{
  "meta": {
    "generated": "2026-09-29T00:00:00Z",
    "license": {
      "name": "EveryAILaw Data License v1.4.1",
      "url": "https://everyailaw.com/data-license.html",
      "summary": "Direct use, evaluation, research, citation, internal tooling, and machine/agent querying (including by LLMs and via MCP) are free via the public Free Endpoint, no permission required. Commercial redistribution, or embedding the corpus into a Product or Service made available to a Third Party, requires a Commercial Agreement.",
      "commercial": "https://paice.work/contact/"
    },
    "count": 219
  },
  "provisions": [
    {
      "id": "au-nsw-digital-work-systems-risk-assessment",
      "regulation": "au-nsw-digital-work-systems",
      "name": "Digital Work System Risk Assessment",
      "requirements": [
        {
          "requirement": "Commencement qualification",
          "details": "The following new statutory duties apply once Schedule 1[1]-[3] commence by proclamation; these amendments are exempt from the minimum one-month wait after guideline publication in section 2(2). No commencement date was established in the retained 2026-09-08 source review; this correction does not establish a later proclamation date"
        },
        {
          "requirement": "Work-allocation risks",
          "details": "Under section 21A(2), consider whether allocation of work by or using a digital work system creates excessive or unreasonable workloads, metrics or monitoring/surveillance, or unlawful discriminatory practices or decision-making"
        },
        {
          "requirement": "Risk management",
          "details": "Section 19(3)(c1) addresses risks from use of digital work systems; section 21A(1) requires ensuring, so far as reasonably practicable, that worker health and safety is not put at risk from allocation of work by a digital work system"
        },
        {
          "requirement": "Scope of digital work systems",
          "details": "Section 4 defines a digital work system as an algorithm, artificial intelligence, automation or online platform; the duties supply the relevant business/undertaking and work-allocation context"
        }
      ],
      "penalties": [
        {
          "violation": "Individual (failure to manage digital work system risks)",
          "fine": "WHS Act penalty framework; applicable current maxima and offence-category conditions were not established in this bounded review"
        },
        {
          "violation": "Corporation (failure to manage digital work system risks)",
          "fine": "WHS Act penalty framework; applicable current maxima and offence-category conditions were not established in this bounded review"
        }
      ],
      "scope": "Persons conducting a business or undertaking in New South Wales that use a digital work system for work allocation, monitoring, performance management, or similar workplace functions",
      "context": "The enacted amendments expressly cover algorithms, artificial intelligence, automation and online platforms. Section 19(3)(c1) addresses worker health and safety risks from their use; section 21A specifically addresses allocation of work and requires consideration of listed workload, metrics, monitoring and unlawful-discrimination risks. These amendments require proclamation. Their pending status does not mean existing WHS duties cease to apply to digital systems. The section 118 duty to assist an entry permit holder is separate from the risk duties summarized here. Its penalties are not penalties for breach of sections 19(3)(c1) or 21A.",
      "instrument_notes": "Phased commencement: the instrument date 2026-02-18 covers only Schedule 1[7], [9] and [11], the initial guideline-enabling phase. The two substantive provisions remain pending with proclamation dates unestablished in this review. Schedule 1[1]-[3] are exempt from the minimum guideline-plus-one-month wait but still require proclamation; the reasonable-assistance power also requires relevant published guidelines.",
      "roles": [
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://legislation.nsw.gov.au/view/html/inforce/current/act-2026-005",
        "locator": "WHS Act 2011 sections 19(3)(c1) and 21A, inserted by Schedule 1[2]-[3]; Amendment Act section 2",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/au-nsw-digital-work-systems-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/au-nsw-digital-work-systems-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": null,
        "verified": "2026-03-28",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "au-nsw-digital-work-systems-transparency",
      "regulation": "au-nsw-digital-work-systems",
      "name": "Digital Work System Transparency and Inspection Access",
      "requirements": [
        {
          "requirement": "Inspection assistance",
          "details": "Once commenced and applicable guidelines exist, a WHS entry permit holder may require reasonable assistance to access and inspect a digital work system relevant to the suspected contravention; this is not an unconditional inspection entitlement"
        },
        {
          "requirement": "Reasonable assistance",
          "details": "The new assistance duty is subject to the commencement, suspected-contravention, notice and applicable-guideline conditions"
        },
        {
          "requirement": "Notice requirement",
          "details": "At least 48 hours before the proposed entry, not an obligation to provide assistance within 48 hours of a request"
        },
        {
          "requirement": "Notice timing",
          "details": "Notice must be given during business hours and not more than 14 days before entry"
        },
        {
          "requirement": "SafeWork guidelines",
          "details": "Section 118A requires consultation, consideration of feedback and publication. Proclamation remains necessary after the minimum one-month wait; publication plus one month does not automatically commence the power. Schedule 1[11] also requires guidelines relevant to its exercise, including any class limitation"
        }
      ],
      "penalties": [
        {
          "violation": "Failure to provide reasonable assistance (individual)",
          "fine": "121 penalty units (~AUD 13,310)"
        },
        {
          "violation": "Failure to provide reasonable assistance (corporation)",
          "fine": "607 penalty units (~AUD 69,980)"
        }
      ],
      "scope": "Persons conducting a business or undertaking whose digital work system is relevant to a suspected WHS contravention and is accessed by a WHS entry permit holder under the guideline-gated inspection provisions",
      "context": "The new power requires a PCBU to provide reasonable assistance with access and inspection of a digital work system relevant to a suspected WHS contravention. SafeWork distinguishes this from existing inspection rights. Commencement requires proclamation and cannot be earlier than one month after publication of the first guidelines; exercise also requires guidelines relevant to the particular power/workplace under Schedule 1[11]. The 2026-09-08 source review did not establish these events, so the provision is pending with no effective date assigned.",
      "instrument_notes": "Phased commencement: the instrument date 2026-02-18 covers only Schedule 1[7], [9] and [11], the initial guideline-enabling phase. The two substantive provisions remain pending with proclamation dates unestablished in this review. Schedule 1[1]-[3] are exempt from the minimum guideline-plus-one-month wait but still require proclamation; the reasonable-assistance power also requires relevant published guidelines.",
      "roles": [
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://legislation.nsw.gov.au/view/html/inforce/current/act-2026-005",
        "locator": "WHS Act 2011 sections 118(1)(a1), 118(2A) and 118A; Amendment Act section 2 and Schedule 1[5]-[9], [11]",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/au-nsw-digital-work-systems-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/au-nsw-digital-work-systems-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": null,
        "verified": "2026-06-30",
        "checked": "2026-08-06",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "au-privacy-act-adm-data-governance",
      "regulation": "au-privacy-act-adm",
      "name": "Data Minimisation for AI Systems",
      "requirements": [
        {
          "requirement": "APP 3 collection boundary",
          "details": "For non-sensitive personal information, an agency's collection must be reasonably necessary for, or directly related to, its functions or activities; an organisation's collection must be reasonably necessary for its functions or activities"
        },
        {
          "requirement": "Sensitive information and collection method",
          "details": "APP 3 adds consent or exception requirements for sensitive information and generally requires lawful and fair collection directly from the individual unless an exception applies"
        },
        {
          "requirement": "Proportionality and minimisation guidance",
          "details": "OAIC's APP 3 Guidelines say proportionality is implicit in reasonable necessity and that entities should limit collection to the minimum amount necessary in the circumstances"
        },
        {
          "requirement": "APP 6 purpose limitation",
          "details": "An APP entity must not use or disclose personal information for a secondary purpose unless consent or another APP 6 exception applies; reasonable-expectations exceptions require a related purpose, or a directly related purpose for sensitive information"
        },
        {
          "requirement": "AI-specific OAIC guidance",
          "details": "For AI uses, OAIC guidance tells organisations to identify whether an AI input is a use or disclosure, assess the primary purpose and any exception, and minimise the personal information used or disclosed for a secondary purpose"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "A breach of an APP can constitute an interference with privacy; remedies and penalties depend on the applicable Privacy Act enforcement provisions and facts"
        }
      ],
      "scope": "APP entities when collecting, holding, using, or disclosing personal information in an AI context, subject to the Act's entity coverage and applicable exceptions",
      "context": "APP 3 regulates an APP entity's collection of solicited personal information, and APP 6 restricts an APP entity's use or disclosure of personal information for a secondary purpose unless an exception applies. OAIC guidance applies those existing rules to covered AI collection, generation, inference, inputs, uses, and disclosures. It describes proportionality and data minimisation under APP 3 and recommends minimising personal information used or disclosed for an APP 6 secondary purpose. These are not duties on every AI system or new APP clauses commencing in December 2026.",
      "instrument_notes": null,
      "roles": [
        "controller",
        "government"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.gov.au/C2004A03712/2026-06-04/2026-06-04/text/original/pdf",
        "locator": "APP 3, APP 6",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/au-privacy-act-adm-data-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/au-privacy-act-adm-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2014-03-12",
        "verified": "2026-05-15",
        "checked": "2026-08-09",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "au-privacy-act-adm-risk",
      "regulation": "au-privacy-act-adm",
      "name": "Privacy Impact Assessments for AI",
      "requirements": [
        {
          "requirement": "APP 1.2 relationship",
          "details": "OAIC says a PIA may assist an entity to demonstrate privacy compliance and identify practices, procedures, or systems that may be reasonable for new projects under APP 1.2"
        },
        {
          "requirement": "Private-sector guidance",
          "details": "OAIC strongly encourages PIAs for projects involving personal information and says organisations considering AI products should take a privacy-by-design approach that includes a PIA; this guidance does not create a generic statutory PIA mandate"
        },
        {
          "requirement": "Project-specific threshold",
          "details": "OAIC says not every project needs a PIA and recommends a threshold assessment based on the project's handling of personal information and privacy risk"
        },
        {
          "requirement": "Separate agency mandate",
          "details": "The Privacy (Australian Government Agencies - Governance) APP Code 2017 separately requires covered Australian Government agencies to conduct a PIA for high privacy risk projects"
        }
      ],
      "penalties": [
        {
          "violation": "Private-sector PIA guidance",
          "fine": "OAIC states that its power to direct agencies to undertake a PIA does not apply to private-sector organisations"
        }
      ],
      "scope": "APP entities receive OAIC guidance and encouragement; Australian Government agencies have a separate high-privacy-risk-project mandate under the Privacy (Australian Government Agencies - Governance) APP Code 2017",
      "context": "Review of APP 1.2 in the current Privacy Act compilation, the OAIC PIA Guide, and the OAIC commercial-AI guidance did not establish a generic private-sector PIA mandate for AI use. OAIC guidance says a PIA can assist an APP entity to identify practices, procedures, and systems that may be reasonable under APP 1.2, strongly encourages PIAs for projects involving personal information, and recommends a PIA when an organisation considers commercially available AI. The OAIC also states that not every project needs a PIA and that its power to direct agencies does not apply to private-sector organisations. A separate APP Code requires Australian Government agencies to conduct PIAs for high privacy risk projects; that Code mandate is not reclassified here as a Privacy Act AI obligation.",
      "instrument_notes": null,
      "roles": [],
      "status": "voluntary",
      "source": {
        "url": "https://oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/guide-to-undertaking-privacy-impact-assessments",
        "locator": "OAIC PIA guidance; APP 1.2 relationship",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/au-privacy-act-adm-risk.json",
        "obligations": []
      },
      "dates": {
        "recorded_effective": null,
        "verified": "2026-05-15",
        "checked": "2026-08-13",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "au-privacy-act-adm-transparency",
      "regulation": "au-privacy-act-adm",
      "name": "Automated Decision-Making Transparency (APP 1.7/1.8)",
      "requirements": [
        {
          "requirement": "Actor and arrangement",
          "details": "The actor is an APP entity that has arranged for a computer program to make a decision or do a thing substantially and directly related to making it"
        },
        {
          "requirement": "Significant-effect condition",
          "details": "The decision must be one that could reasonably be expected to significantly affect an individual's rights or interests, adversely or beneficially"
        },
        {
          "requirement": "Personal-information condition",
          "details": "Personal information about that individual must be used in the program to make the decision or do the substantially and directly related thing"
        },
        {
          "requirement": "Kinds of personal information",
          "details": "The privacy policy must state the kinds of personal information used in such programs"
        },
        {
          "requirement": "Solely automated decisions",
          "details": "The privacy policy must state the kinds of covered decisions made solely by such programs"
        },
        {
          "requirement": "Computer-assisted decisions",
          "details": "The privacy policy must state the kinds of covered decisions for which such programs do a thing substantially and directly related to making the decision"
        },
        {
          "requirement": "Application after commencement",
          "details": "The amendment applies to decisions made after 10 December 2026 even if the arrangement, data use, or acquisition or creation of the personal information occurred earlier"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "A breach of an APP can constitute an interference with privacy; remedies and penalties depend on the applicable Privacy Act enforcement provisions and facts"
        }
      ],
      "scope": "APP entities meeting every condition in APP 1.7(a)-(c)",
      "context": "From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to contain the APP 1.8 information only when the entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect an individual's rights or interests; and personal information about that individual is used in the program for that decision or related thing. This is an APP-entity duty with statutory conditions, not a rule for every AI provider or every use of personal information.",
      "instrument_notes": null,
      "roles": [
        "controller",
        "government"
      ],
      "status": "enacted",
      "source": {
        "url": "https://legislation.gov.au/C2024A00128/asmade/2024-12-10/text/1/pdf",
        "locator": "APP 1.7, APP 1.8, APP 1.9",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/au-privacy-act-adm-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/au-privacy-act-adm-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-12-10",
        "verified": "2026-06-30",
        "checked": "2026-08-06",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "br-ai-bill-oversight",
      "regulation": "br-ai-bill",
      "name": "Human Oversight and Contestation",
      "requirements": [
        {
          "requirement": "Human review",
          "details": "Art. 6(III) gives a person affected by a high-risk system the right to human review of the decision, weighed against context, risk, and the state of the art"
        },
        {
          "requirement": "Right to contest",
          "details": "Art. 6(II) gives the right to contest and request review of a decision, recommendation, or prediction"
        },
        {
          "requirement": "Human supervision",
          "details": "Art. 8 requires human supervision of high-risk systems that lets supervisors understand, interpret, decide, and intervene; not required where implementation is provably impossible or disproportionate, in which case effective alternative measures apply"
        },
        {
          "requirement": "Procedures for exercising rights",
          "details": "Art. 9 requires agents to state how the rights are exercised; Art. 10 has the competent authority issue general guidelines with the SIA sector authorities"
        },
        {
          "requirement": "Enforcement avenues",
          "details": "Art. 11 allows the rights to be asserted before the competent administrative body or in court, individually or collectively"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Up to BRL 50 million or 2% of revenue"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "proposed",
      "source": {
        "url": "https://www25.senado.leg.br/web/atividade/materias/-/materia/157233",
        "locator": "Articles 6, 8-11",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/br-ai-bill-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/br-ai-bill-oversight-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": null,
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "br-ai-bill-risk",
      "regulation": "br-ai-bill",
      "name": "Risk-Based AI Classification",
      "requirements": [
        {
          "requirement": "Risk classification",
          "details": "AI systems classified by risk level: excessive (Art. 13), high (Art. 14), and general"
        },
        {
          "requirement": "Preliminary assessment",
          "details": "Self-classification before market introduction is optional — Art. 12 makes it a good-practice measure (\"poderá realizar\") that earns favourable treatment, not a precondition; a sector authority may simplify or waive it, and the competent authority may order reclassification or require an algorithmic impact assessment (Art. 12 § 4)"
        },
        {
          "requirement": "Prohibited practices",
          "details": "Art. 13 bans systems that induce harmful behaviour, exploit vulnerabilities, profile people to predict criminality or recidivism, or facilitate child sexual abuse material; plus public-authority social scoring, autonomous weapons systems, and real-time remote biometric identification in public spaces (with judicially authorised exceptions)"
        },
        {
          "requirement": "High-risk categories",
          "details": "Art. 14 lists twelve: critical-infrastructure safety devices; student admission selection and evaluations determining academic progress or monitoring; recruitment and employment decisions; access to essential public and private services; triage of emergency service calls; administration of justice; autonomous vehicles in public spaces; health diagnostics and procedures; analytical study of crimes; investigative credibility assessment and profiling; biometric emotion recognition; immigration and border control"
        },
        {
          "requirement": "Algorithmic impact assessment",
          "details": "Mandatory for high-risk systems (Art. 25), performed before placing the system on the market (Art. 26); conclusions are public, subject to trade-secret protection (Art. 28)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Up to BRL 50 million or 2% of revenue"
        },
        {
          "violation": "Severe violations",
          "fine": "Warnings, suspension, or bans on AI system operation"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "proposed",
      "source": {
        "url": "https://www25.senado.leg.br/web/atividade/materias/-/materia/157233",
        "locator": "Articles 12-17, 25-28",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/br-ai-bill-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/br-ai-bill-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": null,
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "br-ai-bill-transparency",
      "regulation": "br-ai-bill",
      "name": "Transparency and Explainability",
      "requirements": [
        {
          "requirement": "Vulnerable groups",
          "details": "Systems intended for vulnerable groups must be transparent at every lifecycle stage, use simple, clear language appropriate to age and cognitive ability, and consider those groups’ best interests (Art. 5 § 2)"
        },
        {
          "requirement": "Disclosure of AI interaction",
          "details": "Art. 5(I) gives every affected person, at any risk level, the right to accessible free information that an interaction is automated, conveyed with standardised icons or symbols (Art. 5 § 1); cybersecurity and cyberdefence systems are excepted"
        },
        {
          "requirement": "Right to explanation",
          "details": "Art. 6(I) grants an explanation of a high-risk system's decision, recommendation, or prediction, subject to trade and industrial secrecy (Art. 6 § 1)"
        },
        {
          "requirement": "Explanation procedure",
          "details": "Art. 7 requires the explanation to be free, in plain accessible language, within a reasonable period; the competent authority sets deadlines and a simplified procedure scaled to system complexity and agent size"
        },
        {
          "requirement": "Documentation",
          "details": "Art. 18 requires developers and deployers of high-risk systems to keep lifecycle documentation and to use tools that allow accuracy and robustness to be assessed"
        },
        {
          "requirement": "Procedures for exercising rights",
          "details": "Art. 9 requires high-risk agents to state, clearly and accessibly, how the Chapter II rights are exercised"
        },
        {
          "requirement": "Synthetic content marking",
          "details": "Art. 19 requires an identifier in AI-generated synthetic content for authenticity and provenance verification; artistic, cultural, or entertainment works may signal via credits or metadata where doing so does not risk spreading false information (Art. 19 § 3)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Up to BRL 50 million or 2% of revenue"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "proposed",
      "source": {
        "url": "https://www25.senado.leg.br/web/atividade/materias/-/materia/157233",
        "locator": "Articles 5-7, 9, 18-19",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/br-ai-bill-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/br-ai-bill-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": null,
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ab2013-training-data",
      "regulation": "california-ab2013",
      "name": "Training Data Documentation",
      "requirements": [
        {
          "requirement": "Posting duty",
          "details": "Post training-data documentation on the developer's own website before each time the system, service, or a substantial modification is made publicly available to Californians (§ 3111)"
        },
        {
          "requirement": "Dataset sources",
          "details": "Identify the sources or owners of the datasets, and describe how they further the intended purpose of the system (§ 3111(a)(1)-(2))"
        },
        {
          "requirement": "Dataset size and shape",
          "details": "State the number of data points, which may be given in general ranges with estimates for dynamic datasets, and describe the types of data points — label types where labelled, general characteristics where not (§ 3111(a)(3)-(4))"
        },
        {
          "requirement": "IP status",
          "details": "State whether the datasets include data protected by copyright, trademark, or patent, or are entirely in the public domain (§ 3111(a)(5))"
        },
        {
          "requirement": "Provenance of acquisition",
          "details": "State whether the datasets were purchased or licensed (§ 3111(a)(6))"
        },
        {
          "requirement": "Personal information",
          "details": "State whether the datasets include personal information or aggregate consumer information as defined in Civ. Code § 1798.140 (§ 3111(a)(7)-(8))"
        },
        {
          "requirement": "Cleaning and processing",
          "details": "Describe any cleaning, processing, or other modification of the datasets, and its intended purpose in relation to the system (§ 3111(a)(9))"
        },
        {
          "requirement": "Collection period",
          "details": "Give the time period during which the data were collected, with notice if collection is ongoing, and the dates the datasets were first used in development (§ 3111(a)(10)-(11))"
        },
        {
          "requirement": "Synthetic data",
          "details": "State whether the system used or continuously uses synthetic data generation in development; a functional-need description may be included (§ 3111(a)(12))"
        },
        {
          "requirement": "Substantial modification trigger",
          "details": "A new version, release, or update that materially changes functionality or performance — including results of retraining or fine tuning — re-triggers the posting duty (§ 3110(d))"
        },
        {
          "requirement": "Exemptions",
          "details": "No documentation is required for systems whose sole purpose is security and integrity as defined in Civ. Code § 1798.140(ac), whose sole purpose is operating aircraft in the national airspace, or that are developed for national security, military, or defense purposes and made available only to a federal entity (§ 3111(b))"
        }
      ],
      "penalties": [
        {
          "violation": "No express statutory penalty",
          "fine": "Civil Code §§ 3110–3111 specify no penalty or enforcing authority for this documentation duty"
        }
      ],
      "scope": "Developers — persons, partnerships, state or local government agencies, or corporations that design, code, produce, or substantially modify a GenAI system or service for use by members of the public — for any system or service released on or after 2022-01-01 that is made publicly available to Californians, whether or not for compensation (§§ 3110(b), 3111)",
      "context": "The disclosure runs to training inputs rather than outputs, which makes it the counterpart to the provenance duties in the California AI Transparency Act: one documents what went into the model, the other marks what comes out. It bites on every substantial modification — a new version, release, update, retraining, or fine-tune that materially changes functionality or performance — so it is a recurring release-gate obligation, not a one-time filing. There is no penalty provision and no named enforcer in the chapter.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013",
        "locator": "Cal. Civ. Code §§ 3110, 3111",
        "citation": "Cal. Civ. Code §§ 3110-3111 (Ch. 817, Stats. 2024)"
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ab2013-training-data.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ab2013-training-data-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-08-02",
        "checked": "2026-09-22",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [
          {
            "date": "2025-07-28",
            "description": "AB 1170 (Ch. 67, Sec. 35) removed the word be from the opening including-but-not-limited-to clause of Civil Code 3111, effective January 1, 2026; the listed disclosures and exemptions are unchanged"
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ab3030-disclosure",
      "regulation": "california-ab3030",
      "name": "GenAI Patient Communication Disclosure",
      "requirements": [
        {
          "requirement": "AI disclosure",
          "details": "Covered facilities and practices using GenAI for patient clinical communications must include a disclaimer indicating AI generation"
        },
        {
          "requirement": "Human contact instructions",
          "details": "Communications must include clear instructions for contacting a human healthcare provider, employee of the covered facility or practice, or other appropriate person"
        },
        {
          "requirement": "Exemption",
          "details": "A GenAI communication read and reviewed by a human licensed or certified healthcare provider is exempt from both the disclaimer and human-contact instruction requirements"
        },
        {
          "requirement": "Disclaimer placement",
          "details": "Format-specific: written communications must disclose at the beginning; chat/continuous interactions must disclose throughout; audio must disclose at both start and end; video must disclose throughout (per Medical Board of California GenAI Notification Requirements guidance)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Existing regulatory enforcement mechanisms"
        }
      ],
      "scope": "health facilities, clinics, physician's offices, and group practices using GenAI for written or verbal patient clinical communications (excluding purely administrative communications)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "healthcare-provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB3030",
        "locator": "Cal. Health & Safety Code § 1339.75",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ab3030-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ab3030-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-01-01",
        "verified": "2026-06-30",
        "checked": "2026-08-19",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ab3030-oversight",
      "regulation": "california-ab3030",
      "name": "Human Oversight of AI Healthcare Communications",
      "requirements": [
        {
          "requirement": "Provider review exemption",
          "details": "A GenAI communication read and reviewed by a human licensed or certified healthcare provider is exempt from both the disclaimer and human-contact instruction requirements."
