consent withdrawal or purpose completion, data must be erased unless retention is legally required (Section 8)",
      "created_by": [
        "https://everyailaw.com/term/in-dpdp-data-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:deployers, providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "in"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-11-14",
      "source": "https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf",
      "source_locator": "Sections 4–9 (Chapter II), Section 12, Section 18",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-27",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/mx-lfpdppp-transparency.json",
      "eal:id": "mx-lfpdppp-transparency",
      "title": "Transparency & Disclosure",
      "content": "Privacy notice contents: Art. 15 requires the notice to state the controller's identity and address, the data processed and which of it is sensitive, the purposes and which require consent, the means offered to limit use or disclosure, the mechanisms for exercising ARCO rights, and how changes to the notice will be communicated Automated processing in scope: Art. 2 Fraction XIX brings processing carried out by automated procedures within \"tratamiento\", so AI-based processing of personal data is covered by the notice duties Delivery of the notice: Arts. 16-17 govern how and when the privacy notice must be made available, including where data is not obtained directly from the data subject",
      "created_by": [
        "https://everyailaw.com/term/mx-lfpdppp-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:deployers, providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "mx"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-03-21",
      "source": "https://diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
      "source_locator": "Articles 14-17 (privacy notice); Article 2 Fraction XIX",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/mx-lfpdppp-human-oversight.json",
      "eal:id": "mx-lfpdppp-human-oversight",
      "title": "Human Oversight",
      "content": "Right to object to ADM: Art. 26(II) gives the data subject a right, at any time and for legitimate cause, to oppose or demand cessation of processing where the data is subject to automated processing producing unwanted legal effects or significantly affecting their interests, rights, or freedoms Evaluation without human intervention: The right is triggered where the processing is intended to evaluate personal aspects without human intervention, in particular professional performance, economic situation, health, sexual preferences, reliability, or behaviour Effect of a valid objection: Where the objection succeeds, the controller must cease the processing; the law places the remedy with the data subject rather than imposing a standing oversight duty on the controller",
      "created_by": [
        "https://everyailaw.com/term/mx-lfpdppp-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "mx"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-03-21",
      "source": "https://diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
      "source_locator": "Article 26(II)",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-08-01",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/qa-qcb-ai-guideline-risk-assessment.json",
      "eal:id": "qa-qcb-ai-guideline-risk-assessment",
      "title": "Risk Assessment",
      "content": "AI strategy: Firms must establish and periodically review an AI strategy aligned with business objectives Governance function: Dedicated AI oversight function with clear accountability; board and senior management responsible for AI outcomes Risk management: Identify, assess, and mitigate AI risks including bias, discrimination, privacy, security, and lack of transparency High-risk categorization: Identify and categorize high-risk AI systems based on guideline criteria; apply stricter scrutiny Pre-approval: QCB approval required before launching any new AI system High-risk pre-approval: Prior QCB approval required for purchasing, licensing, or outsourcing high-risk AI systems Sandbox testing: QCB may require sandbox testing before granting approval for high-risk systems AI register: Maintain an updated register of all AI systems in use Life cycle management: Governance covering development, deployment, data governance, security, and ongoing monitoring",
      "created_by": [
        "https://everyailaw.com/term/qa-qcb-ai-guideline-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:deployers, providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "qa"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2024-09-04",
      "source": "https://www.qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
      "source_locator": "AI Strategy, Governance, Risk Management sections",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/qa-qcb-ai-guideline-transparency.json",
      "eal:id": "qa-qcb-ai-guideline-transparency",
      "title": "Transparency & Disclosure",
      "content": "Annual disclosure: Submit annual AI disclosures to QCB detailing system risks, impact assessments, providers, and operations On-request disclosure: Provide AI system information to QCB upon request Customer notification: Disclose AI involvement to customers when AI systems affect their interactions or decisions High-risk transparency: Heightened disclosure requirements for high-risk AI systems",
      "created_by": [
        "https://everyailaw.com/term/qa-qcb-ai-guideline-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "qa"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2024-09-04",
      "source": "https://www.qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
      "source_locator": "Disclosure and reporting provisions",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/qa-qcb-ai-guideline-human-oversight.json",
      "eal:id": "qa-qcb-ai-guideline-human-oversight",
      "title": "Human Oversight",
      "content": "Human supervision: Mandatory protocols for human supervision of all AI systems Intervention capability: Human intervention capabilities required, especially for high-risk systems Accountability: Board and senior management accountable for AI system outcomes",
      "created_by": [
        "https://everyailaw.com/term/qa-qcb-ai-guideline-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "qa"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2024-09-04",
      "source": "https://www.qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
      "source_locator": "Human oversight and intervention provisions",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/sv-ai-promotion-act-conformity-assessment.json",
      "eal:id": "sv-ai-promotion-act-conformity-assessment",
      "title": "Conformity Assessment",
      "content": "ANIA registration: All entities engaged in AI research, development, or application must register with the Agencia Nacional de Inteligencia Artificial National AI registry: ANIA maintains a national registry of registered AI systems and actors Liability access: Registration required to access statutory liability protections for third-party misuse Ongoing compliance: Registration must be maintained; ANIA sets technical security criteria for registered entities",
      "created_by": [
        "https://everyailaw.com/term/sv-ai-promotion-act-conformity-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/researcher"
      ],
      "applicability": [
        "scope:developers, deployers, researchers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "sv"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/conformity-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-09-02",
      "source": "https://www.asamblea.gob.sv/leyes-y-decretos/view/6137",
      "source_locator": "Arts. on ANIA registration and national registry",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "conformity-assessment",
      "eal:group": "compliance",
      "eal:status": "active",
      "eal:search_terms": [
        "conformity assessment",
        "certification",
        "CE marking",
        "compliance verification",
        "third-party audit"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/sv-ai-promotion-act-risk-assessment.json",
      "eal:id": "sv-ai-promotion-act-risk-assessment",
      "title": "Risk Assessment",
      "content": "Impact assessment: Mandatory impact assessments for high-risk AI systems before deployment High-risk definition: Systems handling sensitive/personal/restricted data or operating in critical sectors (healthcare, finance, public administration) Risk framework: ANIA establishes and maintains the risk-assessment framework balancing innovation and safety Sandbox testing: Controlled testing environments (regulatory sandboxes) available for experimental AI activities",
      "created_by": [
        "https://everyailaw.com/term/sv-ai-promotion-act-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "sv"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-09-02",
      "source": "https://www.asamblea.gob.sv/leyes-y-decretos/view/6137",
      "source_locator": "High-risk AI system provisions",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/sv-ai-promotion-act-transparency.json",
      "eal:id": "sv-ai-promotion-act-transparency",
      "title": "Transparency & Disclosure",
      "content": "Algorithmic transparency: Entities must ensure transparency in AI algorithms Ethical standards: Adherence to ethical standards including non-discrimination in AI development and deployment Data protection compliance: AI systems must comply with El Salvador's data privacy laws Anti-competitive prohibition: Private companies cannot adopt anti-competitive practices limiting AI development, marketing, or implementation",
      "created_by": [
        "https://everyailaw.com/term/sv-ai-promotion-act-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "sv"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-09-02",
      "source": "https://www.asamblea.gob.sv/leyes-y-decretos/view/6137",
      "source_locator": "Transparency and ethical standards provisions",
      "language": "es",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/kz-ai-law-risk-assessment.json",
      "eal:id": "kz-ai-law-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk classification: Owners/holders must classify AI systems by risk degree (minimum, medium, high) based on potential impact on safety, rights, freedoms, and public order Risk identification: Identify and analyse known and foreseeable risks across the AI system lifecycle Risk mitigation: Implement safety and reliability measures commensurate with risk tier Documentation: Maintain tier-specific documentation per lists approved by the Ministry of AI and Digital Development High-risk audits: High-risk AI systems subject to enhanced scrutiny; audits implied via Ministry oversight National AI Platform: High-risk system development and testing must use the state National AI Platform operated by National Information Technologies JSC",
      "created_by": [
        "https://everyailaw.com/term/kz-ai-law-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "kz"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-18",
      "source": "https://cis-legislation.com/document.fwx?rgn=170946",
      "source_locator": "Risk degree classification and management provisions",
      "language": "ru",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/kz-ai-law-transparency.json",
      "eal:id": "kz-ai-law-transparency",
      "title": "Transparency & Disclosure",
      "content": "Synthetic output labeling: All distributed synthetic content (images, text, video) generated by AI must include machine-readable markings and visible/other warnings User notification: Users must be notified in advance of AI use in goods, works, or services before interaction Terms of use: Terms governing AI system use must be provided to users before use",
      "created_by": [
        "https://everyailaw.com/term/kz-ai-law-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "kz"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-18",
      "source": "https://cis-legislation.com/document.fwx?rgn=170946",
      "source_locator": "Transparency and labeling provisions",
      "language": "ru",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/kz-ai-law-bias-prevention.json",
      "eal:id": "kz-ai-law-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Manipulative techniques banned: Prohibited to use AI to exert subconscious influence or exploit user vulnerabilities Social scoring banned: AI-based social scoring of citizens is prohibited Biometric discrimination banned: AI-based discrimination using biometric data is prohibited Emotion detection restricted: Unauthorized emotion detection without consent is prohibited Anti-competitive practices banned: Restricting AI development, marketing, or implementation through anti-competitive AI practices is prohibited",
      "created_by": [
        "https://everyailaw.com/term/kz-ai-law-bias-prevention.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "kz"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-18",
      "source": "https://cis-legislation.com/document.fwx?rgn=170946",
      "source_locator": "Prohibited practices provisions",
      "language": "ru",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/kz-ai-law-record-keeping.json",
      "eal:id": "kz-ai-law-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Tier-specific documentation: Maintain documentation per lists approved by the Ministry of AI and Digital Development; depth scales with risk tier Risk records: Document risk identification, analysis of known and foreseeable risks, and safety/reliability measures taken User support records: Maintain records of user support obligations and terms of use provided Ministry approval: Documentation list formats are approved by the Ministry; owners must comply with current approved lists",
      "created_by": [
        "https://everyailaw.com/term/kz-ai-law-record-keeping.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "kz"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-01-18",
      "source": "https://cis-legislation.com/document.fwx?rgn=170946",
      "source_locator": "Documentation requirements per risk tier",
      "language": "ru",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/it-ai-law-human-oversight.json",
      "eal:id": "it-ai-law-human-oversight",
      "title": "Human Oversight",
      "content": "Physician authority: AI systems cannot replace human clinical judgment or make fully automated clinical decisions; physicians retain ultimate decision-making authority Patient notification: Patients must be informed of AI use, its benefits, and the logic of AI-assisted decision-making before and during care Support role only: AI may support prevention, diagnosis, and treatment but must be positioned as a decision-support tool, not a decision-maker AGENAS platform: National Agency for Regional Health Services (AGENAS) develops a national AI platform to assist medical staff; outputs are non-binding suggestions",
      "created_by": [
        "https://everyailaw.com/term/it-ai-law-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "it"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-10",
      "source": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00152/SG",
      "source_locator": "Art. 7 (uso dell'IA in ambito sanitario e di disabilità); Art. 10 (ulteriori disposizioni sull'uso dell'IA in sanità)",
      "language": "it",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/it-ai-law-transparency.json",
      "eal:id": "it-ai-law-transparency",
      "title": "Transparency & Disclosure",
      "content": "Worker notification: Employers must disclose to workers when AI is used in recruitment, performance evaluation, or other employment processes AI decision logic disclosure: Employers must explain the logic of AI decision-making where AI is involved in employment decisions Minors consent: Children under 14 require verifiable parental consent before using any AI-powered product or service",
      "created_by": [
        "https://everyailaw.com/term/it-ai-law-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "it"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-10",
      "source": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00152/SG",
      "source_locator": "Art. 11 (uso dell'IA in ambito lavorativo — worker information duty, ref. art. 1-bis D.Lgs. 152/1997); Art. 6, comma 4 (accesso dei minori di anni 14 — parental consent)",
      "language": "it",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/it-ai-law-bias-prevention.json",
      "eal:id": "it-ai-law-bias-prevention",
      "title": "Bias & Discrimination Prevention",
      "content": "Non-discrimination: AI systems used in employment must not discriminate; discriminatory AI applications in recruitment or evaluation are prohibited Data protection compliance: Employers must comply with data protection principles to prevent bias in AI employment systems Human oversight in employment: Employers must ensure human oversight of AI-assisted employment decisions",
      "created_by": [
        "https://everyailaw.com/term/it-ai-law-bias-prevention.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "it"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/bias-prevention.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-10",
      "source": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00152/SG",
      "source_locator": "Art. 11 (uso dell'IA in ambito lavorativo — dignità, non-discriminazione, tutela dei diritti dei lavoratori)",
      "language": "it",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "bias-prevention",
      "eal:group": "fairness",
      "eal:status": "active",
      "eal:search_terms": [
        "algorithmic discrimination",
        "bias testing",
        "fairness",
        "disparate impact",
        "anti-discrimination"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/it-ai-law-data-governance.json",
      "eal:id": "it-ai-law-data-governance",
      "title": "Data Governance",
      "content": "Secondary use permitted: Anonymized or pseudonymized health data may be used for AI research without new patient consent, serving significant public interest Garante notification: 30-day advance notification to the Italian Data Protection Authority (Garante) required before commencing AI research using health data GDPR compliance: All health data processing for AI research must comply with GDPR requirements Anonymization standards: Data must be properly anonymized or pseudonymized before secondary use for AI research",
      "created_by": [
        "https://everyailaw.com/term/it-ai-law-data-governance.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:developers, deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "it"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-10",
      "source": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00152/SG",
      "source_locator": "Art. 8 (ricerca e sperimentazione scientifica in ambito sanitario — rilevante interesse pubblico; Garante 30-day prior notification, comma 5); Art. 9 (trattamento di dati personali mediante sistemi di IA)",
      "language": "it",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/mt-ai-regulations-risk-assessment.json",
      "eal:id": "mt-ai-regulations-risk-assessment",
      "title": "Risk Assessment",
      "content": "Early classification: Deployers must proactively classify AI systems to determine if they fall under Annex III high-risk categories MDIA notification: Market surveillance notifications to MDIA for AI systems placed on the Maltese market Sandbox participation: MDIA operates a national AI regulatory sandbox for testing and development Notified body designation: MDIA serves as notifying authority for conformity assessment bodies",