        },
        {
          "requirement": "Human contact instructions",
          "details": "Where the disclosure duty applies, the communication must give clear instructions for contacting a human healthcare provider, employee of the covered facility or practice, or other appropriate person"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Existing regulatory enforcement mechanisms"
        }
      ],
      "scope": "health facilities, clinics, physician's offices, and group practices using GenAI for written or verbal patient clinical communications (excluding purely administrative communications)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "healthcare-provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB3030",
        "locator": "Cal. Health & Safety Code § 1339.75",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ab3030-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ab3030-oversight-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-01-01",
        "verified": "2026-06-30",
        "checked": "2026-08-22",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ads-employment-bias",
      "regulation": "california-ads-employment-regs",
      "name": "Prohibition on Discriminatory Automated Employment Decisions",
      "requirements": [
        {
          "requirement": "Non-discrimination",
          "details": "Employers and other covered entities must not use automated-decision systems or selection criteria that discriminate against applicants or employees on a basis protected by FEHA, subject to any available defense (§ 11009(f))"
        },
        {
          "requirement": "Anti-bias evidence",
          "details": "Evidence or lack of anti-bias testing or similar proactive efforts is relevant to a discrimination claim or defense, including the quality, efficacy, recency, scope, results, and response (§ 11009(f))"
        },
        {
          "requirement": "Scope of decisions",
          "details": "Covers recruitment, hiring, promotion, renewal, training, discharge, discipline, tenure, and employment terms"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Existing FEHA enforcement mechanisms"
        }
      ],
      "scope": "employers and other covered entities",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "employer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://calcivilrights.ca.gov/employment/",
        "locator": "2 CCR § 11009(f) (discrimination prohibition); Cal. Gov. Code §§ 12935(a), 12940, 12941 (statutory authority)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ads-employment-bias.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ads-employment-bias-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-10-01",
        "verified": "2026-06-30",
        "checked": "2026-08-21",
        "instrument_last_verified": "2026-08-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ads-employment-records",
      "regulation": "california-ads-employment-regs",
      "name": "Employment Records Retention for ADS",
      "requirements": [
        {
          "requirement": "Records retention",
          "details": "Personnel and other employment records — expressly including selection criteria and automated-decision system data — must be preserved for four years from the date the record was made or the date of the personnel action, whichever is later (§ 11013(c))"
        },
        {
          "requirement": "Complaint preservation",
          "details": "On notice or knowledge that a complaint has been filed, a respondent must preserve all relevant records and files, expressly including automated-decision system data, until the later of expiry of the civil-action filing period or final disposition of the complaint and all related proceedings (§ 11013(c)(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Existing FEHA enforcement mechanisms"
        }
      ],
      "scope": "employers and other covered entities",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "employer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://calcivilrights.ca.gov/employment/",
        "locator": "2 CCR § 11013(c) (four-year preservation of records); 2 CCR § 11013(c)(4) (preservation after a complaint is filed); Cal. Gov. Code §§ 12935(a), 12940, 12941 (statutory authority)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ads-employment-records.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ads-employment-records-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-10-01",
        "verified": "2026-08-25",
        "checked": "2026-08-25",
        "instrument_last_verified": "2026-08-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ai-transparency-act-capture-device",
      "regulation": "california-ai-transparency-act",
      "name": "Capture Device Latent Disclosure",
      "requirements": [
        {
          "requirement": "User option",
          "details": "Provide the user with the option to include a latent disclosure in captured content (§ 22757.3.3(a)(1))"
        },
        {
          "requirement": "Disclosure contents",
          "details": "The latent disclosure conveys the capture device manufacturer's name, the device name and version number, and the time and date of the content's creation or alteration (§ 22757.3.3(a)(1)(A)-(C))"
        },
        {
          "requirement": "Default embedding",
          "details": "Embed latent disclosures in content captured by the device by default (§ 22757.3.3(a)(2))"
        },
        {
          "requirement": "Feasibility limit",
          "details": "Compliance is required only to the extent technically feasible and compliant with widely adopted specifications adopted by an established standards-setting body (§ 22757.3.3(b))"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "$5,000; each day a capture device manufacturer is in violation is a discrete violation (§ 22757.4(a)(1), (b))"
        },
        {
          "violation": "Enforcement",
          "fine": "Civil action by the Attorney General, a city attorney, or a county counsel; prevailing plaintiff recovers reasonable attorney's fees and costs (§ 22757.4(a))"
        }
      ],
      "scope": "Capture device manufacturers, for any capture device first produced for sale in California on or after 2028-01-01; a capture device is any device that records photographs, audio, or video, including cameras, mobile phones with built-in cameras or microphones, and voice recorders (§ 22757.1(c)-(d))",
      "context": "The provenance chain's other end: the rest of the chapter marks content as synthetic, while this section marks content as camera-captured. It reaches hardware manufacturers rather than AI developers, so it lands on companies that may not otherwise track AI regulation — and default-on embedding (subdivision (a)(2)) is a firmware-level design decision with a long lead time.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942",
        "locator": "Cal. Bus. & Prof. Code § 22757.3.3",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ai-transparency-act-capture-device.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ai-transparency-act-capture-device-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2028-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-28",
        "instrument_last_verified": "2026-08-28",
        "instrument_amendments": [
          {
            "date": "2026-09-30",
            "description": "SB 1000 (Ch. 861) removes the covered-provider user threshold and manifest-disclosure option, revises verification tools and licensee remedies, and adds assistive-technology rules; official status records approval and chaptering, while the retrieved Text page still serves the August 30 enrolled version"
          },
          {
            "date": "2025-10-13",
            "description": "AB 853 (Ch. 674) added §§ 22757.3.1-.3.3 (large online platform, GenAI hosting platform, capture device manufacturer duties), pushed the chapter's operative date to 2026-08-02 (§ 22757.6), and expanded enforcement under § 22757.4 to city attorneys and county counsel with prevailing-plaintiff fees"
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ai-transparency-act-platform",
      "regulation": "california-ai-transparency-act",
      "name": "Platform Content Provenance Detection",
      "requirements": [
        {
          "requirement": "Provenance detection",
          "details": "Large online platforms must detect whether content distributed on the platform carries provenance data compliant with widely adopted specifications (§ 22757.3.1)"
        },
        {
          "requirement": "User interface disclosure",
          "details": "Provide a user interface disclosing whether system provenance data is available for the content (§ 22757.3.1)"
        },
        {
          "requirement": "Provenance inspection",
          "details": "Allow users to inspect available system provenance data (§ 22757.3.1)"
        },
        {
          "requirement": "No stripping",
          "details": "Must not strip system provenance data or digital signatures, to the extent technically feasible (§ 22757.3.1)"
        },
        {
          "requirement": "Hosting compliance",
          "details": "GenAI system hosting platforms must not knowingly make available a GenAI system that fails to place the required disclosures (§ 22757.3.2)"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "$5,000; each day in violation is a discrete violation (§ 22757.4(a)(1), (b))"
        },
        {
          "violation": "Enforcement",
          "fine": "Civil action by the Attorney General, a city attorney, or a county counsel; prevailing plaintiff recovers reasonable attorney's fees and costs (§ 22757.4(a))"
        }
      ],
      "scope": "Large online platforms — public-facing social media, file-sharing, mass messaging platforms, or stand-alone search engines distributing content users did not create, exceeding 2,000,000 unique monthly users over the preceding 12 months, excluding broadband internet access services and telecommunications services (§ 22757.1(i)); and GenAI hosting platforms — websites or applications making GenAI source code or model weights available for download to state residents (§ 22757.1(h))",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942",
        "locator": "Cal. Bus. & Prof. Code §§ 22757.3.1, 22757.3.2",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ai-transparency-act-platform.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ai-transparency-act-platform-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-28",
        "instrument_last_verified": "2026-08-28",
        "instrument_amendments": [
          {
            "date": "2026-09-30",
            "description": "SB 1000 (Ch. 861) removes the covered-provider user threshold and manifest-disclosure option, revises verification tools and licensee remedies, and adds assistive-technology rules; official status records approval and chaptering, while the retrieved Text page still serves the August 30 enrolled version"
          },
          {
            "date": "2025-10-13",
            "description": "AB 853 (Ch. 674) added §§ 22757.3.1-.3.3 (large online platform, GenAI hosting platform, capture device manufacturer duties), pushed the chapter's operative date to 2026-08-02 (§ 22757.6), and expanded enforcement under § 22757.4 to city attorneys and county counsel with prevailing-plaintiff fees"
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ai-transparency-act-provenance",
      "regulation": "california-ai-transparency-act",
      "name": "GenAI Content Provenance Disclosure",
      "requirements": [
        {
          "requirement": "Latent disclosure",
          "details": "To the extent technically feasible, include latent disclosure in image, video, audio, or combined content created or altered by the provider's GenAI system, except by minor modification (§ 22757.3(a)); defined minor modifications include brightness, contrast, color, sharpening, saturation, resizing, scaling, cropping, format conversion, and denoising and removal of background noise in audio (§ 22757.1(l))"
        },
        {
          "requirement": "Latent disclosure contents",
          "details": "Convey directly or through a permanent website the provider name, system name/version, creation or alteration time/date, unique identifier, and whether the system created or altered the content; from 2029-01-01 also state whether the system is designed primarily as assistive technology (§ 22757.3(a)(1))"
        },
        {
          "requirement": "Persistence and interoperability",
          "details": "Disclosure must be permanent or extraordinarily difficult to remove or tamper with, compatible with the provider's disclosure verification tool, and compliant or interoperable with widely recognized industry standards (§ 22757.3(a)(2)-(4))"
        },
        {
          "requirement": "Free disclosure verification tool",
          "details": "Provide a free tool assessing whether image, video, audio, or combined content was created or altered, except by minor modification, by the provider's GenAI system; output detected system provenance data (§ 22757.2(a)(1)-(2))"
        },
        {
          "requirement": "Personal-information output",
          "details": "Do not output detected personal information unless the user to whom the personal information pertains expressly consents in clear, conspicuous plain language to including personal information specified by that user in the content, after notice of what may be output and the permanent digital footprint that cannot be retracted from circulated copies (§ 22757.2(a)(3))"
        },
        {
          "requirement": "Tool accessibility",
          "details": "Make the tool publicly accessible subject to reasonable security, integrity, or malicious-misuse limits; accept uploads or URLs; support technology including an API for invocation without visiting the provider's website (§ 22757.2(a)(4)-(6))"
        },
        {
          "requirement": "Feedback loop",
          "details": "Collect efficacy feedback and incorporate relevant feedback into improvement attempts (§ 22757.2(b))"
        },
        {
          "requirement": "Personal-information limits",
          "details": "Do not collect, use, retain, sell, share, or otherwise make available personal information from tool users or processed content beyond what is strictly necessary for compliance, except information used solely to communicate with an opted-in user. Do not condition GenAI system or tool access on information beyond what is strictly necessary (§ 22757.2(c)-(d))"
        },
        {
          "requirement": "Third-party tool option",
          "details": "A third-party tool may satisfy these duties if compliant with § 22757.2, compatible with the provider's latent disclosures, and clearly and conspicuously accessible through its GenAI system interface (§ 22757.2(e))"
        },
        {
          "requirement": "Licensee notification",
          "details": "Notify third-party licensees of their chapter obligations when granting a license (§ 22757.3(b)(1))"
        },
        {
          "requirement": "72-hour response",
          "details": "On knowledge that an identifiable licensee modified a system out of compliance, terminate authorization within 72 hours or notify the licensee within 72 hours of noncompliance and the AG-reporting requirement (§ 22757.3(b)(2))"
        },
        {
          "requirement": "Licensee cure and reporting",
          "details": "A notified licensee must make the system compliant or cease using or making it available, including copies or modifications, and report its chosen action to the provider within 96 hours. The provider must report to the AG if no report arrives or the report indicates neither required action was taken (§ 22757.3(b)(3)-(4))"
        },
        {
          "requirement": "Monitoring limit",
          "details": "The licensee-response subdivision does not require monitoring, investigation, or inquiry into licensee use or modification (§ 22757.3(b)(5))"
        },
        {
          "requirement": "Assistive-technology representation",
          "details": "Do not falsely represent that a GenAI system is designed primarily as assistive technology (§ 22757.3(d)); the chapter's pre-2029 assistive-technology exclusion and temporary separate penalty must be read alongside this prohibition"
        }
      ],
      "penalties": [
        {
          "violation": "General violation",
          "fine": "$5,000 per violation; each day a covered provider, large online platform, or capture device manufacturer violates the chapter is a discrete violation (§ 22757.4(a)-(b))"
        },
        {
          "violation": "Enforcement",
          "fine": "Civil action by the AG, a city attorney, or county counsel; prevailing plaintiff recovers reasonable attorney's costs and fees (§ 22757.4(a))"
        },
        {
          "violation": "Earlier actions",
          "fine": "A civil action brought under § 22757.4 before the amendment's effective date cannot be maintained if the alleged conduct no longer violates the amended chapter (§ 22757.4(c))"
        },
        {
          "violation": "False assistive-technology representation",
          "fine": "Excluded from § 22757.4; temporary § 22757.4.1 provides $50,000 per violation, each day discrete, enforceable by the AG, city attorney, or county counsel with prevailing-plaintiff costs and fees; § 22757.4.1 repeals on 2029-01-01 (§§ 22757.4(d), 22757.4.1)"
        }
      ],
      "scope": "Covered providers: persons creating, coding, or otherwise producing a GenAI system publicly accessible within California, without a monthly-user threshold (§ 22757.1(e)). The chapter excludes products, services, websites, or applications providing exclusively non-user-generated videogames (§ 22757.5(a)); before 2029-01-01 it also excludes GenAI systems designed primarily as assistive technology (§ 22757.5(b)).",
      "context": "SB 1000 was approved and chaptered on 2026-09-30 as Chapter 861. Its urgency clause makes the amendments immediate; the original chapter became operative on 2026-08-02. The October 1 source comparison uses the official approval/chaptering record and August 30 enrolled text still served by the official Text page. A separately published chaptered or consolidated text was not retrieved; no human Verified or Checked date is renewed.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942",
        "locator": "Cal. Bus. & Prof. Code §§ 22757.1-22757.5",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ai-transparency-act-provenance.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ai-transparency-act-provenance-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-08-02",
        "verified": "2026-08-02",
        "checked": "2026-08-28",
        "instrument_last_verified": "2026-08-28",
        "instrument_amendments": [
          {
            "date": "2026-09-30",
            "description": "SB 1000 (Ch. 861) removes the covered-provider user threshold and manifest-disclosure option, revises verification tools and licensee remedies, and adds assistive-technology rules; official status records approval and chaptering, while the retrieved Text page still serves the August 30 enrolled version"
          },
          {
            "date": "2025-10-13",
            "description": "AB 853 (Ch. 674) added §§ 22757.3.1-.3.3 (large online platform, GenAI hosting platform, capture device manufacturer duties), pushed the chapter's operative date to 2026-08-02 (§ 22757.6), and expanded enforcement under § 22757.4 to city attorneys and county counsel with prevailing-plaintiff fees"
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ccpa-admt-risk-assessment",
      "regulation": "california-ccpa-admt",
      "name": "ADMT Risk Assessment",
      "requirements": [
        {
          "requirement": "Pre-processing assessment",
          "details": "Risk assessment required before initiating covered processing, including ADMT for significant decisions (§ 7155(a)(1), referring to § 7150(b)); contents governed by § 7152"
        },
        {
          "requirement": "Assessment review and approval",
          "details": "Document the assessment review/approval date and reviewers; an individual authorized to participate in deciding whether processing begins must review and approve the assessment (§ 7152(a)(9)); legal counsel providing legal advice need not be named"
        },
        {
          "requirement": "Triennial review",
          "details": "Review at least every 3 years and update as necessary; material-change updates as soon as feasibly possible and no later than 45 calendar days (§ 7155(a)(2)-(3))"
        },
        {
          "requirement": "Retention",
          "details": "Retain original and updated assessments while processing continues or for 5 years after completion of the risk assessment, whichever is later (§ 7155(c))"
        },
        {
          "requirement": "Submission to CPPA",
          "details": "Risk assessment information, including attestation, submitted to CPPA by April 1, 2028 for 2026-2027 assessments; after 2027, by April 1 following each assessment year (§ 7157(a)-(b)). Assessment reports must separately be produced to CPPA or the Attorney General within 30 calendar days of a request (§ 7157(e))"
        },
        {
          "requirement": "Pre-2026 activities",
          "details": "Covered processing initiated before January 1, 2026 and continuing after that date must be assessed by December 31, 2027 (§ 7155(b))"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "Up to $2,663 per violation; $7,988 for intentional violations or violations involving personal information known to concern consumers under 16 (CPI adjustment effective January 1, 2025)"
        }
      ],
      "scope": "Businesses using ADMT to make a **significant decision** concerning a consumer. \"Significant decision\" means one resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services (11 CCR § 7001(ddd)). Each domain is defined in turn: housing excludes decisions based solely on availability, vacancy, or receipt of payment (§ 7001(ddd)(2)); education covers admission, credentials, and suspension or expulsion (§ 7001(ddd)(3)); employment covers hiring, work allocation and compensation, promotion, and demotion, suspension or termination (§ 7001(ddd)(4)). Advertising to a consumer is expressly not a significant decision (§ 7001(ddd)(6))",
      "context": null,
      "instrument_notes": "Package and Article 10 assessment requirements begin 2026-01-01; Article 11 ADMT consumer-rights compliance begins 2027-01-01. Covered processing begun before 2026 and continuing afterward has a 2027-12-31 assessment deadline; first general assessment-information submission is due 2028-04-01 for 2026-2027 assessments. These are distinct clocks, not a universal January 2027 grace period.",
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cppa.ca.gov/regulations/",
        "locator": "11 CCR §§ 7150–7157",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ccpa-admt-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ccpa-admt-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-04-27",
        "checked": "2026-08-13",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-ccpa-admt-transparency",
      "regulation": "california-ccpa-admt",
      "name": "Consumer Transparency for ADMT",
      "requirements": [
        {
          "requirement": "Pre-use notice",
          "details": "Conspicuous notice before ADMT use describing purpose, how it works, outputs, and available consumer rights (§ 7220)"
        },
        {
          "requirement": "Opt-out right",
          "details": "Consumers may opt out of ADMT used to make significant decisions, subject to the exceptions in § 7221(b). A business that interacts with consumers online and provides an opt-out must include an opt-out link in the Pre-use Notice (§ 7221(a)-(c))"
        },
        {
          "requirement": "Access right",
          "details": "Consumers may request information about the business's use of ADMT with respect to them (§ 7222)"
        },
        {
          "requirement": "Human appeal exception",
          "details": "A business may use the § 7221(b)(1) exception to the opt-out duty if it provides a qualifying method to appeal the significant decision to a human reviewer with authority to overturn it; the Pre-use Notice must then explain how to appeal (§§ 7220(c)(2)(A), 7221(b)(1))"
        },
        {
          "requirement": "No retaliation",
          "details": "Business may not retaliate against consumer for exercising ADMT rights"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "Up to $2,663 per violation; $7,988 for intentional violations or violations involving personal information known to concern consumers under 16 (CPI adjustment effective January 1, 2025)"
        }
      ],
      "scope": "Businesses using ADMT to make a **significant decision** concerning a consumer. \"Significant decision\" means one resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services (11 CCR § 7001(ddd)). Each domain is defined in turn: housing excludes decisions based solely on availability, vacancy, or receipt of payment (§ 7001(ddd)(2)); education covers admission, credentials, and suspension or expulsion (§ 7001(ddd)(3)); employment covers hiring, work allocation and compensation, promotion, and demotion, suspension or termination (§ 7001(ddd)(4)). Advertising to a consumer is expressly not a significant decision (§ 7001(ddd)(6))",
      "context": null,
      "instrument_notes": "Package and Article 10 assessment requirements begin 2026-01-01; Article 11 ADMT consumer-rights compliance begins 2027-01-01. Covered processing begun before 2026 and continuing afterward has a 2027-12-31 assessment deadline; first general assessment-information submission is due 2028-04-01 for 2026-2027 assessments. These are distinct clocks, not a universal January 2027 grace period.",
      "roles": [
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://cppa.ca.gov/regulations/",
        "locator": "11 CCR §§ 7220–7222",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-ccpa-admt-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-ccpa-admt-transparency.json",
          "https://everyailaw.com/obligation/california-ccpa-admt-transparency-explainability.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-04-27",
        "checked": "2026-08-23",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-sb1120-physician-supervision",
      "regulation": "california-sb1120",
      "name": "Physician Supervision of AI",
      "requirements": [
        {
          "requirement": "Licensed clinical decision maker",
          "details": "A medical-necessity determination must be made only by a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues involved. The decision maker must review and consider the requesting provider's recommendation, the enrollee's or insured's medical or other clinical history as applicable, and individual clinical circumstances (§ 1367.01(k)(2); Ins. Code § 10123.135(j)(2))"
        },
        {
          "requirement": "Tool may not make adverse medical-necessity decision",
          "details": "The artificial intelligence, algorithm, or other software tool shall not deny, delay, or modify health care services based in whole or part on medical necessity (§ 1367.01(k)(2); Ins. Code § 10123.135(j)(2))"
        },
        {
          "requirement": "Clinical basis and no group-only basis",
          "details": "As applicable, the tool must base its determination on the enrollee's or insured's medical or clinical history, individual clinical circumstances presented by the requesting provider, and other relevant clinical-record information; it does not base its determination solely on a group dataset"
        },
        {
          "requirement": "Legal criteria and non-supplanting",
          "details": "Tool criteria and guidelines must comply with the governing code and applicable state and federal law, and the tool must not supplant health care provider decision-making"
        },
        {
          "requirement": "Nondiscrimination and equitable application",
          "details": "Tool use must not directly or indirectly discriminate in violation of state or federal law and must be fairly and equitably applied, including under applicable federal Department of Health and Human Services regulations and guidance"
        },
        {
          "requirement": "Auditability and written oversight",
          "details": "The tool must be open to inspection for audit or compliance review; disclosures about its use and oversight must appear in the required written policies and procedures"
        },
        {
          "requirement": "Performance review",
          "details": "Tool performance, use, and outcomes must be periodically reviewed and revised to maximize accuracy and reliability"
        },
        {
          "requirement": "Patient-data purpose limit",
          "details": "Patient data may not be used beyond its intended and stated purpose, consistent with the Confidentiality of Medical Information Act and HIPAA as applicable"
        },
        {
          "requirement": "No direct or indirect harm",
          "details": "The tool does not directly or indirectly cause harm to the enrollee or insured"
        },
        {
          "requirement": "Covered review timing",
          "details": "The AI-specific subdivision applies to utilization review or utilization management functions that prospectively, retrospectively, or concurrently review covered-service requests"
        },
        {
          "requirement": "Federal guidance",
          "details": "Covered plans and disability insurers must comply with applicable federal Department of Health and Human Services rules and guidance on AI, algorithms, or other software tools"
        },
        {
          "requirement": "Medi-Cal managed care qualification, plans only",
          "details": "Health and Safety Code § 1367.01(k) applies to a Medi-Cal managed care plan only to the extent the State Department of Health Care Services obtains necessary federal approvals and federal financial participation is not otherwise jeopardized (§ 1367.01(k)(7)); the parallel Insurance Code section has no such clause"
        },
        {
          "requirement": "Religious-care exception, plans only",
          "details": "Health and Safety Code § 1367.01 does not apply to decisions for the care or treatment of the sick who depend on prayer or spiritual means for healing in the practice of religion described by § 1270(a) (§ 1367.01(m)); the parallel Insurance Code section has no such clause"
        }
      ],
      "penalties": [
        {
          "violation": "Health care service plan failure",
          "fine": "Department of Managed Health Care director may order an administrative penalty for each failure, after appropriate notice and an opportunity for hearing; the penalty is not the director's exclusive remedy (§ 1367.01(h)(6))"
        },
        {
          "violation": "Disability insurer failure",
          "fine": "Insurance Commissioner may order an administrative penalty for each failure, after appropriate notice and an opportunity for hearing; the penalty is not the commissioner's exclusive remedy (Ins. Code § 10123.135(h)(6))"
        }
      ],
      "scope": "Health care service plans and disability insurers, including specialized plans and insurers, that use AI, an algorithm, or another software tool for utilization review or utilization management based in whole or part on medical necessity, or contract with or otherwise work through an entity that does so. The AI-specific rules cover prospective, retrospective, and concurrent review of covered-service requests. For health care service plans only, § 1367.01(k)(7) conditions application to a Medi-Cal managed care plan on necessary federal approvals and no jeopardy to federal financial participation, and § 1367.01(m) excludes the specified religious prayer or spiritual-healing care decisions; those provisions do not appear in Insurance Code § 10123.135",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "insurer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1120",
        "locator": "Health and Safety Code § 1367.01; Insurance Code § 10123.135",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-sb1120-physician-supervision.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-sb1120-physician-supervision-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-01-01",
        "verified": "2026-04-27",
        "checked": "2026-08-18",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-sb243-crisis-protocol",
      "regulation": "california-sb243",
      "name": "Self-Harm Crisis Protocol",
      "requirements": [
        {
          "requirement": "Protocol as a precondition",
          "details": "Prevent the companion chatbot from engaging with users unless the operator maintains a protocol for preventing the production of suicidal ideation, suicide, or self-harm content (§ 22602(b)(1))"
        },
        {
          "requirement": "Crisis referral",
          "details": "The protocol must include notifying a user who expresses suicidal ideation, suicide, or self-harm and referring them to crisis service providers, including a suicide hotline or crisis text line (§ 22602(b)(1))"
        },
        {
          "requirement": "Publication",
          "details": "Publish details of the protocol on the operator's internet website (§ 22602(b)(2))"
        },
        {
          "requirement": "Minor sexual content",
          "details": "For a user known to be a minor, institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct (§ 22602(c)(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Private right of action",
          "fine": "Injunctive relief, the greater of actual damages or $1,000 per violation, plus reasonable attorney's fees and costs (§ 22605)"
        }
      ],
      "scope": "Operators of companion chatbot platforms made available to users in California (§ 22601(e))",
      "context": "The duty is structured as a gate: without the protocol, the operator must prevent the chatbot from engaging with users. The operator must publish details of the protocol, not necessarily the full internal document (§ 22602(b)(2)).",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243",
        "locator": "Cal. Bus. & Prof. Code § 22602(b), § 22602(c)(3)",
        "citation": "Cal. Bus. & Prof. Code §§ 22601-22606 (Ch. 677, Stats. 2025)"
      },
      "of": {
        "term": "https://everyailaw.com/term/california-sb243-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-sb243-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-sb243-disclosure",
      "regulation": "california-sb243",
      "name": "Companion Chatbot Disclosure",
      "requirements": [
        {
          "requirement": "Artificiality notice",
          "details": "Where a reasonable person interacting with the companion chatbot would be misled into believing they are interacting with a human, issue a clear and conspicuous notification that the chatbot is artificially generated and not human (§ 22602(a))"
        },
        {
          "requirement": "Minor disclosure",
          "details": "For a user the operator knows is a minor, disclose that the user is interacting with artificial intelligence (§ 22602(c)(1))"
        },
        {
          "requirement": "Three-hour break reminder",
          "details": "For known minors, provide by default a clear and conspicuous notification at least every three hours during continuing interactions, reminding the user to take a break and that the chatbot is artificially generated and not human (§ 22602(c)(2))"
        },
        {
          "requirement": "Suitability disclosure",
          "details": "Disclose on the application, browser, or any other access format that companion chatbots may not be suitable for some minors (§ 22604)"
        }
      ],
      "penalties": [
        {
          "violation": "Private right of action",
          "fine": "A person who suffers injury in fact may sue for injunctive relief, damages of the greater of actual damages or $1,000 per violation, and reasonable attorney's fees and costs (§ 22605)"
        },
        {
          "violation": "Cumulative liability",
          "fine": "The duties and remedies are cumulative to those imposed under other law and do not relieve an operator of any other obligation (§ 22606)"
        }
      ],
      "scope": "Operators — persons who make a companion chatbot platform available to a user in California, where a companion chatbot is an AI system with a natural language interface giving adaptive, human-like responses capable of meeting a user's social needs and sustaining a relationship across interactions; customer-service and operational bots, video-game bots confined to game topics, and voice-assistant speaker devices are excluded (§ 22601(b))",
      "context": "For an operator of a companion chatbot platform within § 22601(b) and (e), the artificiality-notice duty uses a reasonable-person test. Section 22601(b)(2) excludes specified customer-service, video-game, and voice-assistant interactions. The three-hour break reminder for known minors also constrains session flow.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243",
        "locator": "Cal. Bus. & Prof. Code §§ 22601, 22602(a), 22602(c)(1)-(2), 22604",
        "citation": "Cal. Bus. & Prof. Code §§ 22601-22606 (Ch. 677, Stats. 2025)"
      },
      "of": {
        "term": "https://everyailaw.com/term/california-sb243-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-sb243-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-sb243-reporting",
      "regulation": "california-sb243",
      "name": "Annual Crisis Referral Reporting",
      "requirements": [
        {
          "requirement": "Annual report",
          "details": "Beginning 2027-07-01, report annually to the Office of Suicide Prevention (§ 22603(a))"
        },
        {
          "requirement": "Referral counts",
          "details": "Report the number of crisis service provider referral notifications issued under § 22602 in the preceding calendar year (§ 22603(a)(1))"
        },
        {
          "requirement": "Detection protocols",
          "details": "Report the protocols in place to detect, remove, and respond to instances of suicidal ideation by users (§ 22603(a)(2))"
        },
        {
          "requirement": "Response prohibition protocols",
          "details": "Report the protocols in place to prohibit a companion chatbot response about suicidal ideation or actions with the user (§ 22603(a)(3))"
        },
        {
          "requirement": "No personal data",
          "details": "The report must contain only the listed information and no identifiers or personal information about users (§ 22603(b))"
        },
        {
          "requirement": "Evidence-based measurement",
          "details": "Use evidence-based methods for measuring suicidal ideation (§ 22603(d))"
        }
      ],
      "penalties": [
        {
          "violation": "Private right of action",
          "fine": "Injunctive relief, the greater of actual damages or $1,000 per violation, plus reasonable attorney's fees and costs (§ 22605)"
        }
      ],
      "scope": "Operators of companion chatbot platforms made available to users in California (§ 22601(e))",
      "context": "Reporting runs to a public-health body rather than a regulator, and the Office must publish the data, so the reports become a public dataset on how often companion chatbots encounter user self-harm. The § 22603(d) requirement to use evidence-based measurement methods means the counting methodology is itself regulated.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243",
        "locator": "Cal. Bus. & Prof. Code § 22603",
        "citation": "Cal. Bus. & Prof. Code §§ 22601-22606 (Ch. 677, Stats. 2025)"
      },
      "of": {
        "term": "https://everyailaw.com/term/california-sb243-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-sb243-reporting-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-sb53-incident-reporting",
      "regulation": "california-sb53",
      "name": "Incident Reporting",
      "requirements": [
        {
          "requirement": "15-day OES report",
          "details": "Report critical safety incidents to OES within 15 days of discovery (§ 22757.13(c)(1))"
        },
        {
          "requirement": "24-hour imminent-risk report",
          "details": "If an incident poses an imminent risk of death or serious physical injury, disclose it within 24 hours to an authority appropriate to the nature of the incident, including a law enforcement or public safety agency with jurisdiction (§ 22757.13(c)(2))"
        },
        {
          "requirement": "OES reporting mechanism",
          "details": "OES must establish a mechanism for frontier developers and the public to report critical safety incidents (§ 22757.13(a))"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "Up to $1M"
        }
      ],
      "scope": "frontier developers (models trained with > 10^26 operations)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legiscan.com/CA/text/SB53/id/3270002",
        "locator": "Bus. & Prof. Code § 22757.13",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-sb53-incident-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-sb53-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "california-sb53-transparency",
      "regulation": "california-sb53",
      "name": "Frontier AI Framework Publication",
      "requirements": [
        {
          "requirement": "Publish frontier AI framework",
          "details": "LFDs must write, implement, and clearly publish a frontier AI framework covering governance structures, catastrophic risk mitigation, cybersecurity practices, and standards alignment (§ 22757.12)"
        },
        {
          "requirement": "Annual review",
          "details": "Review the framework at least annually and update it as appropriate (§ 22757.12(b)(1))"
        },
        {
          "requirement": "Material modification",
          "details": "Publish a materially modified framework and a justification for the modification within 30 days (§ 22757.12(b)(2))"
        },
        {
          "requirement": "Model transparency reports",
          "details": "Before or when deploying a new or substantially modified frontier model, publish the model information required by § 22757.12(c); large frontier developers must also publish summaries of catastrophic-risk assessments, results, third-party evaluator involvement, and framework implementation steps"
        },
        {
          "requirement": "Internal-use risk summaries",
          "details": "Large frontier developers must transmit summaries of catastrophic-risk assessments from internal model use to OES every three months, or on another reasonable schedule communicated in writing (§ 22757.12(d))"
        },
        {
          "requirement": "Redaction allowance",
          "details": "Frontier developers may make necessary redactions to protect trade secrets, cybersecurity, public safety, or national security, or comply with law; describe their character and justification as permitted and retain unredacted information for five years (§ 22757.12(f))"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "Up to $1M"
        }
      ],
      "scope": "Large frontier developers (annual gross revenue > $500M) for the framework, added risk summaries, and added transparency report content; all frontier developers for the basic model transparency report (§ 22757.12(c)(1))",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legiscan.com/CA/text/SB53/id/3270002",
        "locator": "Bus. & Prof. Code § 22757.12",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/california-sb53-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/california-sb53-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-04-27",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cms-medicare-clinician-oversight",
      "regulation": "cms-medicare-advantage",
      "name": "Clinician Oversight Mandate",
      "requirements": [
        {
          "requirement": "No sole reliance on AI",
          "details": "Population-level algorithms or predictions alone cannot replace individual medical-necessity criteria; AI alone cannot deny an inpatient admission, downgrade it to observation, or terminate post-acute care on predicted length of stay (CMS FAQ, Question 2)"
        },
        {
          "requirement": "Individual circumstances",
          "details": "Coverage decisions must rely on individual patient history and circumstances, not population-level algorithms alone"
        },
        {
          "requirement": "No alteration of public criteria",
          "details": "AI tools may not alter publicly available coverage criteria"
        },
        {
          "requirement": "Individualized post-acute reassessment",
          "details": "A predicted length of stay alone cannot support termination. Reassess the patient's individual condition and confirm that the level-of-care requirements are no longer met before issuing a termination notice (CMS FAQ, Question 2)"
        },
        {
          "requirement": "Tool vetting",
          "details": "MA plans remain responsible for ensuring AI/algorithmic tools are used consistently with coverage criteria and applicable law; CMS guidance does not specify a standalone mandated audit requirement"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "CMS enforcement; potential plan sanctions"
        }
      ],
      "scope": "Medicare Advantage organizations and plans",
      "context": "FAQ guidance (CMS memo, Feb 6, 2024) interpreting the 2024 MA final rule (CMS-4201-F); not a standalone AI-specific rule. The stored provision heading is a catalog label; the FAQ requires individual medical-necessity review, not a categorical clinician-final-approval step.",
      "instrument_notes": null,
      "roles": [
        "insurer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://federalregister.gov/documents/2023/04/12/2023-07115/medicare-program",
        "locator": "CMS-4201-F (42 CFR Parts 417, 422, 423, 460)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cms-medicare-clinician-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/cms-medicare-clinician-oversight-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-01-01",
        "verified": "2026-06-30",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-ai-content-labeling-conformity-assessment",
      "regulation": "cn-ai-content-labeling",
      "name": "Platform Label Verification",
      "requirements": [
        {
          "requirement": "Verify metadata",
          "details": "Dissemination platforms must check whether file metadata contains an implicit label; where the metadata clearly marks content as generated, add a conspicuous prompt around the published content stating plainly that it is generated content (Article 6(1))"
        },
        {
          "requirement": "Handle user declarations",
          "details": "Where no implicit label is found but the user has declared the content as generated, add a conspicuous prompt stating the content **may be** generated (Article 6(2))"
        },
        {
          "requirement": "Detect suspected content",
          "details": "Where there is neither an implicit label nor a user declaration, but the platform detects an explicit label or other traces of generation, classify it as **suspected** generated content and add a conspicuous prompt saying so (Article 6(3))"
        },
        {
          "requirement": "Provide labeling function",
          "details": "Provide the necessary labeling function and prompt users to proactively declare whether published content contains generated content (Article 6(4))"
        },
        {
          "requirement": "App store listing check",
          "details": "At listing or launch review, app distribution platforms must require the app provider to state whether it offers AI generation or synthesis services, and where it does, must verify the provider's content-labeling materials (Article 7)"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the Measures",
          "remedy": "No standalone penalty schedule; handled by the cyberspace, telecommunications, public security, and radio and television authorities under existing law (Article 13)"
        }
      ],
      "scope": "Providers of network information content dissemination services, and internet application distribution platforms (app stores)",
      "context": "The compliance dimension the Deep Synthesis Provisions do not have: duties that bind actors who never generated the content. Article 6 makes every covered network-information-content dissemination-service provider a verifier with a three-tier response, and Article 7 adds an app-store listing check.",
      "instrument_notes": null,
      "roles": [
        "deployer",
        "distributor"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "locator": "Articles 6, 7",
        "citation": "国信办通字〔2025〕2号"
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-ai-content-labeling-conformity-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-ai-content-labeling-conformity-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-09-01",
        "verified": "2026-08-20",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-08-20",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-ai-content-labeling-record-keeping",
      "regulation": "cn-ai-content-labeling",
      "name": "Implicit Metadata Labels and Provenance Records",
      "requirements": [
        {
          "requirement": "Implicit metadata label",
          "details": "Add an implicit label to the file metadata of generated content as required by Article 16 of the Deep Synthesis Provisions, containing content attribute information, the provider's name or code, and a content number (Article 5, first paragraph)"
        },
        {
          "requirement": "Digital watermarking",
          "details": "Providers are encouraged, not required, to add implicit labels in the form of digital watermarks (Article 5, second paragraph)"
        },
        {
          "requirement": "Dissemination metadata",
          "details": "Where a dissemination platform applies a prompt label under Article 6(1)-(3), it must also write content attribute information, the platform name or code, and a content number into the file metadata (Article 6, second paragraph)"
        },
        {
          "requirement": "Delivery without an explicit label",
          "details": "On user request, a provider may deliver generated content without an explicit label after the user agreement specifies the user's labeling obligations and use responsibilities; retain recipient information and related logs for **not less than six months** (Article 9)"
        },
        {
          "requirement": "Filing materials",
          "details": "Submit labeling materials when completing algorithm filing and security assessment formalities, and strengthen sharing of labeling information to support the prevention and investigation of related offences (Article 12)"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the Measures",
          "remedy": "No standalone penalty schedule; handled by the cyberspace, telecommunications, public security, and radio and television authorities under existing law (Article 13)"
        }
      ],
      "scope": "Providers of generative and deep synthesis services, and providers of network information content dissemination services",
      "context": "Article 5 specifies the implicit metadata elements for covered generated content under Article 16 of the Deep Synthesis Provisions: content attribute information, provider name or code, and content number. Article 9 permits delivery without an explicit label on user request after the user agreement allocates labeling and use responsibilities; the provider must retain recipient information and related logs for at least six months.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "locator": "Articles 5, 6 (second paragraph), 9, 12",
        "citation": "国信办通字〔2025〕2号"
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-ai-content-labeling-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-ai-content-labeling-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-09-01",
        "verified": "2026-08-20",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-08-20",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-ai-content-labeling-transparency",
      "regulation": "cn-ai-content-labeling",
      "name": "AI Content Labeling Disclosure",
      "requirements": [
        {
          "requirement": "Text explicit label",
          "details": "Add a textual or common-symbol prompt at the start, end, or an appropriate interior position of the text, or a conspicuous prompt in the interaction interface or around the text (Article 4(1))"
        },
        {
          "requirement": "Audio explicit label",
          "details": "Add a voice or rhythm-cue prompt at the start, end, or an appropriate interior position of the audio, or a conspicuous prompt in the interaction interface (Article 4(2))"
        },
        {
          "requirement": "Image explicit label",
          "details": "Add a conspicuous prompt label at an appropriate position in the image (Article 4(3))"
        },
        {
          "requirement": "Video explicit label",
          "details": "Add a conspicuous prompt at the opening frame and around the playback area; optionally also at the end and at appropriate interior positions (Article 4(4))"
        },
        {
          "requirement": "Virtual scene explicit label",
          "details": "Add a conspicuous prompt at an appropriate position in the opening frame; optionally also at appropriate points during continuing service (Article 4(5))"
        },
        {
          "requirement": "Label survives export",
          "details": "When offering download, copy, or export, ensure the resulting file still carries a conforming explicit label (Article 4, second paragraph)"
        },
        {
          "requirement": "User-requested unmarked delivery",
          "details": "A provider may supply generated content without an explicit label on user request after specifying the user's labeling obligations and use responsibilities in the user agreement; retain recipient information and related logs for at least six months (Article 9)"
        },
        {
          "requirement": "Service agreement disclosure",
          "details": "State the labeling methods and styles in the user service agreement and prompt users to read and understand the labeling requirements (Article 8)"
        },
        {
          "requirement": "User declaration duty",
          "details": "Users publishing generated content through a dissemination service must proactively declare it and use the labeling function the provider supplies (Article 10, first paragraph)"
        },
        {
          "requirement": "Anti-tampering prohibition",
          "details": "No organization or individual may maliciously delete, alter, forge, or conceal a label, provide tools or services for others to do so, or harm others' lawful rights through improper labeling (Article 10, second paragraph)"
        },
        {
          "requirement": "Standards conformity",
          "details": "Labeling activity must also satisfy applicable laws, administrative regulations, departmental rules, and mandatory national standards — in practice GB 45438-2025 (Article 11)"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the Measures",
          "remedy": "No standalone penalty schedule. Article 13 directs the cyberspace, telecommunications, public security, and radio and television authorities to handle violations according to their respective duties under applicable laws, administrative regulations, and departmental rules — principally the Cybersecurity Law, the Deep Synthesis Provisions, and the Interim Measures for Generative AI"
        }
      ],
      "scope": "Providers of generative and deep synthesis services falling within Article 17(1) of the Deep Synthesis Provisions, and users publishing generated content through dissemination services",
      "context": "Article 4 requires explicit labels for generative and deep-synthesis services within the specified Deep Synthesis Provisions Article 17(1) scenarios. Article 9 permits delivery without an explicit label on user request if the provider allocates labeling duties and use responsibilities in the user agreement and retains recipient information and related logs for at least six months. Article 10 extends the anti-tampering prohibition to **any organization or individual**, including providers of label-removal tools or services.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "locator": "Articles 4, 8-11",
        "citation": "国信办通字〔2025〕2号"
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-ai-content-labeling-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-ai-content-labeling-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-09-01",
        "verified": "2026-08-20",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-08-20",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-algorithm-recommendation-risk",
      "regulation": "cn-algorithm-recommendation",
      "name": "Algorithmic Risk Assessment",
      "requirements": [
        {
          "requirement": "Periodic review",
          "details": "Must periodically review, evaluate, and verify algorithms, models, data, and outcomes (Art. 8)"
        },
        {
          "requirement": "Security governance and content handling",
          "details": "Maintain security assessment and monitoring plus incident-response systems (Art. 7); maintain an illegal/undesirable-content feature database, stop and report illegal information, and handle undesirable information under the prescribed content-governance rules (Art. 9)"
        },
        {
          "requirement": "User controls",
          "details": "Provide users either a non-personalized option or a convenient option to turn off algorithmic recommendations (Art. 17)"
        },
        {
          "requirement": "Filing and security assessment",
          "details": "Providers with public-opinion properties or social-mobilization capabilities must file with an algorithm self-assessment report (Art. 24) and separately conduct a security assessment under applicable national rules (Art. 27)"
        }
      ],
      "penalties": [
        {
          "violation": "Listed governance, review, and filing violations",
          "fine": "Where no other law or administrative regulation governs, Article 31 provides warnings, circulated criticism, correction orders, and, for refusal to correct or serious violations, suspended updates and an RMB 10,000-100,000 fine"
        },
        {
          "violation": "Security-assessment and special filing violations",
          "fine": "Article 32 routes Article 27 violations to applicable law; Article 33 addresses fraudulent filing and cancellation failures, not every risk-assessment breach"
        }
      ],
      "scope": "Providers using algorithmic recommendation technology to offer internet information services within China (Articles 2-3)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
        "locator": "Articles 7-9, 17, 24, 27, 31-33",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-algorithm-recommendation-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-algorithm-recommendation-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2022-03-01",
        "verified": "2026-06-30",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-algorithm-recommendation-transparency",
      "regulation": "cn-algorithm-recommendation",
      "name": "Algorithm Filing and Registration",
      "requirements": [
        {
          "requirement": "Algorithm filing",
          "details": "Providers with public-opinion properties or social-mobilization capabilities must file within ten working days after starting service, including an algorithm self-assessment report (Art. 24)"
        },
        {
          "requirement": "Public disclosure",
          "details": "Disclose the service's basic principles, purposes, and main operating mechanisms to users (Art. 16)"