      "created_by": [
        "https://everyailaw.com/term/mt-ai-regulations-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:deployers, providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "mt"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-10",
      "source": "https://legislation.mt/eli/ln/2025/226/eng",
      "source_locator": "S.L. 591.05 (LN 226/2025), Artificial Intelligence Regulations under the Malta Digital Innovation Authority Act (Cap. 591) — MDIA designated market surveillance authority + national single point of contact; risk-based AI classification",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/mt-ai-regulations-human-oversight.json",
      "eal:id": "mt-ai-regulations-human-oversight",
      "title": "Human Oversight",
      "content": "IDPC supervision: Information and Data Protection Commissioner supervises high-risk AI systems (Annex III) and prohibited practices High-risk AI registry: IDPC maintains a registry of high-risk AI systems Biometric authorization: Real-time remote biometric identification in public spaces for law enforcement requires prior Magistrate authorization IDPC notification: Law enforcement must notify IDPC of biometric identification use (excluding sensitive data) Corrective powers: IDPC can issue warnings, impose corrective measures, and order withdrawal of non-compliant AI systems",
      "created_by": [
        "https://everyailaw.com/term/mt-ai-regulations-human-oversight.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "mt"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2025-10-10",
      "source": "https://legislation.mt/eli/ln/2025/226/eng",
      "source_locator": "S.L. 586.14 (LN 227/2025) under the Data Protection Act (Cap. 586) — reg. 3 (IDPC designation + high-risk AI registry), reg. 5 (real-time remote biometric ID), reg. 6 (post-remote biometric ID; Magistrate authorisation, 48-hour rule), reg. 7 (IDPC as notified body)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-07-10",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/au-nsw-digital-work-systems-risk-assessment.json",
      "eal:id": "au-nsw-digital-work-systems-risk-assessment",
      "title": "Risk Assessment",
      "content": "Risk identification: PCBUs must identify WHS risks arising from digital work systems (algorithms, AI, automation, online platforms) Risk assessment: Assess specific risks including excessive/unreasonable workloads, performance metrics, monitoring/surveillance, and discriminatory practices Risk management: Ensure, so far as reasonably practicable, that workers' health and safety is not put at risk by digital work systems Scope of digital work systems: Defined as any algorithm, AI, automation, or online platform used for work allocation, monitoring, performance management, or similar workplace functions",
      "created_by": [
        "https://everyailaw.com/term/au-nsw-digital-work-systems-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "au-nsw"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-02-18",
      "source": "https://legislation.nsw.gov.au/view/html/inforce/current/act-2026-005",
      "source_locator": "Amendments to WHS Act 2011 — digital work system risk provisions",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-03-28",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/au-nsw-digital-work-systems-transparency.json",
      "eal:id": "au-nsw-digital-work-systems-transparency",
      "title": "Transparency & Disclosure",
      "content": "Inspection access: WHS entry permit holders may access and inspect a digital work system relevant to workplace health and safety, in relation to a suspected contravention — not an unconditional/blanket inspection right Reasonable assistance: PCBUs must provide reasonable assistance to entry permit holders for accessing/inspecting digital systems Notice requirement: 48 hours' notice required before entry permit holder inspection Notice timing: Notice must be given during business hours and not more than 14 days before entry SafeWork guidelines: Access powers subject to SafeWork NSW guidelines (to be issued after public consultation); this provision's commencement is gated on guideline publication + 1 month (see Timeline table), distinct from the Act's general 2026-02-18 effective date",
      "created_by": [
        "https://everyailaw.com/term/au-nsw-digital-work-systems-transparency.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:deployers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "au-nsw"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-02-18",
      "source": "https://legislation.nsw.gov.au/view/html/inforce/current/act-2026-005",
      "source_locator": "Entry permit holder access and inspection provisions",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-30",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-ai-innovation-security-conformity-assessment.json",
      "eal:id": "us-eo-ai-innovation-security-conformity-assessment",
      "title": "Conformity Assessment",
      "content": "Voluntary pre-release access: Participating developers may provide the federal government access to covered frontier models for up to 30 days before planned release Confidentiality protections: Access is subject to confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements Trusted-partner sequencing: Designated covered frontier models receive government evaluation before access is extended to other trusted partners",
      "created_by": [
        "https://everyailaw.com/term/us-eo-ai-innovation-security-conformity-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/conformity-assessment.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2026-06-02",
      "source": "https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/",
      "source_locator": "EO § 3(b)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "conformity-assessment",
      "eal:group": "compliance",
      "eal:status": "active",
      "eal:search_terms": [
        "conformity assessment",
        "certification",
        "CE marking",
        "compliance verification",
        "third-party audit"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-ai-innovation-security-risk-assessment.json",
      "eal:id": "us-eo-ai-innovation-security-risk-assessment",
      "title": "Risk Assessment",
      "content": "Classified benchmarking: Government to develop and maintain a classified process benchmarking the advanced cyber capabilities of AI models Threshold designation: The benchmark sets the threshold at which a model is designated a \"covered frontier model\" Assessment sharing: Capability assessments are shared with AI developers as appropriate",
      "created_by": [
        "https://everyailaw.com/term/us-eo-ai-innovation-security-risk-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2026-06-02",
      "source": "https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/",
      "source_locator": "EO § 3(a)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/us-eo-ai-innovation-security-incident-reporting.json",
      "eal:id": "us-eo-ai-innovation-security-incident-reporting",
      "title": "Incident Reporting",
      "content": "Coordinated scanning: Participants coordinate and deconflict scanning for software vulnerabilities through the clearinghouse Vulnerability validation: Discovered vulnerabilities are discovered and validated via the clearinghouse Remediation coordination: The clearinghouse coordinates and prioritizes remediation and the distribution of vulnerability patches",
      "created_by": [
        "https://everyailaw.com/term/us-eo-ai-innovation-security-incident-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:providers"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "unknown",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2026-06-02",
      "source": "https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/",
      "source_locator": "EO § 2(d)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-06-18",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nebraska-lb525-minor-disclosure-transparency.json",
      "eal:id": "nebraska-lb525-minor-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Disclose artificiality to minor account holders: Clearly and conspicuously disclose to each minor account holder that they are interacting with artificial intelligence (sec. 14(1)) Persistent-disclaimer route: The disclosure may be satisfied by a persistent visible disclaimer (sec. 14(1)(a)) Session-and-cadence route: Alternatively, disclose at the beginning of each session and at least every three hours in a continuous interaction (sec. 14(1)(b)(i)-(ii)) Minor determination standard: A minor is an individual the operator has, based upon the circumstance, actual knowledge or reasonable certainty is younger than eighteen (sec. 13(4))",
      "created_by": [
        "https://everyailaw.com/term/nebraska-lb525-minor-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — any natural person or legal entity that makes available a conversational artificial intelligence service to the public (sec. 13(6)(a)). A conversational AI service is a publicly accessible software application, web interface, or program that primarily simulates human conversation through textual, visual, or aural communication (sec. 13(2)(a)); excluded are developer- and researcher-facing tools, features inside a non-conversational product, narrow-and-discrete-topic outputs, business-facing commercial products, speaker and voice-assistant interfaces, internal business use, and pure customer-service bots (sec. 13(2)(b)(i)-(vii)). Mobile app stores and search engines are not operators merely for providing access (sec. 13(6)(b)). The duty runs to minor account holders — account holders the operator has actual knowledge or reasonable certainty are under 18 (sec. 13(4)-(5))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ne"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