        },
        {
          "requirement": "User controls",
          "details": "Provide users either a non-personalized option or a convenient option to turn off algorithmic recommendations (Art. 17)"
        },
        {
          "requirement": "Filing number disclosure",
          "details": "A provider that has completed filing must display its filing number and a public-information link on its service website or app (Art. 26)"
        }
      ],
      "penalties": [
        {
          "violation": "Listed disclosure, control, and filing violations",
          "fine": "Where no other law or administrative regulation governs, warnings, circulated criticism, and correction orders; refusal to correct or a serious violation can lead to suspended information updates and an RMB 10,000-100,000 fine (Art. 31)"
        },
        {
          "violation": "Filing by concealment or false materials; cancellation failure",
          "fine": "Article 33 provides filing cancellation or revocation and specified administrative measures; serious fraudulent filing can also lead to suspended updates and an RMB 10,000-100,000 fine"
        }
      ],
      "scope": "Providers using algorithmic recommendation technology to offer internet information services within China under Article 2; filing and security assessment additionally apply to providers with public-opinion properties or social-mobilization capabilities",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
        "locator": "Articles 16-17, 24, 26-27, 31-33",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-algorithm-recommendation-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-algorithm-recommendation-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2022-03-01",
        "verified": "2026-06-30",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-deep-synthesis-record-keeping",
      "regulation": "cn-deep-synthesis",
      "name": "Deep Synthesis Record-Keeping",
      "requirements": [
        {
          "requirement": "Network logs",
          "details": "Record and retain relevant network logs for prohibited-content detection (Art. 10); retain log information for generated or edited content under applicable laws and regulations (Art. 16)"
        },
        {
          "requirement": "User identity",
          "details": "Authenticate users' real identity by the listed methods; do not provide information-publishing services to unauthenticated users (Art. 9)"
        },
        {
          "requirement": "Incident records",
          "details": "Preserve records when prohibited or harmful information is found (Art. 10), and when false information is found and debunked (Art. 11); this rule sets no universal log-retention period"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Article 22 routes penalties to applicable laws and administrative regulations; it sets no standalone warning or fine schedule. Article 21 permits specified temporary service measures and rectification when authorities find a major information-security risk"
        }
      ],
      "scope": "Deep synthesis service providers offering internet information services within China (Article 2); Articles 21-22 separately cover technical supporters for inspection cooperation and liability",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2022-12/11/c_1672221949354811.htm",
        "locator": "Articles 9-11, 16, 21-22",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-deep-synthesis-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-deep-synthesis-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-01-10",
        "verified": "2026-06-30",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-deep-synthesis-transparency",
      "regulation": "cn-deep-synthesis",
      "name": "Deep Synthesis Content Labeling",
      "requirements": [
        {
          "requirement": "Technical marking and logs",
          "details": "Apply a technical mark to content generated or edited through the service that does not affect user use, and preserve logs under applicable law (Art. 16)"
        },
        {
          "requirement": "Conspicuous labeling",
          "details": "Conspicuously label the listed Article 17 service outputs when they may cause public confusion or misrecognition"
        },
        {
          "requirement": "Labeling function for other services",
          "details": "For deep synthesis services outside Article 17's listed scenarios, provide a conspicuous-labeling function and prompt users that they may apply it (Art. 17)"
        },
        {
          "requirement": "Label integrity",
          "details": "No organization or individual may technically delete, alter, or conceal marks required by Articles 16-17 (Art. 18)"
        }
      ],
      "penalties": [
        {
          "violation": "Violations of the Provisions",
          "fine": "Article 22 routes penalties to applicable laws and administrative regulations; it sets no standalone fine schedule. Article 21 separately permits specified temporary service measures for serious information-security risk"
        }
      ],
      "scope": "Deep synthesis service providers offering internet information services within China (Article 2) have the Article 16-17 marking duties; Article 18's label-integrity prohibition applies to any organization or individual",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2022-12/11/c_1672221949354811.htm",
        "locator": "Articles 16-18",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-deep-synthesis-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-deep-synthesis-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-01-10",
        "verified": "2026-03-26",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-generative-ai-incident",
      "regulation": "cn-generative-ai",
      "name": "Generative AI Incident Response",
      "requirements": [
        {
          "requirement": "Illegal content response",
          "details": "On discovering illegal content, take timely measures including stopping generation and transmission and eliminating the content as applicable, rectify through measures such as model optimization, and report to the competent departments"
        },
        {
          "requirement": "Unlawful user activity",
          "details": "On discovering unlawful use, take lawful and contractual measures such as warning, restricting functions, suspending or terminating service; preserve records and report to the competent departments"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Article 21 applies relevant-law penalties or, where none is specified, warning, criticism and correction; suspension requires refusal to correct or serious circumstances. Criminal liability applies only when conduct constitutes a crime"
        }
      ],
      "scope": "Providers offering generative AI services to the public within China that discover illegal content or unlawful user activity (Articles 2, 14)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2023-07/13/c_1690898327029107.htm",
        "locator": "Article 14",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-generative-ai-incident.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-generative-ai-incident-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-08-15",
        "verified": "2026-06-30",
        "checked": "2026-08-07",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-generative-ai-risk",
      "regulation": "cn-generative-ai",
      "name": "Generative AI Risk Assessment",
      "requirements": [
        {
          "requirement": "Security assessment and filing",
          "details": "Providers of services with public-opinion properties or social-mobilization capability must conduct a security assessment and complete algorithm filing under applicable rules (Art. 17)"
        },
        {
          "requirement": "Training data compliance",
          "details": "Providers must lawfully process training data, respect intellectual property and personal information rights, and take measures to improve data quality (Art. 7)"
        },
        {
          "requirement": "Data-labeling governance",
          "details": "Providers that label data during development must establish labeling rules, assess quality, sample-check accuracy and train and supervise labelers (Art. 8)"
        },
        {
          "requirement": "Cooperation with inspections",
          "details": "Providers must cooperate with lawful supervision and explain specified training-data and algorithm matters and provide needed support (Art. 19)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Article 21 applies relevant-law penalties or, where none is specified, warning, criticism and correction; suspension requires refusal to correct or serious circumstances. Criminal liability applies only when conduct constitutes a crime"
        }
      ],
      "scope": "Providers offering generative AI services to the public within China; research, development, and internal non-public uses are outside Article 2",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2023-07/13/c_1690898327029107.htm",
        "locator": "Articles 7-8, 17, 19",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-generative-ai-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-generative-ai-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-08-15",
        "verified": "2026-06-30",
        "checked": "2026-08-04",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "cn-generative-ai-transparency",
      "regulation": "cn-generative-ai",
      "name": "Generative AI Content Compliance",
      "requirements": [
        {
          "requirement": "Content labeling",
          "details": "Label generated images, videos and other covered content under the Deep Synthesis Provisions (Art. 12); this article does not impose an all-output label"
        },
        {
          "requirement": "Content compliance",
          "details": "Providers and users must observe Article 4's content rules; providers bear online-information-content duties under Article 9"
        },
        {
          "requirement": "Service agreement",
          "details": "Providers must agree service terms with users who register for their service, defining both sides' rights and duties (Art. 9); this is not a universal human-vs-AI interaction notice"
        },
        {
          "requirement": "Complaint mechanism",
          "details": "Providers must establish complaint and reporting channels, publish the process and feedback period, and handle complaints (Art. 15)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Article 21 applies penalties under relevant laws; absent a specified penalty there, authorities may warn, criticize and order correction, with suspension for refusal to correct or serious circumstances. Public-security and criminal consequences require their separate legal predicates"
        }
      ],
      "scope": "Providers offering generative AI services to the public within China; research, development, and internal non-public uses are outside Article 2",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cac.gov.cn/2023-07/13/c_1690898327029107.htm",
        "locator": "Articles 4, 9, 12, 15",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/cn-generative-ai-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/cn-generative-ai-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-08-15",
        "verified": "2026-06-30",
        "checked": "2026-08-04",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "coe-cets-225-bias-prevention",
      "regulation": "coe-cets-225",
      "name": "Non-Discrimination and Equality (Human Rights Framework)",
      "requirements": [
        {
          "requirement": "Non-discrimination principle",
          "details": "Art. 10(1) requires Party measures with a view to ensuring AI lifecycle activities respect equality, including gender equality, and the prohibition of discrimination under applicable international and domestic law"
        },
        {
          "requirement": "Equality risk assessment",
          "details": "Risk management under Article 16 must consider equality and non-discrimination impacts"
        },
        {
          "requirement": "Overcoming inequalities",
          "details": "Art. 10(2) commits Parties to measures aimed at overcoming inequalities to achieve fair, just, and equitable outcomes"
        },
        {
          "requirement": "Non-discriminatory implementation",
          "details": "Art. 17 requires the Convention's provisions to be implemented without discrimination on any ground"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "No direct supranational fine; applicable duties and consequences depend on Party implementation after entry into force"
        }
      ],
      "scope": "Treaty Parties adopting or maintaining equality and nondiscrimination measures under Articles 10, 16 and 17; private actor duties depend on domestic implementation",
      "context": "Article 10 calls for Party measures respecting equality, including gender equality and nondiscrimination under applicable law, and measures aimed at overcoming inequalities. Article 16 addresses related risks and impacts; Article 17 requires nondiscriminatory implementation of the Convention. These are Party-level duties qualified by applicable international and domestic law.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://rm.coe.int/1680afae3c",
        "locator": "Articles 10, 16, 17",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/coe-cets-225-bias-prevention.json",
        "obligations": [
          "https://everyailaw.com/obligation/coe-cets-225-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "Pending entry into force",
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "coe-cets-225-human-oversight",
      "regulation": "coe-cets-225",
      "name": "Remedies and Procedural Safeguards (Articles 14–15)",
      "requirements": [
        {
          "requirement": "Access to redress",
          "details": "Each Party adopts or maintains accessible and effective remedies for human-rights violations from AI lifecycle activities to the extent required by its international obligations and consistent with its domestic legal system (Art. 14(1))"
        },
        {
          "requirement": "Contestability",
          "details": "Party measures make relevant information sufficient to contest decisions made or substantially informed by AI and, where relevant and appropriate, use of the system itself (Art. 14(2)(a)-(b))"
        },
        {
          "requirement": "Complaints",
          "details": "Party measures provide an effective possibility for concerned persons to complain to competent authorities (Art. 14(2)(c))"
        },
        {
          "requirement": "Procedural safeguards",
          "details": "Each Party ensures safeguards where an AI system significantly affects enjoyment of human rights, under applicable international and domestic law (Art. 15(1))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "No direct supranational fine; applicable remedies and consequences depend on Party implementation after entry into force"
        }
      ],
      "scope": "Treaty Parties adopting or maintaining Article 14 remedies and Article 15 safeguards; private actor duties depend on domestic implementation",
      "context": "Article 14 remedies are qualified by each Party's international obligations and domestic legal system. Article 15(1) applies procedural safeguards where an AI system significantly affects enjoyment of human rights; Article 15(2) separately asks Parties to seek context-appropriate interaction notice. The treaty text does not create an unqualified private appeal right.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://rm.coe.int/1680afae3c",
        "locator": "Articles 14, 15",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/coe-cets-225-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/coe-cets-225-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "Pending entry into force",
        "verified": "2026-08-01",
        "checked": "2026-08-12",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "coe-cets-225-record-keeping",
      "regulation": "coe-cets-225",
      "name": "Documentation and Record-Keeping (Articles 14–16)",
      "requirements": [
        {
          "requirement": "Risk documentation",
          "details": "Party risk measures include documentation of risks, actual and potential impacts and the management approach (Art. 16(2)(f))"
        },
        {
          "requirement": "Relevant system information",
          "details": "Party measures document relevant information about systems with potential significant human-rights effects and their use, provide it to authorized bodies and, when appropriate and applicable, affected persons (Art. 14(2)(a))"
        },
        {
          "requirement": "Contestability information",
          "details": "That information must be sufficient for affected persons to contest decisions made or substantially informed by the system and, where relevant and appropriate, use of the system itself (Art. 14(2)(b)); the treaty sets no universal private log-retention period"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "No direct supranational fine; applicable duties and consequences depend on Party implementation after entry into force"
        }
      ],
      "scope": "Treaty Parties adopting or maintaining Article 14 and 16 information and risk-documentation measures; private actor duties depend on domestic implementation",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://rm.coe.int/1680afae3c",
        "locator": "Articles 14, 16",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/coe-cets-225-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/coe-cets-225-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "Pending entry into force",
        "verified": "2026-08-01",
        "checked": "2026-08-19",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "coe-cets-225-risk-assessment",
      "regulation": "coe-cets-225",
      "name": "Risk and Impact Management (Article 16)",
      "requirements": [
        {
          "requirement": "Lifecycle risk measures",
          "details": "Each Party must adopt or maintain measures to identify, assess, prevent and mitigate AI-system risks to human rights, democracy and the rule of law (Art. 16(1))"
        },
        {
          "requirement": "Graduated approach",
          "details": "Party measures account for context, intended use, severity and probability; they apply iteratively and include monitoring of risks and adverse impacts (Art. 16(2)(a)-(e))"
        },
        {
          "requirement": "Risk documentation",
          "details": "Party measures include documentation of risks, actual and potential impacts, and the management approach (Art. 16(2)(f))"
        },
        {
          "requirement": "Pre-use testing",
          "details": "Party measures require testing before first use and when significantly modified, where appropriate (Art. 16(2)(g))"
        },
        {
          "requirement": "Moratoria assessment",
          "details": "Each Party assesses the need for a moratorium, ban or other measure for uses it considers incompatible with human rights, democracy or the rule of law (Art. 16(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "No direct supranational fine; Party implementation and oversight mechanisms determine applicable domestic consequences after entry into force"
        }
      ],
      "scope": "Treaty Parties adopting or maintaining Article 16 risk measures for covered AI lifecycle activities; private actor duties depend on domestic implementation",
      "context": "Article 16 directs Parties to adopt graduated, context-sensitive risk measures and assess whether uses they consider incompatible with human rights, democracy or the rule of law warrant a moratorium, ban or other measure. Its operation depends on treaty entry into force and Party implementation.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://rm.coe.int/1680afae3c",
        "locator": "Article 16",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/coe-cets-225-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/coe-cets-225-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "Pending entry into force",
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "coe-cets-225-transparency",
      "regulation": "coe-cets-225",
      "name": "Transparency and Notification (Articles 8 and 15)",
      "requirements": [
        {
          "requirement": "Transparency and oversight",
          "details": "Article 8 directs each Party to adopt or maintain adequate requirements across covered AI lifecycle activities, tailored to specific contexts and risks"
        },
        {
          "requirement": "Identification of AI-generated content",
          "details": "Article 8 includes identification of AI-generated content within those Party-level measures; it does not prescribe a universal provider label for every output"
        },
        {
          "requirement": "Human-vs-AI notification",
          "details": "Article 15(2) directs each Party to seek, as appropriate for the context, notification to persons interacting with AI systems that they are interacting with a system rather than a human"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Binding treaty — enforcement through domestic implementation; no direct supranational fines"
        }
      ],
      "scope": "Treaty Parties adopting or maintaining measures for covered AI lifecycle activities under Article 3; private provider and deployer duties depend on each Party's implementation approach",
      "context": "Article 8 addresses transparency and identification of AI-generated content through context- and risk-tailored measures adopted by Parties; it does not directly impose a universal content label on providers. Article 15(2) says each Party \"shall seek to ensure\" contextual human-vs-AI notification. Signature or approval alone does not establish that the treaty is in force or that a particular private actor has a direct duty.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://rm.coe.int/1680afae3c",
        "locator": "Articles 8, 15(2)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/coe-cets-225-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/coe-cets-225-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "Pending entry into force",
        "verified": "2026-08-01",
        "checked": "2026-08-06",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-cpa-rules-human-oversight",
      "regulation": "colorado-cpa-rules",
      "name": "Automated Processing Definitions (Rule 2.02)",
      "requirements": [
        {
          "requirement": "Solely Automated Processing",
          "details": "Automated processing of Personal Data with no human review, oversight, involvement or intervention (Rule 2.02)"
        },
        {
          "requirement": "Human Reviewed Automated Processing",
          "details": "Human review of automated processing that does not rise to Human Involved Automated Processing; review of output without meaningful consideration is insufficient (Rule 2.02)"
        },
        {
          "requirement": "Human Involved Automated Processing",
          "details": "Meaningful consideration of available data used in processing or any output, and authority to change or influence the processing outcome (Rule 2.02)"
        },
        {
          "requirement": "Profiling opt-out effect",
          "details": "For covered profiling of statutory consumer personal data in furtherance of a decision with legal or similarly significant effects, Rule 9.04(B) requires honoring opt-out requests based on solely or human reviewed processing. Rule 9.04(C) allows a controller to decline a request based on human involved processing, with the required notice and information."
        },
        {
          "requirement": "Employment boundary",
          "details": "“Employment opportunities” remains one listed significant-effect domain, but the consumer definition excludes the employment context, job applicants, and employment-context beneficiaries, and § 6-1-1304(2)(k) exempts employment records"
        },
        {
          "requirement": "Separate biometric rule",
          "details": "Rule 7.09 separately governs employer consent for employee or prospective-employee biometric identifiers under C.R.S. § 6-1-1314(6)"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "Up to USD 20,000 per violation (deceptive trade practice)"
        }
      ],
      "scope": "Controllers subject to C.R.S. § 6-1-1304 when processing personal data of statutory consumers, subject to the Act's thresholds and exemptions",
      "context": "These definitions govern profiling within the CPA's controller, personal-data, and statutory-consumer scope. The significant-effects definition includes employment opportunities, but “Consumer” excludes a person acting in a commercial or employment context, a job applicant, and a beneficiary of someone acting in an employment context; C.R.S. § 6-1-1304(2)(k) separately exempts data maintained for employment records purposes. Rule 7.09 creates a distinct employee biometric-identifier consent regime and does not expand Part 9 profiling duties to ordinary employment records. Rule 9.04(B)-(C) applies the three processing definitions to profiling opt-out requests within the CPA’s covered scope.",
      "instrument_notes": null,
      "roles": [
        "controller"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://coag.gov/colorado-privacy-act-rulemaking/",
        "locator": "Rules 2.02, 9.04(B)-(C)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-cpa-rules-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-cpa-rules-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-07-01",
        "verified": "2026-06-30",
        "checked": "2026-08-09",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-cpa-rules-risk-assessment",
      "regulation": "colorado-cpa-rules",
      "name": "Data Protection Assessments for Profiling (Rule 9.06(A)-(B))",
      "requirements": [
        {
          "requirement": "DPA for profiling",
          "details": "Controllers must conduct and document a Data Protection Assessment before processing consumer personal data for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial or physical injury, offensive intrusion on privacy, or other substantial injury to consumers (Rule 9.06(A))"
        },
        {
          "requirement": "Risk evaluation",
          "details": "Assess risks to consumers from profiling activities"
        },
        {
          "requirement": "Mitigation measures",
          "details": "Identify and document mitigation measures for identified risks"
        },
        {
          "requirement": "Covers automated decisions",
          "details": "Applies to all three tiers of automated processing defined in Rule 2.02"
        },
        {
          "requirement": "Employment boundary",
          "details": "“Employment opportunities” is a listed significant-effect domain, but ordinary employment-context and job-applicant processing is outside the statutory Consumer definition, and data maintained for employment records purposes is exempt under § 6-1-1304(2)(k)"
        },
        {
          "requirement": "Separate biometric rule",
          "details": "Rule 7.09 employee biometric consent duties are distinct from Part 9 profiling assessments"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "Up to USD 20,000 per violation (deceptive trade practice)"
        }
      ],
      "scope": "Controllers subject to C.R.S. § 6-1-1304 before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in Rule 9.06(A), subject to statutory thresholds and exemptions",
      "context": "Rule 9.06 applies to covered controllers before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in C.R.S. § 6-1-1309(2)(a). Rules 9.02 and 9.03 list employment opportunities among significant-effect decision domains, but the statute's Consumer definition excludes an employment context, a job applicant, and an employment-context beneficiary, and § 6-1-1304(2)(k) exempts employment records. Rule 7.09 separately regulates employee biometric identifiers.",
      "instrument_notes": null,
      "roles": [
        "controller"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://coag.gov/colorado-privacy-act-rulemaking/",
        "locator": "Rule 9.06(A)-(B)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-cpa-rules-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-cpa-rules-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-07-01",
        "verified": "2026-06-30",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-hb26-1263-age-estimation",
      "regulation": "colorado-hb26-1263",
      "name": "Age Estimation and Minor Identification",
      "requirements": [
        {
          "requirement": "Estimate user age",
          "details": "Use commercially reasonable methods or generally accepted methods to estimate the age of account holders or users (§ 6-1-1708(2))"
        },
        {
          "requirement": "No willful disregard",
          "details": "Do not willfully disregard clear and convincing information that an account holder or user is a minor (§ 6-1-1708(2))"
        },
        {
          "requirement": "Estimate is knowledge",
          "details": "The estimated age or age range of a minor account holder or user is considered knowledge of the minor's age for the whole of § 6-1-1708 (§ 6-1-1708(2))"
        },
        {
          "requirement": "Minor user definition",
          "details": "A minor user is a user the operator has knowledge is a minor by using commercially reasonable or generally accepted age-estimation methods (§ 6-1-1708(1)(c))"
        },
        {
          "requirement": "Trigger for minor duties",
          "details": "Where the operator knows an account holder or user is a minor, the duties at § 6-1-1708(2)(a)-(h) apply on and after 2027-01-01 (§ 6-1-1708(2))"
        }
      ],
      "penalties": [
        {
          "violation": "Enforcement route",
          "fine": "Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved."
        },
        {
          "violation": "Civil penalty",
          "fine": "HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved."
        },
        {
          "violation": "Private right of action",
          "fine": "Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies."
        }
      ],
      "scope": "Operators — a person, partnership, corporation, or entity that develops and makes publicly available a conversational AI service, or offers one to a consumer (§ 6-1-1701(15.5)(a)); mobile application stores and search engines are excluded when they merely provide access (§ 6-1-1701(15.5)(b)). A minor is a consumer under eighteen years old (§ 6-1-1701(15.3))",
      "context": "The 2026 C.R.S. publishes the section as § 6-1-1708 through 2026-12-31, then expressly harmonizes it with SB 26-189 and relocates it to § 6-1-1710 effective 2027-01-01. The separate predecessor-framework operative history remains unresolved, and no court interpretation is claimed. Colorado requires age estimation by commercially reasonable or generally accepted methods and deems the estimate to be knowledge of the minor's age. The age-estimation and willful-disregard sentences sit before the \"on and after January 1, 2027\" clause in the same paragraph. The saved pending status and 2027-01-01 date describe the minor-triggered duties in the list, not a resolved conclusion that the preceding age-estimation commands have no effect before 2027. The official bill summary broadly describes 2027 commencement; this textual timing question remains unresolved.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leg.colorado.gov/bills/HB26-1263",
        "locator": "C.R.S. § 6-1-1708(1)(c), (2) through 2026-12-31; § 6-1-1710(1)(c), (2) effective 2027-01-01",
        "citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (through 2026-12-31), 6-1-1710 (effective 2027-01-01) (2026 Colo. Sess. Laws, HB 26-1263)"
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-hb26-1263-age-estimation.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-hb26-1263-age-estimation-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-hb26-1263-annual-reporting",
      "regulation": "colorado-hb26-1263",
      "name": "Annual Attorney General Reporting",
      "requirements": [
        {
          "requirement": "Annual filing",
          "details": "Annually report to the Attorney General's office on and after 2027-07-01 (§ 6-1-1708(6)(a))"
        },
        {
          "requirement": "Referral count",
          "details": "Report the number of times the operator issued a crisis service provider referral notification in the preceding calendar year (§ 6-1-1708(6)(a)(I))"
        },
        {
          "requirement": "Detection protocols",
          "details": "Report any protocols implemented to detect, remove, and respond to instances of suicidal ideation or self-harm by a user (§ 6-1-1708(6)(a)(II))"
        },
        {
          "requirement": "Prevention protocols",
          "details": "Report any protocols implemented to prevent a service response about suicidal ideation or self-harm actions (§ 6-1-1708(6)(a)(III))"
        },
        {
          "requirement": "Attorney-General-determined metrics",
          "details": "Report any additional metrics necessary to determine the efficacy and reliability of implemented safeguards or detection, removal, and response protocols, as determined by the Attorney General (§ 6-1-1708(6)(a)(IV))"
        },
        {
          "requirement": "No personal information",
          "details": "The report must not include any identifiers or personal information about a user (§ 6-1-1708(6)(b))"
        },
        {
          "requirement": "Public posting",
          "details": "The Attorney General's office posts data from the reports on its public website (§ 6-1-1708(6)(c))"
        },
        {
          "requirement": "Evidence-based measurement",
          "details": "For the purpose of creating the report, the operator must use evidence-based methods for measuring suicidal ideation or self-harm (§ 6-1-1708(6)(d))"
        }
      ],
      "penalties": [
        {
          "violation": "Enforcement route",
          "fine": "Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved."
        },
        {
          "violation": "Civil penalty",
          "fine": "HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved."
        },
        {
          "violation": "Private right of action",
          "fine": "Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies."
        }
      ],
      "scope": "Operators of any conversational AI service (§ 6-1-1708(6)(a)); the recipient is the Attorney General's office, which posts the reported data publicly (§ 6-1-1708(6)(c))",
      "context": "This is a filing to a regulator, not a website self-disclosure — the contrast with Washington ESHB 2225 and Oregon, which require operators to publish crisis-referral counts themselves. It starts on 2027-07-01. The statute calls for the preceding calendar year's referral count but does not state an exact first filing date, so the first reporting period and its relationship to the 2027-01-01 protocol commencement remain unresolved. The Attorney General may expand the report by determining additional metrics necessary to judge the efficacy and reliability of safeguards, which is an open-ended content hook without a rulemaking procedure attached. Reports must exclude user identifiers and personal information, and measurement must use evidence-based methods.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leg.colorado.gov/bills/HB26-1263",
        "locator": "C.R.S. § 6-1-1708(6) through 2026-12-31; § 6-1-1710(6) effective 2027-01-01",
        "citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (through 2026-12-31), 6-1-1710 (effective 2027-01-01) (2026 Colo. Sess. Laws, HB 26-1263)"
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-hb26-1263-annual-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-hb26-1263-annual-reporting-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-hb26-1263-consumer-disclosure",
      "regulation": "colorado-hb26-1263",
      "name": "General Consumer Disclosure and Licensed-Professional Representation Bar",
      "requirements": [
        {
          "requirement": "Artificiality disclosure",
          "details": "Clearly and conspicuously disclose to a user that the conversational AI service is artificial intelligence (§ 6-1-1708(3))"
        },
        {
          "requirement": "Daily first-interaction timing",
          "details": "Provide the disclosure at the beginning of a user's first interaction with the service for each day of interaction (§ 6-1-1708(3)(a))"
        },
        {
          "requirement": "Three-hour or persistent cadence",
          "details": "The disclosure must appear at least once every three hours in a continuous interaction, or appear as a persistent disclosure visible to the user (§ 6-1-1708(3)(b))"
        },
        {
          "requirement": "Prompt-responsive delivery",
          "details": "The disclosure must be provided in response to user prompts regarding whether the service is artificially generated and not human (§ 6-1-1708(3)(c))"
        },
        {
          "requirement": "No professional-equivalence claims",
          "details": "Do not use any term, letter, or phrase in advertising, the interface, or outputs stating that output data is provided by, endorsed by, or equivalent to services provided by a licensed health-care professional, a licensed legal professional, or a licensed, certified, or registered mental health professional (§ 6-1-1708(5)(a)-(c))"
        },
        {
          "requirement": "Dietitian claims",
          "details": "The same bar covers claims of equivalence to a qualified dietitian as described in § 6-1-707(1)(b) (§ 6-1-1708(5)(d))"
        },
        {
          "requirement": "Savings clauses",
          "details": "Nothing in the section limits constitutional information access, requires disclosure of trade secrets or protected confidential information, or authorizes content moderation inconsistent with the United States Constitution (§ 6-1-1708(7)(a)-(c))"
        }
      ],
      "penalties": [
        {
          "violation": "Enforcement route",
          "fine": "Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved."
        },
        {
          "violation": "Civil penalty",
          "fine": "HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved."
        },
        {
          "violation": "Private right of action",
          "fine": "Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies."
        }
      ],
      "scope": "Operators of any conversational AI service, as to every user regardless of age (§ 6-1-1708(3), § 6-1-1708(5))",
      "context": "The general disclosure is unconditional — there is no reasonable-person trigger, so a plainly artificial service still discloses. Colorado's daily-reset cadence is distinctive: the disclosure is owed at the beginning of the user's first interaction for each day of interaction, then either every three hours in a continuous interaction or as a persistent visible disclosure. The false-representation bar at § 6-1-1708(5) covers four named professions — licensed health-care professionals, licensed legal professionals, licensed, certified, or registered mental health professionals, and qualified dietitians as described in § 6-1-707(1)(b) — and reaches advertising and interface copy as well as model outputs. Section 6-1-1708(7) preserves constitutional information access, does not require disclosure of trade secrets or confidential information, and does not authorize content moderation inconsistent with the United States Constitution.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leg.colorado.gov/bills/HB26-1263",
        "locator": "C.R.S. § 6-1-1708(3), (5) through 2026-12-31; § 6-1-1710(3), (5) effective 2027-01-01",
        "citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (through 2026-12-31), 6-1-1710 (effective 2027-01-01) (2026 Colo. Sess. Laws, HB 26-1263)"
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-hb26-1263-consumer-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-hb26-1263-consumer-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-hb26-1263-crisis-protocol",
      "regulation": "colorado-hb26-1263",
      "name": "Suicide and Self-Harm Response Protocol",
      "requirements": [
        {
          "requirement": "Crisis protocol",
          "details": "Implement a protocol for the service to respond to a user prompt regarding suicidal ideation or self-harm (§ 6-1-1708(4))"
        },
        {
          "requirement": "Crisis service referral",
          "details": "The protocol must include user referral to a crisis service provider such as a suicide hotline, a crisis text line, or another appropriate crisis service (§ 6-1-1708(4))"
        },
        {
          "requirement": "Law enforcement excluded",
          "details": "The referral expressly does not include a law enforcement agency (§ 6-1-1708(4))"
        },
        {
          "requirement": "Escalation procedures",
          "details": "The protocol must include escalation procedures for repeated or severe crisis indicators (§ 6-1-1708(4))"
        },
        {
          "requirement": "Self-harm definition",
          "details": "Self-harm means intentional self-injury, with or without the intent to cause death (§ 6-1-1701(16.5))"
        }
      ],
      "penalties": [
        {
          "violation": "Enforcement route",
          "fine": "Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved."
        },
        {
          "violation": "Civil penalty",
          "fine": "HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved."
        },
        {
          "violation": "Private right of action",
          "fine": "Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies."
        }
      ],
      "scope": "Operators of any conversational AI service, as to every user regardless of age (§ 6-1-1708(4))",
      "context": "Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says \"but not including a law enforcement agency.\" The exclusion applies to the required crisis-service referral. The text does not resolve every possible separate welfare-check or escalation practice, and a claim of uniqueness would require a separate comparative source review. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leg.colorado.gov/bills/HB26-1263",
        "locator": "C.R.S. § 6-1-1708(4) through 2026-12-31; § 6-1-1710(4) effective 2027-01-01; § 6-1-1701(16.5)",
        "citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (through 2026-12-31), 6-1-1710 (effective 2027-01-01) (2026 Colo. Sess. Laws, HB 26-1263)"
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-hb26-1263-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-hb26-1263-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-hb26-1263-minor-disclosure",
      "regulation": "colorado-hb26-1263",
      "name": "Minor Artificiality Disclosure and Cadence",
      "requirements": [
        {
          "requirement": "Artificiality disclosure",
          "details": "Clearly and conspicuously disclose to the minor account holder or minor user that they are interacting with artificial intelligence that is artificially generated and not human (§ 6-1-1708(2)(a))"
        },
        {
          "requirement": "Prompt-responsive delivery",
          "details": "The disclosure must be provided in response to user prompts regarding whether the service is artificially generated and not human (§ 6-1-1708(2)(a))"
        },
        {
          "requirement": "Screen products",
          "details": "A persistent visible disclaimer for a product with a screen interface (§ 6-1-1708(2)(a)(I))"
        },
        {
          "requirement": "Screenless products",
          "details": "An intermittent audio disclaimer for a product without a screen interface (§ 6-1-1708(2)(a)(II))"
        },
        {
          "requirement": "Cadence",
          "details": "Provided at the beginning of each interaction and at least once every three hours in a continuous interaction (§ 6-1-1708(2)(a)(III))"
        }
      ],
      "penalties": [
        {
          "violation": "Enforcement route",
          "fine": "Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved."
        },
        {
          "violation": "Civil penalty",
          "fine": "HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved."
        },
        {
          "violation": "Private right of action",
          "fine": "Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies."
        }
      ],
      "scope": "Operators that know an account holder or user of a conversational AI service is a minor, i.e. a consumer under eighteen (§ 6-1-1701(15.3), § 6-1-1708(2))",
      "context": "The disclosure duty is written as prompt-responsive first — it \"must be provided in response to user prompts regarding whether the service is artificially generated and not human\" — and then specifies the delivery form by product type: a persistent visible disclaimer on screen products, an intermittent audio disclaimer on screenless products, or beginning-of-interaction plus a three-hour cadence. Colorado gives minors the same three-hour interval as adults, unlike Washington ESHB 2225, which drops the minor cadence to one hour.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leg.colorado.gov/bills/HB26-1263",
        "locator": "C.R.S. § 6-1-1708(2)(a) through 2026-12-31; § 6-1-1710(2)(a) effective 2027-01-01",
        "citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (through 2026-12-31), 6-1-1710 (effective 2027-01-01) (2026 Colo. Sess. Laws, HB 26-1263)"
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-hb26-1263-minor-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-hb26-1263-minor-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-hb26-1263-minor-engagement-limits",
      "regulation": "colorado-hb26-1263",
      "name": "Minor Engagement, Sexual Content, and Emotional-Dependence Limits",
      "requirements": [
        {
          "requirement": "No variable-interval rewards",
          "details": "Do not provide the minor with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement (§ 6-1-1708(2)(b))"
        },
        {
          "requirement": "Sexual content controls",
          "details": "Institute technically feasible measures to prevent the service from producing textual, visual, or aural depictions of explicit sexual conduct, producing an intimate digital depiction, generating a statement that the minor should engage in explicit sexual conduct, or engaging in erotic or sexually explicit interactions with the minor (§ 6-1-1708(2)(c)(I)-(IV))"
        },
        {
          "requirement": "Emotional-dependence controls",
          "details": "Institute reasonable measures to prevent the service from formulating, structuring, or optimizing a response that simulates emotional dependence or isolation from real-world supports (§ 6-1-1708(2)(d))"
        },
        {
          "requirement": "Named prohibited outputs",
          "details": "Those measures must prevent an explicit claim that the service is human or artificially sentient, a statement that simulates a romantic companionship, and role-playing of an adult-minor romantic relationship (§ 6-1-1708(2)(d)(I)-(III))"
        },
        {
          "requirement": "Prohibition protocol",
          "details": "Implement a protocol to prohibit the service from engaging in explicit sexual conduct with a minor (§ 6-1-1708(2)(e))"
        },
        {
          "requirement": "Stop-engagement protocol",
          "details": "Implement a protocol for the service to stop engaging in response to a user prompt regarding explicit sexual conduct with a minor (§ 6-1-1708(2)(f))"
        }
      ],
      "penalties": [
        {
          "violation": "Enforcement route",
          "fine": "Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved."
        },
        {
          "violation": "Civil penalty",
          "fine": "HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved."
        },
        {
          "violation": "Private right of action",
          "fine": "Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies."
        }
      ],
      "scope": "Operators that know an account holder or user is a minor (§ 6-1-1708(2)). \"Explicit sexual conduct\" takes its meaning from C.R.S. § 13-21-1502(7) but excludes evidence-based medical information and factual descriptions of reproductive health care (§ 6-1-1701(10.5)); \"intimate digital depiction\" takes its meaning from § 13-21-1502(10) (§ 6-1-1701(12.5))",
      "context": "Colorado states two different measures inside the same subsection: sexual-content controls must be \"technically feasible measures\" (§ 6-1-1708(2)(c)) while emotional-dependence controls require \"reasonable measures\" (§ 6-1-1708(2)(d)). The text does not rank which standard is more demanding in every application. The emotional-dependence list reaches model behaviour rather than interface copy — the service must be prevented from explicitly claiming to be human or artificially sentient, from simulating romantic companionship, and from role-playing an adult-minor romantic relationship. The variable-reward ban at § 6-1-1708(2)(b) targets points or similar rewards at unpredictable intervals intended to increase engagement.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leg.colorado.gov/bills/HB26-1263",
        "locator": "C.R.S. § 6-1-1708(2)(b)-(f) through 2026-12-31; § 6-1-1710(2)(b)-(f) effective 2027-01-01",
        "citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (through 2026-12-31), 6-1-1710 (effective 2027-01-01) (2026 Colo. Sess. Laws, HB 26-1263)"
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-hb26-1263-minor-engagement-limits.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-hb26-1263-minor-engagement-limits-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-hb26-1263-minor-privacy-tools",
      "regulation": "colorado-hb26-1263",
      "name": "Minor Privacy, Memory, and Parental Control Tools",
      "requirements": [
        {
          "requirement": "Part 13 compliance",
          "details": "Comply with part 13 of article 1 of title 6 regarding protecting the privacy and data of a minor (§ 6-1-1708(2)(g))"
        },
        {
          "requirement": "Minor privacy and account tools",
          "details": "Offer tools for the minor account holder or minor user to manage their privacy and account settings (§ 6-1-1708(2)(h)(I))"
        },
        {
          "requirement": "Memory personalization control",
          "details": "Those tools must include the ability to control whether the service retains information from prior interactions or sessions for the purpose of personalizing the content of future interactions (§ 6-1-1708(2)(h)(I))"
        },
        {
          "requirement": "Training-use control",
          "details": "Those tools must include the ability to control whether the minor's personal data is used for the purposes of training the conversational AI service (§ 6-1-1708(2)(h)(I))"
        },
        {
          "requirement": "Parent and guardian tools",
          "details": "Offer tools for a parent or guardian of the minor to manage the minor's privacy and account settings (§ 6-1-1708(2)(h)(II))"
        }
      ],
      "penalties": [
        {
          "violation": "Enforcement route",
          "fine": "Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved."
        },
        {
          "violation": "Civil penalty",
          "fine": "HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved."
        },
        {
          "violation": "Private right of action",
          "fine": "Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies."