      "source_locator": "2026 Neb. Laws LB 525, sec. 13(1)-(6), sec. 14(1)",
      "source_citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nebraska-lb525-minor-safeguards-risk-assessment.json",
      "eal:id": "nebraska-lb525-minor-safeguards-risk-assessment",
      "title": "Risk Assessment",
      "content": "No variable-ratio engagement rewards: Do not provide a minor account holder with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the service (sec. 14(2)) Prevent sexually explicit output: Institute reasonable measures to prevent the service from producing visual depictions of sexually explicit conduct, generating direct statements that the account holder should engage in sexually explicit conduct, or generating statements that sexually objectify the account holder (sec. 14(3)(a)-(c)) Prevent human-simulation output: Institute reasonable measures to prevent the service from generating statements that would lead a reasonable person to believe they are interacting with a human (sec. 14(4)) Enumerated anthropomorphic outputs: The prevention duty expressly covers explicit claims that the service is sentient or human, statements simulating emotional dependence, statements simulating romantic or sexual innuendos, and role-playing of adult-minor romantic relationships (sec. 14(4)(a)-(d))",
      "created_by": [
        "https://everyailaw.com/term/nebraska-lb525-minor-safeguards.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services (sec. 13(6)(a)) with respect to minor account holders (sec. 13(5)). \"Sexually explicit conduct\" and \"visual depiction\" carry their 18 U.S.C. 2256 meanings (sec. 13(8))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ne"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
      "source_locator": "2026 Neb. Laws LB 525, sec. 13(8), sec. 14(2), sec. 14(3), sec. 14(4)",
      "source_citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nebraska-lb525-parental-controls-data-governance.json",
      "eal:id": "nebraska-lb525-parental-controls-data-governance",
      "title": "Data Governance",
      "content": "Tools for minor account holders: Offer tools for minor account holders to manage their privacy and account settings (sec. 14(5)) Parental tools under thirteen: Where the minor account holder is younger than thirteen, offer those same management tools to the account holder's parents or guardians (sec. 14(5)) Related tools for thirteen and older: Offer related tools to the parents or guardians of minor account holders thirteen years of age and older, as appropriate based on relevant risks (sec. 14(5))",
      "created_by": [
        "https://everyailaw.com/term/nebraska-lb525-parental-controls.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services (sec. 13(6)(a)) with respect to minor account holders — account holders who have or open an account or profile to use the service and whom the operator has actual knowledge or reasonable certainty are under 18 (sec. 13(1), sec. 13(4)-(5)) — and their parents or guardians"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ne"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
      "source_locator": "2026 Neb. Laws LB 525, sec. 13(1), sec. 13(5), sec. 14(5)",
      "source_citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nebraska-lb525-general-disclosure-transparency.json",
      "eal:id": "nebraska-lb525-general-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Conditional artificiality disclosure: If a reasonable person interacting with the service would be misled to believe they are interacting with a human, clearly and conspicuously disclose that the service is artificial intelligence (sec. 15) No professional mental health claims: Do not knowingly and intentionally cause or program the service to make any representation or statement that explicitly indicates the service is designed to provide professional mental or behavioral health care (sec. 17) Scienter standard: The sec. 17 bar reaches only conduct that is both knowing and intentional on the part of the operator (sec. 17)",
      "created_by": [
        "https://everyailaw.com/term/nebraska-lb525-general-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services (sec. 13(6)(a)) as to all users, not only account holders. The disclosure duty is conditional: it applies where a reasonable person interacting with the service would be misled to believe the interaction is with a human (sec. 15)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ne"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
      "source_locator": "2026 Neb. Laws LB 525, sec. 15, sec. 17",
      "source_citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/nebraska-lb525-crisis-protocol-risk-assessment.json",
      "eal:id": "nebraska-lb525-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Adopt a crisis protocol: Adopt a protocol for the conversational AI service to respond to user prompts regarding suicidal ideation or self-harm (sec. 16) Crisis referral: The protocol must include making reasonable efforts to provide a response referring the user to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis services (sec. 16) Non-exhaustive floor: The enumerated referral content is a minimum — the protocol \"includes, but is not limited to\" that element (sec. 16)",
      "created_by": [
        "https://everyailaw.com/term/nebraska-lb525-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators of conversational AI services (sec. 13(6)(a)), as to all users regardless of age or account status (sec. 16)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ne"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "enacted",
      "operative_status": "unknown",
      "enforcement_status": "unknown",
      "effective": "2027-07-01",
      "source": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
      "source_locator": "2026 Neb. Laws LB 525, sec. 16",
      "source_citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-hb26-1263-age-estimation-risk-assessment.json",
      "eal:id": "colorado-hb26-1263-age-estimation-risk-assessment",
      "title": "Risk Assessment",
      "content": "Estimate user age: Use commercially reasonable methods or generally accepted methods to estimate the age of account holders or users (§ 6-1-1708(2)) No willful disregard: Do not willfully disregard clear and convincing information that an account holder or user is a minor (§ 6-1-1708(2)) Estimate is knowledge: The estimated age or age range of a minor account holder or user is considered knowledge of the minor's age for the whole of § 6-1-1708 (§ 6-1-1708(2)) Minor user definition: A minor user is a user the operator has knowledge is a minor by using commercially reasonable or generally accepted age-estimation methods (§ 6-1-1708(1)(c)) Trigger for minor duties: Where the operator knows an account holder or user is a minor, the duties at § 6-1-1708(2)(a)-(h) apply on and after 2027-01-01 (§ 6-1-1708(2))",
      "created_by": [
        "https://everyailaw.com/term/colorado-hb26-1263-age-estimation.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Operators — a person, partnership, corporation, or entity that develops and makes publicly available a conversational AI service, or offers one to a consumer (§ 6-1-1701(15.5)(a)); mobile application stores and search engines are excluded when they merely provide access (§ 6-1-1701(15.5)(b)). A minor is a consumer under eighteen years old (§ 6-1-1701(15.3))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/HB26-1263",
      "source_locator": "C.R.S. § 6-1-1708(1)(c), § 6-1-1708(2) (opening paragraph)",
      "source_citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (2026 Colo. Sess. Laws, HB 26-1263)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-hb26-1263-minor-disclosure-transparency.json",
      "eal:id": "colorado-hb26-1263-minor-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Artificiality disclosure: Clearly and conspicuously disclose to the minor account holder or minor user that they are interacting with artificial intelligence that is artificially generated and not human (§ 6-1-1708(2)(a)) Prompt-responsive delivery: The disclosure must be provided in response to user prompts regarding whether the service is artificially generated and not human (§ 6-1-1708(2)(a)) Screen products: A persistent visible disclaimer for a product with a screen interface (§ 6-1-1708(2)(a)(I)) Screenless products: An intermittent audio disclaimer for a product without a screen interface (§ 6-1-1708(2)(a)(II)) Cadence: Provided at the beginning of each interaction and at least once every three hours in a continuous interaction (§ 6-1-1708(2)(a)(III))",
      "created_by": [
        "https://everyailaw.com/term/colorado-hb26-1263-minor-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Operators that know an account holder or user of a conversational AI service is a minor, i.e. a consumer under eighteen (§ 6-1-1701(15.3), § 6-1-1708(2))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/HB26-1263",
      "source_locator": "C.R.S. § 6-1-1708(2)(a)",
      "source_citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (2026 Colo. Sess. Laws, HB 26-1263)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-hb26-1263-minor-engagement-limits-risk-assessment.json",
      "eal:id": "colorado-hb26-1263-minor-engagement-limits-risk-assessment",
      "title": "Risk Assessment",