        }
      ],
      "scope": "Operators that know an account holder or user is a minor (§ 6-1-1708(2)), plus their parents or guardians as tool recipients (§ 6-1-1708(2)(h)(II))",
      "context": "This provision requires specific minor privacy controls. The minor's own privacy tool must let the user turn off cross-session memory personalization — control over whether the service retains information from prior interactions or sessions to personalize future ones — and separately opt out of having their personal data used to train the service. The source review does not establish whether other states require similar controls. Subsection (2)(g) also bolts on compliance with part 13 of article 1 of title 6, Colorado's existing minor-data privacy regime, so the operator inherits that part's duties by reference rather than restating them.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://leg.colorado.gov/bills/HB26-1263",
        "locator": "C.R.S. § 6-1-1708(2)(g)-(h) through 2026-12-31; § 6-1-1710(2)(g)-(h) effective 2027-01-01",
        "citation": "C.R.S. §§ 6-1-1701, 6-1-1708 (through 2026-12-31), 6-1-1710 (effective 2027-01-01) (2026 Colo. Sess. Laws, HB 26-1263)"
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-hb26-1263-minor-privacy-tools.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-hb26-1263-minor-privacy-tools-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-insurance-ai-bias",
      "regulation": "colorado-insurance-ai",
      "name": "Prohibition on Algorithmic Discrimination in Insurance",
      "requirements": [
        {
          "requirement": "Non-discrimination",
          "details": "Insurers must not unfairly discriminate in a covered insurance practice; pursuant to commissioner rules, they must not use ECDIS or algorithms and predictive models using ECDIS in a way that unfairly discriminates based on protected characteristics (§ 10-3-1104.9(1))"
        },
        {
          "requirement": "Protected classes",
          "details": "Race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, gender expression"
        },
        {
          "requirement": "Demonstration obligation",
          "details": "The commissioner adopts rules by insurance type and practice establishing means for insurers to demonstrate, to the extent practicable, testing of whether covered ECDIS uses unfairly discriminate (§ 10-3-1104.9(3)(a))"
        }
      ],
      "penalties": [
        {
          "violation": "Commissioner order after hearing",
          "fine": "Up to USD 3,000 per act or violation, aggregate USD 30,000; if an insurer knew or reasonably should have known of a violation, up to USD 30,000 per act or violation, aggregate USD 750,000 annually. License suspension or revocation may also apply (§ 10-3-1108(1))"
        }
      ],
      "scope": "Insurers engaged in covered insurance practices; § 10-3-1104.9 excludes title insurance, specified qualified-surety bonds, and commercial insurance policies other than business owners' or commercial general liability policies with annual premiums of USD 10,000 or less",
      "context": "Section 10-3-1104.9(1)(a) bars unfair discrimination in any covered insurance practice. Subsection (1)(b) separately bars discriminatory use of external consumer data and information sources (ECDIS), and algorithms or predictive models using ECDIS, pursuant to commissioner rules. The statute's insurance-line exclusions and rule-specific obligations limit this record.",
      "instrument_notes": null,
      "roles": [
        "insurer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb21-169",
        "locator": "Co. Rev. Stat. § 10-3-1104.9; 3 CCR 702-10, Amended Regulation 10-1-1",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-insurance-ai-bias.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-insurance-ai-bias-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2021-09-07",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-insurance-ai-governance",
      "regulation": "colorado-insurance-ai",
      "name": "Insurance Algorithm Governance Testing",
      "requirements": [
        {
          "requirement": "Governance framework",
          "details": "Insurers must adopt a governance and risk management framework for ECDIS and for algorithms and predictive models that use ECDIS (Amended Regulation 10-1-1)"
        },
        {
          "requirement": "Covered lines",
          "details": "The 2023 rule covered individually issued life insurance; the amended rule added private passenger automobile insurance and health benefit plans effective 2025-10-15"
        },
        {
          "requirement": "Attestation for non-users",
          "details": "Insurers not using covered ECDIS tools must file an officer attestation within one month of the applicable rule effective date and each December 1 thereafter (Regulation 10-1-1 § 6.E)"
        },
        {
          "requirement": "Progress and compliance reporting",
          "details": "Life insurers using covered tools had a 2024-06-01 progress deadline and report compliance from 2024-12-01 annually; newly covered auto and health insurers had a 2025-12-01 progress deadline and report compliance from 2026-07-01 annually (Regulation 10-1-1 § 6.A-C)"
        },
        {
          "requirement": "Quantitative testing description",
          "details": "Document the methodology, assumptions, results, and remediation steps for quantitative testing conducted pursuant to Division-established requirements (Regulation 10-1-1 § 5.A.11); no universal current testing mandate is inferred from this clause alone"
        },
        {
          "requirement": "Regulatory demonstration",
          "details": "Must be able to demonstrate compliance to the Commissioner of Insurance"
        }
      ],
      "penalties": [
        {
          "violation": "Commissioner order after hearing",
          "fine": "Up to USD 3,000 per act or violation, aggregate USD 30,000; if an insurer knew or reasonably should have known of a violation, up to USD 30,000 per act or violation, aggregate USD 750,000 annually. License suspension or revocation may also apply (§ 10-3-1108(1))"
        }
      ],
      "scope": "Colorado-authorized insurers offering individually issued life insurance, private passenger automobile insurance, or health benefit plans that use ECDIS or algorithms and predictive models using ECDIS in an insurance practice (Regulation 10-1-1 §§ 2-3, 5)",
      "context": "Amended Regulation 10-1-1 requires a risk-based governance and risk management framework for covered ECDIS uses, with controls designed to detect potential unfair discrimination and remediate it if identified through Division-established quantitative testing. Its § 5.A.11 requires a documented description of quantitative testing conducted pursuant to Division-established requirements; the reviewed rule does not itself establish a universal quantitative-testing mandate. The 2023 rule began with life insurers and the 2025 amendment added private passenger automobile and health benefit plan insurers.",
      "instrument_notes": null,
      "roles": [
        "insurer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb21-169",
        "locator": "Co. Rev. Stat. § 10-3-1104.9; 3 CCR 702-10, Amended Regulation 10-1-1",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-insurance-ai-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-insurance-ai-governance-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-11-14",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-sb24-205-human-review",
      "regulation": "colorado-sb24-205",
      "name": "Meaningful Human Review",
      "requirements": [
        {
          "requirement": "Opportunity to appeal",
          "details": "Deployers must provide consumers an opportunity to appeal adverse consequential decisions made by or substantially involving high-risk AI"
        },
        {
          "requirement": "Human review on appeal",
          "details": "Appeal must allow for human review of the adverse decision if technically feasible, unless providing an appeal is not in the consumer's best interest, including when delay might risk the consumer's life or safety"
        },
        {
          "requirement": "Data correction",
          "details": "Consumers must have an opportunity to correct incorrect personal data the system processed (§ 6-1-1703(4)(b)(II))"
        },
        {
          "requirement": "Accessibility",
          "details": "Notice of appeal rights must be in plain language, all languages used in the ordinary course of business, and in accessible formats"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "AG enforcement only; no private right of action"
        }
      ],
      "scope": "deployers",
      "context": null,
      "instrument_notes": "Historical predecessor replaced by enacted SB 26-189, section 1. Lifecycle status records the enacted replacement, not whether or when predecessor duties legally operated or can currently be enforced. The retained scheduled effective date is not evidence that the predecessor duties became operative. ECF 24 conditionally bars defendant Colorado Attorney General Philip J. Weiser from initiating enforcement or investigation for alleged violations occurring on or before 14 days after a future preliminary-injunction ruling; it does not establish statutory nonoperation or current docket status. Replacement timing remains subject to section 5; operative and enforcement status remain unknown.",
      "roles": [
        "deployer"
      ],
      "status": "repealed",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb24-205",
        "locator": "C.R.S. § 6-1-1703(4)(b)(III)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-sb24-205-human-review.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-sb24-205-human-review-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-30",
        "verified": "2026-05-15",
        "checked": "2026-08-16",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [
          {
            "date": "2026-05-14",
            "description": "Repealed and reenacted by SB 26-189 (signed by Governor Polis). SECTION 1 of SB 26-189 repeals and reenacts C.R.S. part 17 of article 1 of title 6, replacing this ADMT framework. SB25B-004 moved the scheduled requirement date from 2026-02-01 to 2026-06-30. SB 26-189 section 5 separates general commencement on 2027-01-01 from upon-passage exceptions; predecessor operative history remains unresolved. See instrument colorado-sb26-189."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-sb24-205-transparency",
      "regulation": "colorado-sb24-205",
      "name": "Transparency in Consequential Decisions",
      "requirements": [
        {
          "requirement": "Pre-decision notice",
          "details": "Before making/substantially contributing to a consequential decision, deployer must notify consumer and provide purpose, nature of decision, deployer contact info, and plain-language system description (§ 6-1-1703(4)(a))"
        },
        {
          "requirement": "Opt-out disclosure",
          "details": "Provide opt-out rights for profiling under Colorado CPA § 6-1-1306 if applicable (§ 6-1-1703(4)(a)(III))"
        },
        {
          "requirement": "Post-adverse statement",
          "details": "After adverse decision, disclose AI's role, degree of contribution, data types processed, and data sources (§ 6-1-1703(4)(b)(I))"
        },
        {
          "requirement": "Plain language + accessibility",
          "details": "All notices must be in plain language, all languages used in ordinary course of business, and in accessible formats (§ 6-1-1703(4)(c))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "AG enforcement only"
        }
      ],
      "scope": "deployers",
      "context": null,
      "instrument_notes": "Historical predecessor replaced by enacted SB 26-189, section 1. Lifecycle status records the enacted replacement, not whether or when predecessor duties legally operated or can currently be enforced. The retained scheduled effective date is not evidence that the predecessor duties became operative. ECF 24 conditionally bars defendant Colorado Attorney General Philip J. Weiser from initiating enforcement or investigation for alleged violations occurring on or before 14 days after a future preliminary-injunction ruling; it does not establish statutory nonoperation or current docket status. Replacement timing remains subject to section 5; operative and enforcement status remain unknown.",
      "roles": [
        "deployer"
      ],
      "status": "repealed",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb24-205",
        "locator": "C.R.S. § 6-1-1703(4)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-sb24-205-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-sb24-205-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-30",
        "verified": "2026-05-15",
        "checked": "2026-08-17",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [
          {
            "date": "2026-05-14",
            "description": "Repealed and reenacted by SB 26-189 (signed by Governor Polis). SECTION 1 of SB 26-189 repeals and reenacts C.R.S. part 17 of article 1 of title 6, replacing this ADMT framework. SB25B-004 moved the scheduled requirement date from 2026-02-01 to 2026-06-30. SB 26-189 section 5 separates general commencement on 2027-01-01 from upon-passage exceptions; predecessor operative history remains unresolved. See instrument colorado-sb26-189."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-sb26-189-deployer-disclosures",
      "regulation": "colorado-sb26-189",
      "name": "Deployer Disclosures & Post-Adverse Notice",
      "requirements": [
        {
          "requirement": "Point-of-interaction notice",
          "details": "Before using covered ADMT to materially influence a consequential decision, provide a clear and conspicuous notice to the consumer with instructions for obtaining additional information (§ 6-1-1704(1))"
        },
        {
          "requirement": "Public-posting option",
          "details": "Compliance permitted via a prominent public notice reasonably accessible and proximate to the interaction/transaction (§ 6-1-1704(2))"
        },
        {
          "requirement": "Post-adverse disclosure (30 days)",
          "details": "After an adverse outcome, within 30 days provide a plain-language description of the decision and the ADMT's role; a simple process to request ADMT/input details; and an explanation of § 6-1-1705 consumer rights (§ 6-1-1704(3))"
        },
        {
          "requirement": "AG rulemaking",
          "details": "AG to adopt rules on or before 2027-01-01 clarifying post-adverse disclosure content and sector-specific guidance (§ 6-1-1704(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Deceptive trade practice under the Colorado Consumer Protection Act; AG enforcement only, 60-day right to cure (only where the AG deems cure possible; unavailable for knowing or repeated violations, § 6-1-1706(3)(c); the whole cure subsection is repealed 2030-01-01, § 6-1-1706(3)(f)); no private right of action"
        }
      ],
      "scope": "Deployers using covered ADMT to materially influence a consequential decision involving a Colorado consumer (§§ 6-1-1701(5), 6-1-1704)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb26-189",
        "locator": "C.R.S. § 6-1-1704",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-sb26-189-deployer-disclosures.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-sb26-189-deployer-disclosures-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-05-15",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-05-15",
        "instrument_amendments": [
          {
            "date": "2026-05-14",
            "description": "Signed by Governor Polis. SECTION 1 repeals and reenacts C.R.S. part 17 of article 1 of title 6, replacing the SB 24-205 ADMT framework. Effective 2027-01-01; applies to consequential decisions made on or after that date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-sb26-189-developer-documentation",
      "regulation": "colorado-sb26-189",
      "name": "Developer Documentation",
      "requirements": [
        {
          "requirement": "Form and protected information",
          "details": "Make subsection (1) documentation available to each deployer in a reasonably understandable form and manner that protects trade secrets and information protected from disclosure by state or federal law (§ 6-1-1702(1))"
        },
        {
          "requirement": "Use statement",
          "details": "Developers must provide deployers a general statement of intended uses and known harmful or inappropriate uses of the covered ADMT (§ 6-1-1702(1)(a))"
        },
        {
          "requirement": "Training data categories",
          "details": "Describe categories of data, including personal data, used to train the covered ADMT, to the extent known (§ 6-1-1702(1)(b))"
        },
        {
          "requirement": "Known limitations",
          "details": "Disclose known limitations, risks, and circumstances in which the ADMT should not be used (§ 6-1-1702(1)(c))"
        },
        {
          "requirement": "Human-review instructions",
          "details": "Provide instructions for the deployer's appropriate use, monitoring, and meaningful human review where applicable (§ 6-1-1702(1)(d))"
        },
        {
          "requirement": "Deployer-compliance info",
          "details": "Provide information reasonably necessary for the deployer to comply with § 6-1-1704; notify the deployer if information is withheld (§ 6-1-1702(1)(e))"
        },
        {
          "requirement": "Update notices",
          "details": "Provide notice of material updates, intentional and substantial modifications, and changes to intended use/limitations/risk mitigation within a reasonable time; public release notes permitted with direct notice of the release to each deployer (§ 6-1-1702(2))"
        },
        {
          "requirement": "Recordkeeping",
          "details": "Retain records reasonably necessary to demonstrate compliance, including version identifiers, changelogs, documentation, and update notices, for at least 3 years after record creation or longer if applicable state or federal law requires (§ 6-1-1702(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Deceptive trade practice under the Colorado Consumer Protection Act; AG enforcement only, 60-day right to cure (only where the AG deems cure possible; unavailable for knowing or repeated violations, § 6-1-1706(3)(c); the whole cure subsection is repealed 2030-01-01, § 6-1-1706(3)(f)); no private right of action"
        }
      ],
      "scope": "Developers of covered ADMT for consequential decisions involving Colorado consumers, subject to the intended-use and awareness conditions in § 6-1-1702(5), the narrower disclosure trigger in § 6-1-1702(3), and applicable § 6-1-1708 sector qualifications",
      "context": "Section 6-1-1702 applies when a developer creates covered ADMT intended, documented, marketed, advertised, configured, or contracted to make consequential decisions, or becomes aware it is being used to make such decisions consistently with its intended and contracted uses (§ 6-1-1702(5)). The subsection (1)-(2) disclosure duties apply only where the ADMT was marketed, advertised, configured, contracted, sold, or licensed to materially influence a consequential decision (§ 6-1-1702(3)). The definitions and exclusions for consequential decisions and covered ADMT still apply (§ 6-1-1701(3), (5)). Section 6-1-1708 provides sector qualifications. Qualifying insurers and affiliates are deemed compliant in the practice of insurance, but employment decisions remain covered. The HIPAA exclusion covers a covered entity doing business in Colorado and its business associates for services rendered to that covered entity, with an exception for employment and employment-opportunity decisions; for healthcare providers the subsection (3) treatment applies only when operating from a Colorado location. FDA-supervised medical devices and specified pharmaceutical or medical-device research and development activities are also excluded (§ 6-1-1708(1)-(4)).",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb26-189",
        "locator": "C.R.S. § 6-1-1702",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-sb26-189-developer-documentation.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-sb26-189-developer-documentation-transparency.json",
          "https://everyailaw.com/obligation/colorado-sb26-189-developer-documentation-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-05-15",
        "checked": "2026-07-30",
        "instrument_last_verified": "2026-05-15",
        "instrument_amendments": [
          {
            "date": "2026-05-14",
            "description": "Signed by Governor Polis. SECTION 1 repeals and reenacts C.R.S. part 17 of article 1 of title 6, replacing the SB 24-205 ADMT framework. Effective 2027-01-01; applies to consequential decisions made on or after that date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-sb26-189-human-review",
      "regulation": "colorado-sb26-189",
      "name": "Consumer Correction & Human Review",
      "requirements": [
        {
          "requirement": "Data correction",
          "details": "On request after an adverse outcome, provide instructions to request personal data and correct factually incorrect or materially inaccurate data used in the decision, consistent with § 6-1-1306 (§ 6-1-1705(1)(a)(I))"
        },
        {
          "requirement": "Human review & reconsideration",
          "details": "Provide an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable (§ 6-1-1705(1)(a)(II))"
        },
        {
          "requirement": "Correction limits",
          "details": "No requirement to correct opinions, predictions, scores, or protected evaluations (§ 6-1-1705(1)(c))"
        },
        {
          "requirement": "FERPA pathway",
          "details": "Education deployers subject to FERPA may comply via existing student-record inspection/amendment and appeal processes; no duplicative process required (§ 6-1-1705(2))"
        },
        {
          "requirement": "AG rulemaking",
          "details": "AG to adopt rules on or before 2027-01-01 to clarify and implement this section (§ 6-1-1705(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Deceptive trade practice under the Colorado Consumer Protection Act; AG enforcement only, 60-day right to cure (only where the AG deems cure possible; unavailable for knowing or repeated violations, § 6-1-1706(3)(c); the whole cure subsection is repealed 2030-01-01, § 6-1-1706(3)(f)); no private right of action"
        }
      ],
      "scope": "Deployers whose covered ADMT materially influenced an adverse consequential decision involving a Colorado consumer (§§ 6-1-1701(5), 6-1-1705)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb26-189",
        "locator": "C.R.S. § 6-1-1705",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-sb26-189-human-review.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-sb26-189-human-review-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-05-15",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-05-15",
        "instrument_amendments": [
          {
            "date": "2026-05-14",
            "description": "Signed by Governor Polis. SECTION 1 repeals and reenacts C.R.S. part 17 of article 1 of title 6, replacing the SB 24-205 ADMT framework. Effective 2027-01-01; applies to consequential decisions made on or after that date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "colorado-sb26-189-record-keeping",
      "regulation": "colorado-sb26-189",
      "name": "Deployer Record-Keeping",
      "requirements": [
        {
          "requirement": "Retention period",
          "details": "Retain records for not less than 3 years after the date of a consequential decision (or longer if required by other law) reasonably necessary to demonstrate compliance with part 17 (§ 6-1-1703)"
        },
        {
          "requirement": "Record contents",
          "details": "Records may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes (§ 6-1-1703)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Deceptive trade practice under the Colorado Consumer Protection Act; AG enforcement only, 60-day right to cure (only where the AG deems cure possible; unavailable for knowing or repeated violations, § 6-1-1706(3)(c); the whole cure subsection is repealed 2030-01-01, § 6-1-1706(3)(f)); no private right of action"
        }
      ],
      "scope": "Deployers making consequential decisions materially influenced by covered ADMT (§ 6-1-1703)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://leg.colorado.gov/bills/sb26-189",
        "locator": "C.R.S. § 6-1-1703",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/colorado-sb26-189-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/colorado-sb26-189-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-05-15",
        "checked": "2026-08-05",
        "instrument_last_verified": "2026-05-15",
        "instrument_amendments": [
          {
            "date": "2026-05-14",
            "description": "Signed by Governor Polis. SECTION 1 repeals and reenacts C.R.S. part 17 of article 1 of title 6, replacing the SB 24-205 ADMT framework. Effective 2027-01-01; applies to consequential decisions made on or after that date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-pa26-100-subscription-disclosure",
      "regulation": "connecticut-pa26-100",
      "name": "Generative AI Subscription Disclosure",
      "requirements": [
        {
          "requirement": "Written notice before contract or payment",
          "details": "No subscription-based provider may enter into or renew a subscription, or collect any fee for an initial subscription or renewal, unless it has given the consumer a written notice of the key terms and conditions and the consumer has given written notice accepting them (§ 46(b)(1))"
        },
        {
          "requirement": "Initial-subscription content",
          "details": "The notice must give material information sufficient for a reasonable consumer to decide whether to purchase or maintain the subscription, including any quantitative or qualitative limitations the provider may impose (tokens, images generated or modified, transcription services, and limits imposed in response to consumer conduct) and whether the provider has discretion to limit or eliminate access to, or reduce the quantity or quality of, any functionality (§ 46(b)(2)(A))"
        },
        {
          "requirement": "Renewal content",
          "details": "For a renewal, the notice must state any such limitations or discretion that the provider will be able to exercise for the first time in the renewal term, or that applied in the preceding term but have been modified (§ 46(b)(2)(B))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair trade practice",
          "fine": "A violation of § 46(b) is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a), enforced solely by the Attorney General; the § 42-110g private right of action does not apply and the section creates no private right of action (§ 46(c))"
        }
      ],
      "scope": "Subscription-based providers: persons doing business in Connecticut who create, code or otherwise produce a generative AI system that has more than one million users per month and is publicly accessible to consumers for personal use, and who offer it to consumers by subscription. Government agencies are excluded (§ 46(a)(5))",
      "context": "Enacted eleven days after PA 26-15 § 1 and effective the same day, this is Connecticut's second AI subscription disclosure rule. Section 46 is narrower in actors (generative AI, one-million-user threshold, creators only) and broader in required content (usage limits and functionality discretion, with renewal re-disclosure) than PA 26-15 § 1, which reaches any AI technology subscription. Neither section references the other; both apply. \"Generative artificial intelligence system\" is defined as technology using machine learning to generate images, audio or video, and includes systems using deep learning, natural language processing or comparable techniques (§ 46(a)(2)).",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00100-R00HB-05222-PA.PDF",
        "locator": "Conn. PA 26-100 § 46",
        "citation": "Conn. Public Act No. 26-100 §§ 46-47 (Substitute House Bill No. 5222)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-pa26-100-subscription-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-pa26-100-subscription-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-10-01",
        "verified": "2026-09-29",
        "checked": "2026-09-29",
        "instrument_last_verified": "2026-09-29",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-pa26-15-companion-protocol",
      "regulation": "connecticut-pa26-15",
      "name": "AI Companion Crisis Protocol",
      "requirements": [
        {
          "requirement": "Protocol as a precondition",
          "details": "No operator may provide or operate an AI companion unless it includes a protocol meeting the statutory minimum (§ 5(a)(1)(A))"
        },
        {
          "requirement": "Evidence-based detection",
          "details": "The protocol must use evidence-based methods to detect user expressions clearly indicating a risk of suicide, self-harm, or imminent physical violence, and to institute measures preventing output that encourages them (§ 5(a)(1)(A)(i))"
        },
        {
          "requirement": "Crisis referral",
          "details": "On detection, refer the user to appropriate mental health evaluation and treatment resources, including the 9-8-8 National Suicide Prevention Lifeline (§ 5(a)(1)(A)(ii))"
        },
        {
          "requirement": "Escalation on repeat detection",
          "details": "If a further such expression is detected after a referral, refer the user to mental health services consistent with clinical best practices and expertise (§ 5(a)(1)(A)(iii))"
        },
        {
          "requirement": "No claiming humanity",
          "details": "Implement reasonable measures preventing the companion from claiming to be a human being, including when asked directly, and from generating output that refutes or conflicts with the disclosure that it is not human (§ 5(a)(1)(B))"
        },
        {
          "requirement": "Publish the protocol",