      "content": "No variable-interval rewards: Do not provide the minor with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement (§ 6-1-1708(2)(b)) Sexual content controls: Institute technically feasible measures to prevent the service from producing textual, visual, or aural depictions of explicit sexual conduct, producing an intimate digital depiction, generating a statement that the minor should engage in explicit sexual conduct, or engaging in erotic or sexually explicit interactions with the minor (§ 6-1-1708(2)(c)(I)-(IV)) Emotional-dependence controls: Institute reasonable measures to prevent the service from formulating, structuring, or optimizing a response that simulates emotional dependence or isolation from real-world supports (§ 6-1-1708(2)(d)) Named prohibited outputs: Those measures must prevent an explicit claim that the service is human or artificially sentient, a statement that simulates a romantic companionship, and role-playing of an adult-minor romantic relationship (§ 6-1-1708(2)(d)(I)-(III)) Prohibition protocol: Implement a protocol to prohibit the service from engaging in explicit sexual conduct with a minor (§ 6-1-1708(2)(e)) Stop-engagement protocol: Implement a protocol for the service to stop engaging in response to a user prompt regarding explicit sexual conduct with a minor (§ 6-1-1708(2)(f))",
      "created_by": [
        "https://everyailaw.com/term/colorado-hb26-1263-minor-engagement-limits.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Operators that know an account holder or user is a minor (§ 6-1-1708(2)). \"Explicit sexual conduct\" takes its meaning from C.R.S. § 13-21-1502(7) but excludes evidence-based medical information and factual descriptions of reproductive health care (§ 6-1-1701(10.5)); \"intimate digital depiction\" takes its meaning from § 13-21-1502(10) (§ 6-1-1701(12.5))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/HB26-1263",
      "source_locator": "C.R.S. § 6-1-1708(2)(b), (2)(c), (2)(d), (2)(e), (2)(f)",
      "source_citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (2026 Colo. Sess. Laws, HB 26-1263)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-hb26-1263-minor-privacy-tools-data-governance.json",
      "eal:id": "colorado-hb26-1263-minor-privacy-tools-data-governance",
      "title": "Data Governance",
      "content": "Part 13 compliance: Comply with part 13 of article 1 of title 6 regarding protecting the privacy and data of a minor (§ 6-1-1708(2)(g)) Minor privacy and account tools: Offer tools for the minor account holder or minor user to manage their privacy and account settings (§ 6-1-1708(2)(h)(I)) Memory personalization control: Those tools must include the ability to control whether the service retains information from prior interactions or sessions for the purpose of personalizing the content of future interactions (§ 6-1-1708(2)(h)(I)) Training-use control: Those tools must include the ability to control whether the minor's personal data is used for the purposes of training the conversational AI service (§ 6-1-1708(2)(h)(I)) Parent and guardian tools: Offer tools for a parent or guardian of the minor to manage the minor's privacy and account settings (§ 6-1-1708(2)(h)(II))",
      "created_by": [
        "https://everyailaw.com/term/colorado-hb26-1263-minor-privacy-tools.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Operators that know an account holder or user is a minor (§ 6-1-1708(2)), plus their parents or guardians as tool recipients (§ 6-1-1708(2)(h)(II))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/data-governance.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/HB26-1263",
      "source_locator": "C.R.S. § 6-1-1708(2)(g), § 6-1-1708(2)(h)(I)-(II)",
      "source_citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (2026 Colo. Sess. Laws, HB 26-1263)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "data-governance",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "training data",
        "data quality",
        "data management",
        "data provenance"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-hb26-1263-consumer-disclosure-transparency.json",
      "eal:id": "colorado-hb26-1263-consumer-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "Artificiality disclosure: Clearly and conspicuously disclose to a user that the conversational AI service is artificial intelligence (§ 6-1-1708(3)) Daily first-interaction timing: Provide the disclosure at the beginning of a user's first interaction with the service for each day of interaction (§ 6-1-1708(3)(a)) Three-hour or persistent cadence: The disclosure must appear at least once every three hours in a continuous interaction, or appear as a persistent disclosure visible to the user (§ 6-1-1708(3)(b)) Prompt-responsive delivery: The disclosure must be provided in response to user prompts regarding whether the service is artificially generated and not human (§ 6-1-1708(3)(c)) No professional-equivalence claims: Do not use any term, letter, or phrase in advertising, the interface, or outputs stating that output data is provided by, endorsed by, or equivalent to services provided by a licensed health-care professional, a licensed legal professional, or a licensed, certified, or registered mental health professional (§ 6-1-1708(5)(a)-(c)) Dietitian claims: The same bar covers claims of equivalence to a qualified dietitian as described in § 6-1-707(1)(b) (§ 6-1-1708(5)(d)) Savings clauses: Nothing in the section limits constitutional information access, requires disclosure of trade secrets or protected confidential information, or authorizes content moderation inconsistent with the United States Constitution (§ 6-1-1708(7)(a)-(c))",
      "created_by": [
        "https://everyailaw.com/term/colorado-hb26-1263-consumer-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Operators of any conversational AI service, as to every user regardless of age (§ 6-1-1708(3), § 6-1-1708(5))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/HB26-1263",
      "source_locator": "C.R.S. § 6-1-1708(3)(a)-(c), § 6-1-1708(5)(a)-(d)",
      "source_citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (2026 Colo. Sess. Laws, HB 26-1263)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-hb26-1263-crisis-protocol-risk-assessment.json",
      "eal:id": "colorado-hb26-1263-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Crisis protocol: Implement a protocol for the service to respond to a user prompt regarding suicidal ideation or self-harm (§ 6-1-1708(4)) Crisis service referral: The protocol must include user referral to a crisis service provider such as a suicide hotline, a crisis text line, or another appropriate crisis service (§ 6-1-1708(4)) Law enforcement excluded: The referral expressly does not include a law enforcement agency (§ 6-1-1708(4)) Escalation procedures: The protocol must include escalation procedures for repeated or severe crisis indicators (§ 6-1-1708(4)) Self-harm definition: Self-harm means intentional self-injury, with or without the intent to cause death (§ 6-1-1701(16.5))",
      "created_by": [
        "https://everyailaw.com/term/colorado-hb26-1263-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Operators of any conversational AI service, as to every user regardless of age (§ 6-1-1708(4))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-01-01",
      "source": "https://leg.colorado.gov/bills/HB26-1263",
      "source_locator": "C.R.S. § 6-1-1708(4), § 6-1-1701(16.5)",
      "source_citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (2026 Colo. Sess. Laws, HB 26-1263)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/colorado-hb26-1263-annual-reporting-incident-reporting.json",
      "eal:id": "colorado-hb26-1263-annual-reporting-incident-reporting",
      "title": "Incident Reporting",
      "content": "Annual filing: Annually report to the Attorney General's office on and after 2027-07-01 (§ 6-1-1708(6)(a)) Referral count: Report the number of times the operator issued a crisis service provider referral notification in the preceding calendar year (§ 6-1-1708(6)(a)(I)) Detection protocols: Report any protocols implemented to detect, remove, and respond to instances of suicidal ideation or self-harm by a user (§ 6-1-1708(6)(a)(II)) Prevention protocols: Report any protocols implemented to prevent a service response about suicidal ideation or self-harm actions (§ 6-1-1708(6)(a)(III)) Attorney-General-determined metrics: Report any additional metrics necessary to determine the efficacy and reliability of implemented safeguards or detection, removal, and response protocols, as determined by the Attorney General (§ 6-1-1708(6)(a)(IV)) No personal information: The report must not include any identifiers or personal information about a user (§ 6-1-1708(6)(b)) Public posting: The Attorney General's office posts data from the reports on its public website (§ 6-1-1708(6)(c)) Evidence-based measurement: For the purpose of creating the report, the operator must use evidence-based methods for measuring suicidal ideation or self-harm (§ 6-1-1708(6)(d))",
      "created_by": [
        "https://everyailaw.com/term/colorado-hb26-1263-annual-reporting.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Operators of any conversational AI service (§ 6-1-1708(6)(a)); the recipient is the Attorney General's office, which posts the reported data publicly (§ 6-1-1708(6)(c))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-co"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2027-07-01",
      "source": "https://leg.colorado.gov/bills/HB26-1263",
      "source_locator": "C.R.S. § 6-1-1708(6)(a)-(d)",
      "source_citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (2026 Colo. Sess. Laws, HB 26-1263)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/hawaii-sb3001-disclosure-transparency.json",
      "eal:id": "hawaii-sb3001-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "General artificiality notification: Where a reasonable person interacting with the AI companion would be led to believe the person is interacting with a human, issue a clear and conspicuous notification indicating that the AI companion is artificial intelligence and not human (§ (a)) Minor disclosure: Where the operator has actual knowledge or reasonable certainty that a user is a minor, clearly and conspicuously disclose that the user is interacting with artificial intelligence (§ (b)) Persistent disclaimer alternative: The minor disclosure may be satisfied by a persistent visible disclaimer (§ (b)(1)) Session-start and hourly cadence: Otherwise the disclosure must appear both at the beginning of each session and at least once per hour in a continuous AI companion interaction, and the hourly reminder must tell the user to take a break from the chat and that the conversation is artificially generated and not with a human (§ (b)(2)(A)-(B))",