          "details": "Post the protocol in a prominent, publicly accessible location on the operator's website (§ 5(a)(2))"
        },
        {
          "requirement": "Minor safeguards",
          "details": "Where the operator knows or has reason to believe the user is under eighteen, institute measures meeting or exceeding industry standards to prevent the specified categories of output (§ 6(a)(1))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair trade practice",
          "fine": "Enforced through the Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. § 42-110b(a)"
        }
      ],
      "scope": "Operators providing or operating an artificial intelligence companion for a user in Connecticut, with heightened duties where the operator knows or has reason to believe the user is under eighteen (§§ 4, 6(a)(1))",
      "context": "Connecticut's version goes further than California's or New York's in two ways: it requires escalation to clinically appropriate services when a user expresses risk *again after* an initial referral, and it separately requires measures preventing the companion from claiming to be human or generating output that contradicts its own AI disclosure. The second duty closes the gap a disclosure-only rule leaves open — a system that discloses at the top of a session and then insists it is human when asked.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
        "locator": "Conn. PA 26-15 §§ 4, 5, 6",
        "citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-pa26-15-companion-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-pa26-15-companion-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-pa26-15-disclosure",
      "regulation": "connecticut-pa26-15",
      "name": "AI Companion and Subscription Disclosure",
      "requirements": [
        {
          "requirement": "Subscription contract disclosure",
          "details": "No subscription-based provider may enter into or renew a subscription contract with a consumer unless the disclosure set out in the section is made, setting forth at minimum the information required to purchase or maintain the subscription (§ 1(b))"
        },
        {
          "requirement": "Companion notice",
          "details": "Where an AI companion would cause a reasonable individual to believe they are interacting with a human, the operator must provide clear and conspicuous notice that the user is communicating with an AI companion (§ 5(b))"
        },
        {
          "requirement": "Notice form",
          "details": "The notice must be given either in static written form visible throughout the entire interaction, or in audible or written form at the beginning of the first interaction and at intervals thereafter (§ 5(b)(1)-(2))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair trade practice",
          "fine": "A violation of § 1(b) is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a); the private right of action in § 42-110g does not apply and the section provides no basis for a private claim (§ 1(c))"
        }
      ],
      "scope": "Subscription-based providers of AI technology contracting with Connecticut consumers (§ 1), and operators of AI companions whose product would cause a reasonable user to believe they are interacting with a human (§ 5(b))",
      "context": "Two distinct disclosure regimes ride in one act. The § 1 subscription rules attach at contract formation and renewal, which puts AI-specific terms into consumer contract law rather than product design. The § 5(b) companion notice takes effect later, on 2027-01-01, and offers operators a choice between a persistent static notice visible throughout the interaction and a notice repeated at intervals — the persistent option has no counterpart in the California or New York statutes. A second, separately enacted subscription regime starts the same day: Public Act 26-100 § 46 (Substitute HB 5222, signed 2026-06-02) requires subscription-based providers of generative AI systems with more than one million monthly users to disclose usage limits (tokens, images, transcription) and any discretion to reduce functionality, with renewal re-disclosure, enforced by the Attorney General under CUTPA. PA 26-100 does not repeal or amend § 1; the two sections differ in covered actors and required content and both apply from 2026-10-01. A model-generated claim that PA 26-100 replaced § 1 was checked against the retained PA 26-100 text and is not supported.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
        "locator": "Conn. PA 26-15 §§ 1, 5(b)",
        "citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-pa26-15-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-pa26-15-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-10-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-pa26-15-employment-disclosure",
      "regulation": "connecticut-pa26-15",
      "name": "Automated Employment Decision Technology Disclosure",
      "requirements": [
        {
          "requirement": "Developer information duty",
          "details": "The developer must provide the deployer all information the deployer requires to perform its duties under §§ 9 and 10 (§ 8(a))"
        },
        {
          "requirement": "Interaction disclosure",
          "details": "A deployer must ensure each employee or applicant who interacts with the technology is told, in plain language, that they are interacting with it (§ 9(a))"
        },
        {
          "requirement": "Pre-decision written notice",
          "details": "Before an employment-related decision is made using the technology as a substantial factor, the deployer must give the employee or applicant written notice disclosing the deployment, the purpose of the technology and the nature of the decision, the trade name of the technology, the categories of personal data it will analyse and how they will be assessed, the sources of that data, and deployer contact information (§ 10)"
        },
        {
          "requirement": "Trade secret withholding notice",
          "details": "Where information is withheld as a trade secret or otherwise protected, the withholding person must notify the person from whom it is withheld, stating that information is being withheld and the basis (§ 11)"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair trade practice",
          "fine": "Any violation of §§ 8-11 is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a), enforced solely by the Attorney General (§ 12)"
        }
      ],
      "scope": "Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 2027-10-01. The technology is defined as any technology that processes personal data and uses computation to generate an output — prediction, recommendation, classification, ranking, or score — used in employment-related decisions (§ 7)",
      "context": "Two dates matter and they are a year apart: the sections take effect 2026-10-01, but the duties attach only to technology deployed on or after 2027-10-01, which is the date recorded here. The developer-to-deployer information duty in § 8 is the structural piece — it makes the vendor responsible for supplying whatever the employer needs to meet its own disclosure duties, closing the \"our vendor won't tell us\" gap that undercuts comparable laws.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
        "locator": "Conn. PA 26-15 §§ 7-12",
        "citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-pa26-15-employment-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-pa26-15-employment-disclosure-transparency.json",
          "https://everyailaw.com/obligation/connecticut-pa26-15-employment-disclosure-explainability.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-10-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-pa26-15-employment-discrimination",
      "regulation": "connecticut-pa26-15",
      "name": "AI as No Defense to Employment Discrimination",
      "requirements": [
        {
          "requirement": "No automation defense",
          "details": "The use of an automated employment-related decision technology, as defined in § 7, is not a defense against a complaint alleging a discriminatory practice under Conn. Gen. Stat. § 46a-60(b)(1) (§ 13)"
        },
        {
          "requirement": "Anti-bias testing as evidence",
          "details": "The commission or a court may consider evidence of anti-bias testing or similar proactive efforts to avoid the discriminatory practice, including the quality, efficacy, recency, and scope of the testing, its results, and the response to those results (§ 13)"
        }
      ],
      "penalties": [
        {
          "violation": "Discriminatory practice",
          "fine": "Standard remedies for a discriminatory practice under Conn. Gen. Stat. ch. 814c, before the Commission on Human Rights and Opportunities or a court"
        }
      ],
      "scope": "Employers and their agents subject to Conn. Gen. Stat. § 46a-60",
      "context": "Not a disclosure rule but a liability rule, and it is the sharpest incentive in the Act: using an automated employment-related decision technology is expressly not a defense to a discrimination complaint, while evidence of anti-bias testing may be considered in the employer's favour. That asymmetry converts bias testing from a good practice into the only available mitigation, which is why it belongs under bias-prevention rather than with the disclosure provisions.",
      "instrument_notes": null,
      "roles": [
        "employer",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
        "locator": "Conn. PA 26-15 § 13, amending Conn. Gen. Stat. § 46a-60(b)",
        "citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-pa26-15-employment-discrimination.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-pa26-15-employment-discrimination-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-10-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-pa26-15-frontier-reporting",
      "regulation": "connecticut-pa26-15",
      "name": "Frontier Developer Catastrophic Risk Reporting",
      "requirements": [
        {
          "requirement": "Anti-retaliation rules",
          "details": "A frontier developer may not make, adopt, enforce, or enter into any rule, regulation, policy, or contract allowing it to discharge, discipline, or otherwise penalize any employee for activity protected by Conn. Gen. Stat. § 31-51m(b). It also may not authorize any person with authority over a covered employee, or another covered employee with investigative or corrective authority, to discipline or retaliate against that employee for reporting, on reasonable cause, activity posing the specified catastrophic-risk danger (§ 2(b)(1)-(2))"
        },
        {
          "requirement": "Anonymous internal channel",
          "details": "By 2027-01-01, each large frontier developer must establish and maintain a reasonable internal process for a covered employee to anonymously report information believed in good faith to indicate activity posing a specific and substantial danger to public health or safety due to catastrophic risk (§ 2(c)(1)(A))"
        },
        {
          "requirement": "Investigation updates",
          "details": "The developer must give reasonable updates to each reporting employee on the status of the resulting investigation and the actions taken (§ 2(c)(1)(B))"
        },
        {
          "requirement": "Quarterly board sharing",
          "details": "Reports and updates must be shared with the officers and directors at least quarterly (§ 2(c)(2)(A))"
        },
        {
          "requirement": "Accused-officer carve-out",
          "details": "Where a report alleges wrongdoing by an officer or director, neither the report nor its updates may be shared with that person (§ 2(c)(2)(B))"
        },
        {
          "requirement": "Notice of rights",
          "details": "Each frontier developer must give covered employees clear notice of their rights and responsibilities, either through continuous workplace posting plus equivalent notices to new hires and periodic notices to remote workers, or through at least annual written notice received and acknowledged by each covered employee (§ 2(d)(1)-(2))"
        }
      ],
      "penalties": [
        {
          "violation": "Per violation",
          "fine": "Civil penalty not exceeding $1,000 per violation, recoverable by the Attorney General in Hartford superior court, plus injunctive or equitable relief that is not stayed pending appeal. A prevailing state may recover investigation costs, expert witness fees, action costs, and reasonable attorneys' fees; remedies and penalties are cumulative (§ 2(e))"
        }
      ],
      "scope": "Persons doing business in Connecticut who intend to train, initiate training, or train a foundation model using or intending to use more than 10^26 integer or floating-point operations, including original training and subsequent fine-tuning, reinforcement learning, or other material modifications. The internal-process duty applies to large frontier developers whose prior-calendar-year annual gross revenues exceed $500 million together with controlling, controlled, and commonly controlled persons (§ 2(a)(8)-(9))",
      "context": "Section 2 takes effect on 2026-10-01, including the anti-retaliation rules and notice duties for frontier developers. Large frontier developers must establish the internal anonymous reporting process no later than 2027-01-01. Reports and investigation updates go to officers and directors at least quarterly, except that an accused officer or director must not receive the report or its updates. Section 2(c) requires an internal channel and board sharing; it does not require submitting these reports to the state. Catastrophic risk requires a foreseeable and material risk that a frontier model's development, storage, use, or deployment materially contributes to the death of, or serious injury to, more than fifty individuals, or more than $1 billion in damage to or loss of covered property, arising from a single incident. The incident must involve expert-level assistance creating or releasing a chemical, biological, radiological, or nuclear weapon, or conduct without meaningful human oversight, intervention, or supervision that constitutes a cyberattack or would constitute murder, assault, extortion, or theft if performed by an individual. Covered property includes tangible and intangible property but excludes equity (§ 2(a)(1), (3)). The definition excludes risks from otherwise publicly accessible, substantially similar information; lawful federal-government activity; and combinations of a foundation model with other software where the model does not materially increase the risk (§ 2(a)(1)(B)). A covered employee is an employee responsible for assessing, managing, or addressing the specified model-weight security, catastrophic-risk, loss-of-control, or deceptive-technique risks (§ 2(a)(2)); the section does not treat every employee as a covered employee.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
        "locator": "Conn. PA 26-15 § 2",
        "citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-pa26-15-frontier-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-pa26-15-frontier-reporting-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-10-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-pa26-15-provenance",
      "regulation": "connecticut-pa26-15",
      "name": "Generative AI Content Provenance",
      "requirements": [
        {
          "requirement": "Embed provenance data",
          "details": "To the extent commercially and technically reasonable, include provenance data in any audio, image, or video content created or materially altered by the provider's generative AI system, in a manner letting a consumer assess whether the content was so created or altered (§ 15(b)(1)(A))"
        },
        {
          "requirement": "Tamper resistance",
          "details": "Use commercially and technically reasonable methods, including the relevant C2PA standard, to make that provenance data difficult to tamper with, remove, or disassociate from the content (§ 15(b)(1)(B))"
        },
        {
          "requirement": "No personal data required",
          "details": "The duty does not require including information relating to an identified or reasonably identifiable individual in the provenance data (§ 15(b)(2)(A)(i))"
        },
        {
          "requirement": "Trade secret carve-out",
          "details": "The duty does not require disclosure of trade secrets or information otherwise protected from disclosure under state or federal law (§ 15(b)(2)(A)(ii))"
        },
        {
          "requirement": "Materiality floor",
          "details": "\"Materially alter\" excludes minor modifications that do not significantly change perceived content or meaning — brightness, contrast, colour, sharpening, saturation, filters, resizing, scaling, cropping, format conversion, resampling, denoising, and background-noise removal (§ 15(a)(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair trade practice",
          "fine": "A violation is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a), enforced solely by the Attorney General (§ 15)"
        }
      ],
      "scope": "Covered providers — any person who creates, codes, or otherwise produces a generative AI system with more than one million users per month that is publicly accessible to consumers for personal use; federal, state, and local government agencies are excluded (§ 15(a)(2))",
      "context": "The first US statute in this reference to name the Coalition for Content Provenance and Authenticity standard in its own text rather than gesturing at \"widely accepted industry standards\" as California's SB 942 does. The one-million-users-per-month threshold parallels California's covered-provider test, so a provider building C2PA provenance for California largely satisfies Connecticut — the same convergence the EU Article 50 and California alignment produced.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF",
        "locator": "Conn. PA 26-15 § 15",
        "citation": "Conn. Public Act No. 26-15 (Substitute Senate Bill No. 5)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-pa26-15-provenance.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-pa26-15-provenance-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-10-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-sb1295-ag-assessment-access",
      "regulation": "connecticut-sb1295",
      "name": "Attorney General Access to Assessments",
      "requirements": [
        {
          "requirement": "Production on demand",
          "details": "The Attorney General may require a controller to disclose any data protection assessment or impact assessment relevant to an investigation, and the controller must make it available (§ 42-522(d))"
        },
        {
          "requirement": "Evaluation for compliance",
          "details": "The Attorney General may evaluate a produced assessment for compliance with the responsibilities set out in §§ 42-515 to 42-525 (§ 42-522(d))"
        },
        {
          "requirement": "FOIA exemption",
          "details": "Data protection assessments and impact assessments are confidential and exempt from disclosure under the Freedom of Information Act as defined in Conn. Gen. Stat. § 1-200 (§ 42-522(d))"
        },
        {
          "requirement": "No privilege waiver",
          "details": "Where a produced assessment contains information subject to attorney-client privilege or work product protection, disclosure to the Attorney General does not constitute a waiver (§ 42-522(d))"
        },
        {
          "requirement": "Processor assistance",
          "details": "A processor must provide any information necessary to enable the controller to conduct and document the assessments, so the record must be assemblable across the vendor chain (§ 42-529c(a)(2))"
        },
        {
          "requirement": "Minors' harm mitigation plan",
          "details": "Where a minors' assessment finds a heightened risk of harm to minors, the controller must establish and implement a mitigation or elimination plan, and must disclose it to the Attorney General on request not later than ninety days after being notified (§ 42-529b(f))"
        },
        {
          "requirement": "Minors' assessments confidential",
          "details": "Minors' data protection assessments, impact assessments and harm mitigation plans carry the same FOIA exemption and the same no-waiver rule (§ 42-529b(g))"
        }
      ],
      "penalties": [
        {
          "violation": "Failure to produce",
          "fine": "The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action"
        },
        {
          "violation": "Cure period",
          "fine": "**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525"
        }
      ],
      "scope": "Controllers that conduct data protection assessments under § 42-522(b) or profiling impact assessments under § 42-522(c)",
      "context": "This is the provision that converts the § 42-522(c) impact assessment from a paperwork exercise into a retained, producible record. Three design choices matter together: the Attorney General may compel any assessment relevant to an investigation and evaluate it for compliance across §§ 42-515 to 42-525; the assessments are confidential and exempt from the Freedom of Information Act, so a competitor cannot obtain them by request; and disclosure to the Attorney General waives neither attorney-client privilege nor work product protection. The privilege carve-out is the load-bearing piece — without it, counsel would advise against writing anything candid in an assessment, which is precisely how comparable assessment regimes hollow out.",
      "instrument_notes": null,
      "roles": [
        "controller"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
        "locator": "Conn. Gen. Stat. § 42-522(d) (PA 25-113 § 11); parallel minors' provision at § 42-529b(g) (PA 25-113 § 16)",
        "citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-sb1295-ag-assessment-access.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-sb1295-ag-assessment-access-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-sb1295-llm-training-disclosure",
      "regulation": "connecticut-sb1295",
      "name": "Large Language Model Training Disclosure",
      "requirements": [
        {
          "requirement": "LLM training statement",
          "details": "The privacy notice must include a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models (§ 42-520(b)(1)(H))"
        },
        {
          "requirement": "Notice currency",
          "details": "The same notice must state the most recent month and year during which the controller updated it (§ 42-520(b)(1)(I)), so a stale LLM training statement is visible on its face"
        },
        {
          "requirement": "Publication",
          "details": "The notice must be published through a conspicuous hyperlink containing the word \"privacy\" on the web site home page, on the app store or download page and in the app settings menu where applicable, in every language in which the controller offers the covered product or service, and in a manner reasonably accessible to and usable by individuals with disabilities (§ 42-520(b)(2))"
        },
        {
          "requirement": "Material change notice",
          "details": "Where a controller makes a retroactive material change to its privacy notice or practices, it must comply with the change-notification duties in § 42-520(b)(3)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action"
        },
        {
          "violation": "Cure period",
          "fine": "**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525"
        }
      ],
      "scope": "Every controller subject to the CTDPA that is required to publish a privacy notice under § 42-520(b)(1)",
      "context": "Tagged `sleeper` because the duty is AI-specific but lives inside a general consumer privacy act, so it binds by controller status rather than by anything the controller does with models. Every organization over the § 42-516 threshold — retailers, insurers, hospitals, employers — must now take a position in its published privacy notice on whether it collects, uses or sells personal data to train large language models, including the position that it does not. That makes it the first US statutory disclosure aimed squarely at training-data provenance and the cheapest available discovery tool: the notice is a dated public statement the Attorney General can hold a controller to. Note the statute says \"large language models\" specifically, not \"artificial intelligence\" or \"automated decision systems\", so a controller training a non-language model is outside the literal text.",
      "instrument_notes": null,
      "roles": [
        "controller"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
        "locator": "Conn. Gen. Stat. § 42-520(b)(1)(H) (PA 25-113 § 9)",
        "citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-sb1295-llm-training-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-sb1295-llm-training-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-sb1295-minors-profiling",
      "regulation": "connecticut-sb1295",
      "name": "Minors' Profiling Consent and Assessment",
      "requirements": [
        {
          "requirement": "Consent before minors' profiling",
          "details": "No controller offering an online service, product or feature to known minors may process a minor's personal data for profiling in furtherance of any automated decision producing a legal or similarly significant effect concerning the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care services, or access to essential goods or services, unless reasonably necessary to provide the service, and unless the controller obtains the minor's consent (§ 42-529a(b)(3)(A) and (B))"
        },
        {
          "requirement": "Parental consent under thirteen",
          "details": "Where the minor is younger than thirteen, the consent of a parent or legal guardian is required; compliance with the verifiable parental consent requirements of COPPA, 15 USC 6501 et seq., satisfies that requirement (§ 42-529a(b)(3)(B))"
        },
        {
          "requirement": "No dark-pattern consent",
          "details": "The consent mechanism may not be designed to, or manipulated with the effect of, substantially subverting or impairing user autonomy, decision-making or choice (§ 42-529a(c)(1)(A))"
        },
        {
          "requirement": "Impact assessment on any profiling",
          "details": "A controller offering an online service, product or feature to known minors that engages in any profiling based on those consumers' personal data must conduct an impact assessment for that service (§ 42-529b(b))"
        },
        {
          "requirement": "Six assessment elements",
          "details": "Purpose, intended use cases, deployment context and benefits where the service profiles for legal-effect decisions; heightened-risk analysis for minors and mitigation steps; input categories and outputs; customization data categories; transparency measures, including in-use disclosure that the service is being used for profiling; and post-deployment monitoring and user safeguards, including oversight, use and learning processes (§ 42-529b(b)(1)-(6))"
        },
        {
          "requirement": "Review on material change",
          "details": "The controller must review the data protection assessment or impact assessment as necessary to account for any material change to the processing or profiling operations of the service (§ 42-529b(c)(1))"
        },
        {
          "requirement": "Three-year retention",
          "details": "Documentation must be maintained for the longer of the three-year period beginning when the processing or profiling operations cease, or as long as the controller offers the service (§ 42-529b(c)(2))"
        },
        {
          "requirement": "Reasonable-care presumption",
          "details": "A controller that complied with § 42-529b enjoys a rebuttable presumption of reasonable care under § 42-529a(a) in an Attorney General enforcement action brought under § 42-529e"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "The act sets no penalty amount. A violation of §§ 42-529 to 42-529d is an unfair trade practice under Conn. Gen. Stat. § 42-110b(a), enforced **solely** by the Attorney General under § 42-529e(a), which also bars any private right of action and any action under § 42-110g"
        },
        {
          "violation": "Cure period",
          "fine": "**A separate regime from the general CTDPA, and it sunset later.** The mandatory notice window in § 42-529e(b) ran 2024-10-01 to 2025-12-31. Its mechanic also differs: the controller had 30 days to notify the Attorney General either that no violation occurred or that it had cured and taken preventive measures, and acceptance removed civil liability. Since 2026-01-01, § 42-529e(c) makes that opportunity discretionary on the same seven factors as § 42-525(c). P.A. 25-113 does not amend § 42-529e"
        }
      ],
      "scope": "Controllers offering any online service, product or feature to consumers they have actual knowledge, or wilfully disregard, are minors — any consumer under eighteen. The consent gate covers profiling in furtherance of any automated decision producing a legal or similarly significant effect concerning the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care services, or access to essential goods or services",
      "context": "Filed under `risk-assessment` rather than `data-governance` because the ongoing compliance process the section creates is the § 42-529b(b) impact assessment — six enumerated elements, review on any material change to the profiling operations, and documentation kept for the longer of three years after the operations cease or as long as the service is offered. The consent gate in § 42-529a(b)(3)(B) is a condition on a single processing activity rather than a sustained process, and § 42-529a(a) ties the two together by giving a controller that complies with § 42-529b a rebuttable presumption of reasonable care in any Attorney General enforcement action — the assessment is the safe harbor, so it is where the compliance weight sits. Two scope moves are easy to miss. The consent gate was broadened from profiling in furtherance of any **fully** automated decision to **any** automated decision, so a human reviewer in the loop no longer takes a minor's profiling outside it — the same widening the act made to the adult opt-out in § 42-518. And the assessment trigger in § 42-529b(b) is any profiling at all by a service offered to minors, not only legal-effect profiling; only the first of the six elements is qualified by legal or similarly significant effects. Separately, § 42-529d(d)(4) permits processing a minor's personal data for legal-effect profiling solely to detect or correct bias, on five conditions including deletion once the processing is complete, pseudonymization and other industry-standard security measures, strict documented access controls, and no third-party transmission or access — a construction rule creating a safe harbor rather than an obligation, so it is recorded here rather than as its own provision.",