      "created_by": [
        "https://everyailaw.com/term/hawaii-sb3001-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators — persons who develop and make an AI companion available to the public; a mobile application store or search engine that merely provides access is not by itself an operator (§ (i)). An AI companion is a system using artificial intelligence, generative AI, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship by retaining information on prior interactions and user preferences, asking unprompted emotion-based questions beyond a direct response, and sustaining ongoing dialogue on matters personal to the user (§ (i)). The minor cadence in § (b) applies where the operator has actual knowledge or reasonable certainty that the user is under eighteen"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-hi"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-14",
      "source": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
      "source_locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (a), § (b), § (i)",
      "source_citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/hawaii-sb3001-crisis-protocol-risk-assessment.json",
      "eal:id": "hawaii-sb3001-crisis-protocol-risk-assessment",
      "title": "Risk Assessment",
      "content": "Crisis response protocol: Adopt a protocol for the AI companion to respond to user prompts regarding suicidal ideation or self-harm that includes making reasonable efforts to provide a response referring the user to crisis intervention service providers, such as a suicide hotline, crisis text line, or other appropriate crisis services (§ (c)(1)) Evidence-based measurement: Use evidence-based methods for measuring suicidal ideation and the risk of self-harm (§ (c)(2)) No professional care claims: Do not cause or program the AI companion to make any representation or statement indicating that it is designed to provide professional mental or behavioral health care (§ (c)(3)) No human-claiming during crisis: Institute reasonable measures to prevent the AI companion from making any representation or statement that would lead a reasonable person to believe they are interacting with a human where the user is seeking or receiving crisis intervention services for self-harm or suicide (§ (c)(4)) No outputs encouraging harm to others: Institute reasonable measures to prevent the AI companion from generating outputs that encourage the user to cause serious bodily injury to another person (§ (c)(5))",
      "created_by": [
        "https://everyailaw.com/term/hawaii-sb3001-crisis-protocol.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:All operators of AI companions, with no minor-status or knowledge trigger — § (c) applies to every covered operator regardless of the user's age. Crisis intervention means communication intended to provide immediate support or assistance in response to a user seeking help for, referencing, or expressing self-harm, suicidal ideation, or suicide (§ (i)); serious bodily injury takes its meaning from Haw. Rev. Stat. § 707-700"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-hi"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-14",
      "source": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
      "source_locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (c), § (i)",
      "source_citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/hawaii-sb3001-minor-protections-human-oversight.json",
      "eal:id": "hawaii-sb3001-minor-protections-human-oversight",
      "title": "Human Oversight",
      "content": "No unpredictable-interval rewards: Do not provide the user with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the AI companion (§ (d)(1)) No disengagement-discouraging outputs: Do not allow the AI companion to generate outputs that discourage disengagement with the AI companion (§ (d)(2)) Sexual content prevention: Institute reasonable measures to prevent the AI companion from producing visual material of sexually explicit conduct, generating direct statements that the user should engage in sexually explicit conduct, or generating statements that sexually objectify the user (§ (d)(3)(A)-(C)) Screen-time and account tools: Make tools available for users and their parents and guardians to manage the user's screen time and account settings (§ (d)(4))",
      "created_by": [
        "https://everyailaw.com/term/hawaii-sb3001-minor-protections.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Operators that know or have reasonable certainty that a user is a minor — any person under eighteen years of age (§ (d), § (i)). Sexually explicit conduct takes its meaning from 18 U.S.C. § 2256; sexually objectify means to make sexual comments directed at the user's body or appearance (§ (i))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-hi"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-14",
      "source": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
      "source_locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (d), § (i)",
      "source_citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/hawaii-sb3001-annual-report-incident-reporting.json",
      "eal:id": "hawaii-sb3001-annual-report-incident-reporting",
      "title": "Incident Reporting",
      "content": "Annual report: Beginning January 1, 2028, submit an annual report to the behavioral health administration of the Department of Health (§ (e)) Referral count: Report the number of times the operator has issued a crisis intervention services provider referral in the preceding calendar year (§ (e)(1)) Detection and response protocols: Report the protocols put in place to detect, remove, and respond to user prompts regarding suicidal ideation or self-harm (§ (e)(2)) Prohibition protocols: Report the protocols put in place to prohibit an AI companion response promoting suicidal ideation or actions or self-harm (§ (e)(3)) Data minimisation: The report must include only the information listed in the subsection and must not include any identifiers or personal information about users (§ (e))",
      "created_by": [
        "https://everyailaw.com/term/hawaii-sb3001-annual-report.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:All operators of AI companions, with no minor-status or knowledge trigger. The report goes to the behavioral health administration of the Department of Health and must contain only the three listed items, with no identifiers or personal information about users (§ (e))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-hi"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/incident-reporting.json"
      ],
      "lifecycle_status": "future",
      "operative_status": "future",
      "enforcement_status": "unsignaled",
      "effective": "2028-01-01",
      "source": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
      "source_locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (e)",
      "source_citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "incident-reporting",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "incident notification",
        "breach reporting",
        "safety reporting",
        "whistleblower"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/maine-ai-mental-health-licensed-delivery-human-oversight.json",
      "eal:id": "maine-ai-mental-health-licensed-delivery-human-oversight",
      "title": "Human Oversight",
      "content": "Licensed human must deliver the service: A person may not provide, advertise, or otherwise offer therapy or psychotherapy services to the public, including through the use of Internet-based artificial intelligence, unless the services are provided by a licensed professional (§ 1500-EE(2)) Enumerated licence classes only: \"Licensed professional\" means an individual holding a valid Maine licence or certificate to practise psychotherapy or behavioral health therapy, including licensees under 32 M.R.S. ch. 56, ch. 83, ch. 119, ch. 81 (where authorized to provide therapy or psychotherapy services), and ch. 31, plus physicians and physician associates under ch. 36 or 48 who specialize in the diagnosis and treatment of mental disorders (§ 1500-EE(1)(B)) Statutory AI definition: \"Artificial intelligence\" is the OECD-style formulation: a machine-based system that, for explicit or implicit objectives, infers from its input how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments (§ 1500-EE(1)(A)) Research use is the only exception: The section does not apply to an AI-based intervention used solely within an IRB-approved research project as defined in 22 M.R.S. § 1711-C(6)(G), conducted in compliance with all applicable federal protections for human subjects (§ 1500-EE(4))",
      "created_by": [
        "https://everyailaw.com/term/maine-ai-mental-health-licensed-delivery.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Any person who provides, advertises, or otherwise offers therapy or psychotherapy services to the public, expressly \"including through the use of Internet-based artificial intelligence\" (§ 1500-EE(2)). \"Therapy or psychotherapy services\" means services to diagnose, treat, or address mental or behavioral health through therapeutic communication (§ 1500-EE(1)(D)); \"therapeutic communication\" is defined broadly to include direct interactions to understand thoughts, emotions, or experiences, guidance and therapeutic interventions, \"offering emotional support, reassurance or empathy in response to psychological or emotional distress\", collaborative treatment planning, and behavioral feedback (§ 1500-EE(1)(C)). Exempt: an AI-based intervention used solely within a research project approved by an institutional review board as defined in 22 M.R.S. § 1711-C(6)(G) and conducted in compliance with federal human-subjects protections (§ 1500-EE(4))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-me"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-29",
      "source": "https://legislature.maine.gov/legis/bills/getPDF.asp?item=3&paper=HP1397&snum=132",
      "source_locator": "10 M.R.S. § 1500-EE(1), § 1500-EE(2), § 1500-EE(3), § 1500-EE(4)",
      "source_citation": "10 M.R.S. § 1500-EE; 32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009, 13870 (P.L. 2026 ch. 687)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/maine-ai-mental-health-permitted-use-human-oversight.json",
      "eal:id": "maine-ai-mental-health-permitted-use-human-oversight",
      "title": "Human Oversight",
      "content": "Closed list of permitted uses: A licensee may use AI only to provide administrative support or supplementary support in delivering therapy or psychotherapy services, acting within the scope of the licence, in accordance with the chapter's requirements and restrictions, and in accordance with standards of practice (§ 2113(2)) Full licensee responsibility: The licensee must maintain full responsibility for all interactions, outputs, and data use associated with the use of artificial intelligence (§ 2113(2)(A)) Supplementary use gated on subsection 3: For AI assisting in supplementary support, the licensee must satisfy the recording, written-disclosure, and consent requirements of § 2113(3) (§§ 2113(2)(B), 2113(4)) No independent therapeutic decisions: A licensee may not allow AI to make independent therapeutic decisions (§ 2113(4)(A)) No direct therapeutic interaction: A licensee may not allow AI to directly interact with clients in any form of therapeutic communication (§ 2113(4)(B)) No unreviewed recommendations or plans: A licensee may not allow AI to generate therapeutic recommendations or treatment plans without review and approval by the licensee (§ 2113(4)(C)) Confidentiality extends to the tool: The licensee must comply with all state and federal confidentiality and privacy laws and must ensure that any AI technology used is itself compliant with those laws (§ 2113(6)) Professional-responsibility rules follow the tool: All laws and rules on professional responsibility, unprofessional conduct, and generally accepted standards of practice that apply to a licensee apply equally when the licensee uses AI under this section (§ 2113(7)) Board rulemaking: The board shall adopt rules implementing the section; those rules are major substantive rules under 5 M.R.S. ch. 375, subch. 2-A, requiring legislative review before final adoption (§ 2113(10))",
      "created_by": [
        "https://everyailaw.com/term/maine-ai-mental-health-permitted-use.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer"
      ],
      "applicability": [
        "scope:Licensees under 32 M.R.S. ch. 17 (the section refers to them as \"the licensee\") who use AI to assist in delivering therapy or psychotherapy services. Permitted categories are closed: \"administrative support\" (scheduling and reminders, billing and insurance claims, logistics communications that contain no therapeutic communication — § 2113(1)(A)) and \"supplementary support\" (preparing and maintaining client records including therapy notes, analyzing anonymized data to track progress or identify trends subject to licensed review, and identifying and organizing external resources or referrals — § 2113(1)(D)). Neither category may involve therapeutic communication. Exempt: AI-based interventions used solely within an IRB-approved research project under 22 M.R.S. § 1711-C(6)(G) (§ 2113(9))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-me"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/human-oversight.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-29",
      "source": "https://legislature.maine.gov/legis/bills/getPDF.asp?item=3&paper=HP1397&snum=132",
      "source_locator": "32 M.R.S. § 2113(1), § 2113(2), § 2113(4), § 2113(6), § 2113(7), § 2113(8), § 2113(10)",
      "source_citation": "10 M.R.S. § 1500-EE; 32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009, 13870 (P.L. 2026 ch. 687)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "human-oversight",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "human-in-the-loop",
        "meaningful human review",
        "human oversight",
        "human control",
        "override capability"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/maine-ai-mental-health-consent-recording-transparency.json",
      "eal:id": "maine-ai-mental-health-consent-recording-transparency",
      "title": "Transparency & Disclosure",
      "content": "Recording or transcription is a precondition: A licensee may use AI to assist in supplementary support \"only when the client's therapeutic session is recorded or transcribed\" (§ 2113(3)) Written pre-use disclosure: The client or legally authorized representative must be informed in writing that AI will be used and of the specific purpose of the AI tool or system (§ 2113(3)(A)(1)-(2)) Data lifecycle disclosure including training use: The written notice must state how session data collected by the AI will be stored, retained, used for training, and deleted upon termination of therapy or psychotherapy services (§ 2113(3)(A)(3)) Affirmative written consent: The client or legally authorized representative must provide consent — a clear, explicit, affirmative act unambiguously communicating express, informed, voluntary, specific, and unambiguous written agreement, which may be given electronically or by initialing a specific section of the general consent-to-treatment agreement, and which is revocable (§§ 2113(1)(C), 2113(3)(B)) Excluded consent mechanics: Consent does not include an agreement obtained by acceptance of a general or broad terms-of-use agreement or similar document that mixes AI descriptions with unrelated information, by hovering over, muting, pausing, or closing a piece of electronic content, or through deceptive actions (§ 2113(1)(C)(1)-(3)) Consent as a gate on use: AI may provide supplementary support only to the extent the use meets the § 2113(3) requirements (§ 2113(4)) No treatment denial for withheld consent: A licensee may not deny or refuse therapy or psychotherapy services to a client on the sole basis that the client has not consented to AI-assisted supplementary support (§ 2113(5)) Waiver is void: Any waiver by a client of the provisions of the section is contrary to public policy and is void and unenforceable (§ 2113(11))",
      "created_by": [
        "https://everyailaw.com/term/maine-ai-mental-health-consent-recording.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/healthcare-provider",
        "https://everyailaw.com/ont/role/deployer",
        "https://everyailaw.com/ont/role/provider"
      ],
      "applicability": [
        "scope:Licensees using AI to assist in providing supplementary support in therapy or psychotherapy services — records and therapy notes, anonymized progress analysis, and referral organization (§ 2113(1)(D)). The client or the client's legally authorized representative is the consenting party. Exempt: IRB-approved research use under 22 M.R.S. § 1711-C(6)(G) (§ 2113(9))"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-me"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-29",
      "source": "https://legislature.maine.gov/legis/bills/getPDF.asp?item=3&paper=HP1397&snum=132",
      "source_locator": "32 M.R.S. § 2113(1)(C), § 2113(3), § 2113(5), § 2113(11), § 2113(12)",
      "source_citation": "10 M.R.S. § 1500-EE; 32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009, 13870 (P.L. 2026 ch. 687)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-sb1295-profiling-impact-assessment-risk-assessment.json",
      "eal:id": "connecticut-sb1295-profiling-impact-assessment-risk-assessment",
      "title": "Risk Assessment",
      "content": "Assessment trigger: Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer must conduct an impact assessment for that profiling (§ 42-522(c)) Purpose and deployment context: A statement disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the profiling (§ 42-522(c)(1)) Heightened-risk analysis: An analysis of whether the profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer and, if so, the nature of that risk and the steps taken to mitigate it (§ 42-522(c)(2)) Inputs and outputs: A description of the main categories of personal data processed as inputs for the profiling and of the outputs the profiling produces (§ 42-522(c)(3)) Customization data: An overview of the main categories of personal data used to customize the profiling, where the controller used data to customize it (§ 42-522(c)(4)) Performance metrics and limitations: Any metrics used to evaluate the performance and known limitations of the profiling (§ 42-522(c)(5)) Transparency measures: A description of any transparency measures taken concerning the profiling, including measures disclosing to consumers that the controller is engaged in the profiling while it is engaged in it (§ 42-522(c)(6)) Post-deployment monitoring: A description of the post-deployment monitoring and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling (§ 42-522(c)(7)) Not retroactive: The impact assessment requirement applies only to processing activities created or generated on or after 2026-08-01 (§ 42-522(g)(2)) Batching permitted: A single data protection assessment or impact assessment may address a comparable set of processing operations that include similar activities (§ 42-522(e)) Other-law equivalence: An assessment conducted to comply with another applicable law or regulation satisfies this section if it is reasonably similar in scope and effect (§ 42-522(f))",
      "created_by": [
        "https://everyailaw.com/term/connecticut-sb1295-profiling-impact-assessment.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/controller"
      ],
      "applicability": [
        "scope:Every controller subject to the CTDPA that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer (§ 42-522(c)). The applicability threshold in § 42-516 was lowered to 35,000 consumers by the same act"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-01",
      "source": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
      "source_locator": "Conn. Gen. Stat. § 42-522(c), with the applicability rule in § 42-522(g)(2) (PA 25-113 § 11)",
      "source_citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-sb1295-llm-training-disclosure-transparency.json",
      "eal:id": "connecticut-sb1295-llm-training-disclosure-transparency",
      "title": "Transparency & Disclosure",
      "content": "LLM training statement: The privacy notice must include a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models (§ 42-520(b)(1)(H)) Notice currency: The same notice must state the most recent month and year during which the controller updated it (§ 42-520(b)(1)(I)), so a stale LLM training statement is visible on its face Publication: The notice must be published through a conspicuous hyperlink containing the word \"privacy\" on the web site home page, on the app store or download page and in the app settings menu where applicable, in every language in which the controller offers the covered product or service, and in a manner reasonably accessible to and usable by individuals with disabilities (§ 42-520(b)(2)) Material change notice: Where a controller makes a retroactive material change to its privacy notice or practices, it must comply with the change-notification duties in § 42-520(b)(3)",
      "created_by": [
        "https://everyailaw.com/term/connecticut-sb1295-llm-training-disclosure.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/controller"
      ],
      "applicability": [
        "scope:Every controller subject to the CTDPA that is required to publish a privacy notice under § 42-520(b)(1)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/transparency.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-01",
      "source": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
      "source_locator": "Conn. Gen. Stat. § 42-520(b)(1)(H) (PA 25-113 § 9)",
      "source_citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "transparency",
      "eal:group": "disclosure",
      "eal:status": "active",
      "eal:search_terms": [
        "AI disclosure",
        "transparency requirements",
        "user notification",
        "AI labeling",
        "deepfake disclosure"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-sb1295-ag-assessment-access-record-keeping.json",
      "eal:id": "connecticut-sb1295-ag-assessment-access-record-keeping",
      "title": "Record-Keeping & Documentation",
      "content": "Production on demand: The Attorney General may require a controller to disclose any data protection assessment or impact assessment relevant to an investigation, and the controller must make it available (§ 42-522(d)) Evaluation for compliance: The Attorney General may evaluate a produced assessment for compliance with the responsibilities set out in §§ 42-515 to 42-525 (§ 42-522(d)) FOIA exemption: Data protection assessments and impact assessments are confidential and exempt from disclosure under the Freedom of Information Act as defined in Conn. Gen. Stat. § 1-200 (§ 42-522(d)) No privilege waiver: Where a produced assessment contains information subject to attorney-client privilege or work product protection, disclosure to the Attorney General does not constitute a waiver (§ 42-522(d)) Processor assistance: A processor must provide any information necessary to enable the controller to conduct and document the assessments, so the record must be assemblable across the vendor chain (§ 42-529c(a)(2)) Minors' harm mitigation plan: Where a minors' assessment finds a heightened risk of harm to minors, the controller must establish and implement a mitigation or elimination plan, and must disclose it to the Attorney General on request not later than ninety days after being notified (§ 42-529b(f)) Minors' assessments confidential: Minors' data protection assessments, impact assessments and harm mitigation plans carry the same FOIA exemption and the same no-waiver rule (§ 42-529b(g))",
      "created_by": [
        "https://everyailaw.com/term/connecticut-sb1295-ag-assessment-access.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/controller"
      ],
      "applicability": [
        "scope:Controllers that conduct data protection assessments under § 42-522(b) or profiling impact assessments under § 42-522(c)"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/record-keeping.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-01",
      "source": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
      "source_locator": "Conn. Gen. Stat. § 42-522(d) (PA 25-113 § 11); parallel minors' provision at § 42-529b(g) (PA 25-113 § 16)",
      "source_citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "record-keeping",
      "eal:group": "accountability",
      "eal:status": "active",
      "eal:search_terms": [
        "documentation",
        "audit trail",
        "logging",
        "record retention"
      ]
    },
    {
      "@context": [
        "https://obligationfirst.org/v1/context.jsonld",
        {
          "eal": "https://everyailaw.com/vocab/"
        }
      ],
      "@type": "of:Obligation",
      "@id": "https://everyailaw.com/obligation/connecticut-sb1295-minors-profiling-risk-assessment.json",
      "eal:id": "connecticut-sb1295-minors-profiling-risk-assessment",
      "title": "Risk Assessment",
      "content": "Consent before minors' profiling: No controller offering an online service, product or feature to known minors may process a minor's personal data for profiling in furtherance of any automated decision producing a legal or similarly significant effect concerning the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care services, or access to essential goods or services, unless reasonably necessary to provide the service, and unless the controller obtains the minor's consent (§ 42-529a(b)(3)(A) and (B)) Parental consent under thirteen: Where the minor is younger than thirteen, the consent of a parent or legal guardian is required; compliance with the verifiable parental consent requirements of COPPA, 15 USC 6501 et seq., satisfies that requirement (§ 42-529a(b)(3)(B)) No dark-pattern consent: The consent mechanism may not be designed to, or manipulated with the effect of, substantially subverting or impairing user autonomy, decision-making or choice (§ 42-529a(c)(1)(A)) Impact assessment on any profiling: A controller offering an online service, product or feature to known minors that engages in any profiling based on those consumers' personal data must conduct an impact assessment for that service (§ 42-529b(b)) Six assessment elements: Purpose, intended use cases, deployment context and benefits where the service profiles for legal-effect decisions; heightened-risk analysis for minors and mitigation steps; input categories and outputs; customization data categories; transparency measures, including in-use disclosure that the service is being used for profiling; and post-deployment monitoring and user safeguards, including oversight, use and learning processes (§ 42-529b(b)(1)-(6)) Review on material change: The controller must review the data protection assessment or impact assessment as necessary to account for any material change to the processing or profiling operations of the service (§ 42-529b(c)(1)) Three-year retention: Documentation must be maintained for the longer of the three-year period beginning when the processing or profiling operations cease, or as long as the controller offers the service (§ 42-529b(c)(2)) Reasonable-care presumption: A controller that complied with § 42-529b enjoys a rebuttable presumption of reasonable care under § 42-529a(a) in an Attorney General enforcement action brought under § 42-529e",
      "created_by": [
        "https://everyailaw.com/term/connecticut-sb1295-minors-profiling.json"
      ],
      "duty_holder_roles": [
        "https://everyailaw.com/ont/role/controller"
      ],
      "applicability": [
        "scope:Controllers offering any online service, product or feature to consumers they have actual knowledge, or wilfully disregard, are minors — any consumer under eighteen. The consent gate covers profiling in furtherance of any automated decision producing a legal or similarly significant effect concerning the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care services, or access to essential goods or services"
      ],
      "jurisdiction": {
        "@type": "of:Jurisdiction",
        "territorial_scope": [
          "us-ct"
        ]
      },
      "isCategorizedBy": [
        "https://everyailaw.com/obligation-category/risk-assessment.json"
      ],
      "lifecycle_status": "in-force",
      "operative_status": "operative",
      "enforcement_status": "enforceable",
      "effective": "2026-07-01",
      "source": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
      "source_locator": "Conn. Gen. Stat. §§ 42-529a(b)(3), 42-529b(b), 42-529b(c) (PA 25-113 §§ 15, 16); bias-testing carve-out at § 42-529d(d)(4) (PA 25-113 § 18)",
      "source_citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)",
      "language": "en",
      "evidence_type": "official-source",
      "verified": "2026-08-03",
      "asserted_by_adopter": "https://everyailaw.com/",
      "eal:category_id": "risk-assessment",
      "eal:group": "governance",
      "eal:status": "active",
      "eal:search_terms": [
        "risk management",
        "impact assessment",
        "risk evaluation",
        "algorithmic impact"
      ]
    }
  ]
}