      "instrument_notes": null,
      "roles": [
        "controller"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
        "locator": "Conn. Gen. Stat. §§ 42-529a(b)(3), 42-529b(b), 42-529b(c) (PA 25-113 §§ 15, 16); bias-testing carve-out at § 42-529d(d)(4) (PA 25-113 § 18)",
        "citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-sb1295-minors-profiling.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-sb1295-minors-profiling-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-sb1295-opt-out",
      "regulation": "connecticut-sb1295",
      "name": "Expanded Consumer Opt-Out",
      "requirements": [
        {
          "requirement": "Expanded opt-out",
          "details": "Consumers may opt out of profiling in furtherance of automated decisions with legal/significant effects — \"solely automated\" qualifier removed; now covers human-in-the-loop profiling"
        },
        {
          "requirement": "Right to confirm",
          "details": "Consumers may confirm whether their data is being processed for profiling"
        },
        {
          "requirement": "Right to explanation",
          "details": "Consumers may request explanation of profiling outcomes affecting them"
        },
        {
          "requirement": "Data review and correction",
          "details": "Consumers may review data used in profiling decisions and correct inaccurate data"
        },
        {
          "requirement": "Re-evaluation",
          "details": "Consumers may request re-evaluation after correcting data (especially in housing contexts)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action"
        },
        {
          "violation": "Cure period",
          "fine": "**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525"
        }
      ],
      "scope": "controllers (entities subject to CTDPA)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "controller"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
        "locator": "Conn. Gen. Stat. § 42-518(a)(1), (a)(5)(C), (a)(6) (as amended by P.A. 25-113 § 8)",
        "citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-sb1295-opt-out.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-sb1295-opt-out-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "connecticut-sb1295-profiling-impact-assessment",
      "regulation": "connecticut-sb1295",
      "name": "Profiling Impact Assessment",
      "requirements": [
        {
          "requirement": "Assessment trigger",
          "details": "Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer must conduct an impact assessment for that profiling (§ 42-522(c))"
        },
        {
          "requirement": "Purpose and deployment context",
          "details": "A statement disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the profiling (§ 42-522(c)(1))"
        },
        {
          "requirement": "Heightened-risk analysis",
          "details": "An analysis of whether the profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer and, if so, the nature of that risk and the steps taken to mitigate it (§ 42-522(c)(2))"
        },
        {
          "requirement": "Inputs and outputs",
          "details": "A description of the main categories of personal data processed as inputs for the profiling and of the outputs the profiling produces (§ 42-522(c)(3))"
        },
        {
          "requirement": "Customization data",
          "details": "An overview of the main categories of personal data used to customize the profiling, where the controller used data to customize it (§ 42-522(c)(4))"
        },
        {
          "requirement": "Performance metrics and limitations",
          "details": "Any metrics used to evaluate the performance and known limitations of the profiling (§ 42-522(c)(5))"
        },
        {
          "requirement": "Transparency measures",
          "details": "A description of any transparency measures taken concerning the profiling, including measures disclosing to consumers that the controller is engaged in the profiling while it is engaged in it (§ 42-522(c)(6))"
        },
        {
          "requirement": "Post-deployment monitoring",
          "details": "A description of the post-deployment monitoring and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling (§ 42-522(c)(7))"
        },
        {
          "requirement": "Not retroactive",
          "details": "The impact assessment requirement applies only to processing activities created or generated on or after 2026-08-01 (§ 42-522(g)(2))"
        },
        {
          "requirement": "Batching permitted",
          "details": "A single data protection assessment or impact assessment may address a comparable set of processing operations that include similar activities (§ 42-522(e))"
        },
        {
          "requirement": "Other-law equivalence",
          "details": "An assessment conducted to comply with another applicable law or regulation satisfies this section if it is reasonably similar in scope and effect (§ 42-522(f))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action"
        },
        {
          "violation": "Cure period",
          "fine": "**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525"
        }
      ],
      "scope": "Every controller subject to the CTDPA that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer (§ 42-522(c)). The applicability threshold in § 42-516 was lowered to 35,000 consumers by the same act",
      "context": "This is a second, separate assessment sitting alongside the CTDPA data protection assessment in § 42-522(b) — a controller doing legal-effect profiling now owes both, and the two have different content. The seven elements read as an AI model card written into privacy law: inputs, outputs, customization data, performance metrics, known limitations, transparency measures, and post-deployment monitoring. § 42-522(g)(2) is the date that matters operationally: the impact assessment duty applies only to processing activities created or generated **on or after 2026-08-01** and is expressly not retroactive, one month later than the section's own 2026-07-01 effective date, and a separate clock from the 2023-07-01 line that governs data protection assessments under § 42-522(g)(1).",
      "instrument_notes": null,
      "roles": [
        "controller"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF",
        "locator": "Conn. Gen. Stat. § 42-522(c), with the applicability rule in § 42-522(g)(2) (PA 25-113 § 11)",
        "citation": "Conn. Gen. Stat. §§ 42-515 to 42-529d (Public Act 25-113)"
      },
      "of": {
        "term": "https://everyailaw.com/term/connecticut-sb1295-profiling-impact-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/connecticut-sb1295-profiling-impact-assessment-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-bias-data-basis",
      "regulation": "eu-ai-act",
      "name": "Bias Detection Data Basis (Article 4a)",
      "requirements": [
        {
          "requirement": "Strict necessity",
          "details": "Processing is permitted only to the extent strictly necessary for bias detection and correction under Article 10(2)(f)-(g) (Article 4a(1))"
        },
        {
          "requirement": "No alternative data",
          "details": "Bias detection and correction must be impossible to achieve effectively with other data, including synthetic or anonymised data (Article 4a(1)(a))"
        },
        {
          "requirement": "Technical limits",
          "details": "Re-use must be technically limited, with state-of-the-art security and privacy-preserving measures including pseudonymisation (Article 4a(1)(b))"
        },
        {
          "requirement": "Access control",
          "details": "Strict, documented access controls, confidentiality obligations, and authorised-person-only access (Article 4a(1)(c))"
        },
        {
          "requirement": "No onward transfer",
          "details": "The special-category data must not be transmitted, transferred, or otherwise accessed by other parties (Article 4a(1)(d))"
        },
        {
          "requirement": "Deletion",
          "details": "Delete once the bias is corrected or the retention period ends, whichever is first (Article 4a(1)(e))"
        },
        {
          "requirement": "Documented justification",
          "details": "GDPR/EUDPR/LED records of processing must state why the processing was strictly necessary and why other data would not achieve the objective (Article 4a(1)(f))"
        },
        {
          "requirement": "Extension beyond high-risk",
          "details": "Providers and deployers of other AI systems and models, and deployers of high-risk systems, may rely on the same basis where strictly necessary to address biases affecting health, safety, fundamental rights, or prohibited discrimination — subject to all Article 4a(1) safeguards (Article 4a(2))"
        },
        {
          "requirement": "No duty created",
          "details": "Article 4a(2) expressly creates no obligation to carry out bias detection and correction"
        }
      ],
      "penalties": [
        {
          "violation": "Processing outside the permission",
          "fine": "Processing that does not meet Article 4a conditions cannot rely on this permission; applicable data-protection requirements and enforcement remain separate. This is not a conclusion on every alternative legal basis (Article 4a(1)-(2))."
        },
        {
          "violation": "AI Act enforcement",
          "fine": "Article 4a is not enumerated in Article 99(4), but amended Article 99(1) covers national penalties for any operator infringement. For operators within the AI Office competence defined in Article 75(1), Article 75c(4)(a) separately reaches any applicable provision, including unlisted provisions, through the Article 99(4) tier. This does not establish a universal Article 4a fine or immunity."
        },
        {
          "violation": "Scoped Article 75c route",
          "fine": "Where that route applies, up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher, with the lower-of rule for SMEs and SMCs (Article 99(4), (6), and (6a)). Article 75(1) system categories and exclusions apply; deployers fall within that competence only if they are also the provider or part of the same undertaking."
        }
      ],
      "scope": "Providers of high-risk AI systems (Article 4a(1)); providers and deployers of other AI systems and models, and deployers of high-risk AI systems (Article 4a(2))",
      "context": "A permission, not a mandate — Article 4a(2) states expressly that it creates no obligation to conduct bias detection. It supplies an express AI Act route to processing special-category personal data for covered bias work, with six cumulative safeguards for anyone who uses it; other potential data-protection-law bases require their own analysis. Replaces the former Article 10(5), which was limited to high-risk training data.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Article 4a",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-bias-data-basis.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-bias-data-basis-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-27",
        "verified": "2026-08-02",
        "checked": "2026-08-23",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-conformity",
      "regulation": "eu-ai-act",
      "name": "Conformity Assessment",
      "requirements": [
        {
          "requirement": "Conformity assessment",
          "details": "Must undergo before placing on market or putting into service (Article 43)"
        },
        {
          "requirement": "Annex III assessment route",
          "details": "For Annex III point 1 systems, application of harmonised standards or common specifications permits a choice between Annex VI internal control and Annex VII assessment with a notified body; Article 43(1) requires Annex VII in its listed cases where standards or specifications are unavailable or unapplied, harmonised standards are applied only in part, or a published restriction affects the relevant part. Annex III points 2-8 follow Annex VI internal control without notified-body involvement (Article 43(1)-(2))"
        },
        {
          "requirement": "CE marking",
          "details": "Required for high-risk AI systems once assessment complete (Article 48)"
        },
        {
          "requirement": "Quality management",
          "details": "Must establish quality management system (Article 17); implementation must be proportionate to the size of the provider's organisation, in particular for SMEs, start-ups, and small mid-cap enterprises, without lowering the rigour needed for compliance (Article 17(2), as replaced by Regulation (EU) 2026/1744)"
        },
        {
          "requirement": "Documentation",
          "details": "Keep the technical documentation, quality-management-system documentation, approved changes, and notified-body decisions and certificates at national-authority disposal for 10 years after the high-risk system is placed on the market or put into service (Article 18). SMEs, start-ups, and SMCs may provide the Annex IV elements in simplified form using the Commission-issued form (Article 11(1), as amended)"
        },
        {
          "requirement": "Conditional route without a third party",
          "details": "Where Annex I Section A legislation permits a route without third-party assessment on application of harmonised standards ensuring all relevant sectoral requirements, that option additionally requires application of harmonised standards or applicable Article 41 common specifications covering all Chapter III Section 2 requirements. Subject to those conditions, high-risk classification or inclusion of a high-risk AI safety component does not by itself force third-party assessment (Article 43(3), as replaced)"
        },
        {
          "requirement": "Annex III phasing",
          "details": "Annex III high-risk systems: 2027-12-02 (deferred from 2026-08-02 by Regulation (EU) 2026/1744). Covered Annex I Section A high-risk systems (including product-safety systems such as medical devices): 2028-08-02 (deferred from 2027-08-02). Notified bodies already notified under Annex I Section A legislation must apply for designation under the AI Act by 2028-01-28"
        }
      ],
      "penalties": [
        {
          "violation": "Provider non-compliance with Article 16, including conformity duties",
          "fine": "Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date."
        }
      ],
      "scope": "Providers of high-risk AI systems subject to Article 16(f)-(h), within Article 2 scope, before placing them on the market or putting them into service; Article 43(3) governs Annex I Section A products, while Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products",
      "context": "The Article 16(f)-(h) provider duties to ensure conformity assessment, draw up the declaration, and affix CE marking are in Chapter III Section 3: they apply on 2027-12-02 to Article 6(2)/Annex III systems and on 2028-08-02 to covered Article 6(1)/Annex I systems under amended Article 113(c), subject to Article 111 transitions. The `Effective` field carries the earlier date for those duties. Articles 40-49 are in Section 5 and are not themselves included in that Sections 1-3 deferral; Article 113 retains the general 2026-08-02 application date for provisions not otherwise excepted.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Articles 11, 16(f)-(h), 17-18, 40-49",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-conformity.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-conformity-conformity-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-12-02",
        "verified": "2026-09-01",
        "checked": "2026-09-01",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-fria",
      "regulation": "eu-ai-act",
      "name": "Fundamental Rights Impact Assessment (Article 27)",
      "requirements": [
        {
          "requirement": "Pre-deployment assessment",
          "details": "Assess the impact on fundamental rights before putting the high-risk system into use (Article 27(1))"
        },
        {
          "requirement": "Process description",
          "details": "Describe the deployer processes in which the system will be used, in line with its intended purpose (Article 27(1)(a))"
        },
        {
          "requirement": "Period and frequency",
          "details": "Describe the period and frequency of intended use (Article 27(1)(b))"
        },
        {
          "requirement": "Affected persons",
          "details": "Identify the categories of natural persons and groups likely to be affected in the specific context (Article 27(1)(c))"
        },
        {
          "requirement": "Specific harms",
          "details": "Identify specific risks of harm to those categories, using the provider information supplied under Article 13 (Article 27(1)(d))"
        },
        {
          "requirement": "Human oversight",
          "details": "Describe implementation of human oversight measures per the instructions for use (Article 27(1)(e))"
        },
        {
          "requirement": "Response measures",
          "details": "Set out measures if risks materialise, including internal governance arrangements and complaint mechanisms (Article 27(1)(f))"
        },
        {
          "requirement": "First use and updates",
          "details": "Applies to first use; earlier assessments (including a provider's) may be relied on in similar cases, and the assessment must be updated when elements change (Article 27(2))"
        },
        {
          "requirement": "Notify authority",
          "details": "Notify the market surveillance authority of the results with the filled-out template; deployers may be exempt from notification in Article 46(1) cases (Article 27(3))"
        },
        {
          "requirement": "DPIA cross-reference",
          "details": "Where an obligation is already met by a GDPR Article 35 or LED Article 27 data protection impact assessment, the deployer may cross-reference the relevant sections or incorporate parts of it (Article 27(4), as replaced by Regulation (EU) 2026/1744)"
        },
        {
          "requirement": "AI Office template",
          "details": "The AI Office must develop a questionnaire template, including an automated tool, allowing DPIA cross-references (Article 27(5), as replaced)"
        }
      ],
      "penalties": [
        {
          "violation": "Article 27 non-compliance under national enforcement",
          "fine": "Member State penalties and enforcement measures under Article 99(1). Article 27 is not expressly listed in Article 99(4); there is no uniform Article 99(4) FRIA maximum established by that list. National rules determine the extent of fines on public authorities and bodies under Article 99(8)"
        },
        {
          "violation": "Article 27 non-compliance within AI Office competence",
          "fine": "Article 75c(4)(a) extends the Article 99(4) tier to applicable provisions otherwise unlisted: up to EUR 15M or, for an undertaking, 3% of preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC lower-cap rules in Article 99(6)/(6a). This route applies only within Article 75(1): specified same-undertaking GPAI-based systems (with listed exclusions), or systems constituting or integrated into designated very large online platforms/search engines; deployers must also be the provider or belong to the same undertaking"
        }
      ],
      "scope": "Deployers that are bodies governed by public law or private entities providing public services, and any deployer of Annex III point 5(b)-(c) systems (creditworthiness assessment, life and health insurance risk assessment and pricing); Annex III point 2 (critical infrastructure) systems are excluded",
      "context": "The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: relevant parts of a GDPR or LED data protection impact assessment may be cross-referenced where they already meet particular FRIA obligations; the remaining FRIA duties still apply, and the AI Office must ship a questionnaire template.",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Article 27",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-fria.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-fria-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-12-02",
        "verified": "2026-08-02",
        "checked": "2026-08-24",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-high-risk-transparency",
      "regulation": "eu-ai-act",
      "name": "High-Risk Transparency and Instructions for Use (Article 13)",
      "requirements": [
        {
          "requirement": "Operational transparency",
          "details": "High-risk systems must be designed and developed so their operation is sufficiently transparent to enable deployers to interpret output and use it appropriately (Article 13(1))"
        },
        {
          "requirement": "Instructions for use",
          "details": "High-risk systems must be accompanied by instructions for use in an appropriate digital format or otherwise, containing concise, complete, correct and clear information relevant, accessible and comprehensible to deployers (Article 13(2))"
        },
        {
          "requirement": "Provider identity",
          "details": "Instructions must state the identity and contact details of the provider and, where applicable, its authorised representative (Article 13(3)(a))"
        },
        {
          "requirement": "Capabilities and limitations",
          "details": "Instructions must state intended purpose, the accuracy, robustness and cybersecurity metrics the system was validated against, foreseeable circumstances affecting those levels, and risks arising under intended use or reasonably foreseeable misuse (Article 13(3)(b))"
        },
        {
          "requirement": "Explainability information",
          "details": "Where applicable, instructions must describe technical capabilities to provide information explaining the system's output (Article 13(3)(b)(iv))"
        },
        {
          "requirement": "Group performance and input data",
          "details": "Where appropriate, instructions must state performance regarding specific persons or groups, and input-data specifications or relevant information about training, validation and testing datasets (Article 13(3)(b)(v)-(vi))"
        },
        {
          "requirement": "Output interpretation",
          "details": "Where applicable, instructions must provide information enabling deployers to interpret the system's output and use it appropriately (Article 13(3)(b)(vii))"
        },
        {
          "requirement": "Human oversight measures",
          "details": "Instructions must describe the human oversight measures built in under Article 14, including technical measures facilitating output interpretation by deployers (Article 13(3)(d))"
        },
        {
          "requirement": "Pre-determined changes",
          "details": "Where applicable, instructions must describe the changes to the system and its performance which the provider pre-determined at the moment of the initial conformity assessment (Article 13(3)(c))"
        },
        {
          "requirement": "Resources, lifetime and maintenance",
          "details": "Instructions must state computational and hardware resources needed, expected lifetime, and any necessary maintenance and care measures, including their frequency and software updates (Article 13(3)(e))"
        },
        {
          "requirement": "Logging mechanisms",
          "details": "Where relevant, instructions must describe mechanisms enabling deployers to collect, store and interpret logs under Article 12 (Article 13(3)(f))"
        }
      ],
      "penalties": [
        {
          "violation": "Provider non-compliance through Article 16(a)",
          "fine": "Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date."
        },
        {
          "violation": "Incorrect, incomplete or misleading information supplied to notified bodies or national competent authorities in reply to a request",
          "fine": "Up to EUR 7.5 million; for undertakings, up to 1% of total worldwide annual turnover for the preceding financial year or EUR 7.5 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(5), (6), and (6a))"
        }
      ],
      "scope": "Providers of high-risk AI systems. The duty runs to the instructions for use supplied to deployers, not to end users. Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products",
      "context": "Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Article 13",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-high-risk-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-high-risk-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-12-02",
        "verified": "2026-09-01",
        "checked": "2026-09-01",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-human-oversight",
      "regulation": "eu-ai-act",
      "name": "Human Oversight (Article 14)",
      "requirements": [
        {
          "requirement": "Effective oversight",
          "details": "High-risk AI must enable oversight by natural persons (Article 14(1))"
        },
        {
          "requirement": "Proportionate enablement",
          "details": "Oversight measures must be commensurate with the risks, autonomy, and context of use; the system must be provided so assigned natural persons are enabled, as appropriate and proportionate, to perform the Article 14(4)(a)-(e) functions below (Article 14(3)-(4))"
        },
        {
          "requirement": "Understand capabilities",
          "details": "Enable assigned persons to properly understand relevant system capacities and limitations (Article 14(4)(a))"
        },
        {
          "requirement": "Monitor for anomalies",
          "details": "Enable assigned persons to duly monitor operation, including detecting and addressing unexpected performance, anomalies, and dysfunctions (Article 14(4)(a))"
        },
        {
          "requirement": "Address automation bias",
          "details": "Enable assigned persons to remain aware of automation-bias risk in oversight (Article 14(4)(b))"
        },
        {
          "requirement": "Interpret output",
          "details": "Enable assigned persons to correctly interpret output, taking account of available interpretation tools and methods (Article 14(4)(c))"
        },
        {
          "requirement": "Override/reverse",
          "details": "Enable assigned persons to decide not to use the system or to disregard, override, or reverse its output (Article 14(4)(d))"
        },
        {
          "requirement": "Intervene or halt",
          "details": "Enable assigned persons to intervene or interrupt system operation via a stop button or similar procedure that allows a halt in a safe state (Article 14(4)(e))"
        },
        {
          "requirement": "Competent personnel",
          "details": "Deployers must assign persons with necessary competence, training, authority, and support (Article 26(2))"
        },
        {
          "requirement": "Dual verification (biometric)",
          "details": "For Annex III point 1(a) systems (remote biometric ID), oversight measures must ensure that the deployer takes no action or decision on the basis of the resulting identification unless that identification is separately verified and confirmed by at least two natural persons with necessary competence, training, and authority. The two-person verification requirement does not apply to systems used for law enforcement, migration, border control, or asylum where Union or national law considers that requirement disproportionate (Article 14(5))"
        }
      ],
      "penalties": [
        {
          "violation": "Provider non-compliance through Article 16(a), or deployer non-compliance with Article 26",
          "fine": "Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date."
        }
      ],
      "scope": "Providers and deployers of high-risk AI systems within Article 2 scope; Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products",
      "context": "Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Article 14, Article 26(2)",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-12-02",
        "verified": "2026-06-18",
        "checked": "2026-08-29",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-literacy",
      "regulation": "eu-ai-act",
      "name": "AI Literacy (Article 4)",
      "requirements": [
        {
          "requirement": "Support AI literacy",
          "details": "Providers and deployers must take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf (Article 4(1), as replaced by Regulation (EU) 2026/1744 from 2026-07-27)"
        },
        {
          "requirement": "Context-specific",
          "details": "Measures must take account of technical knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are used (Article 4(1))"
        },
        {
          "requirement": "No guaranteed level",
          "details": "The obligation expressly does not require providers or deployers to guarantee any specific level of AI literacy of any individual (Article 4(1), second sentence — added by the Digital Omnibus)"
        },
        {
          "requirement": "Commission support",
          "details": "The Commission and Member States must support providers and deployers, in particular SMEs, and the Commission must publish practical compliance examples on the single information platform (Article 4(2), Article 62(3)(b))"
        },
        {
          "requirement": "Board recommendations",
          "details": "The AI Board must adopt recommendations, taking account of European competence frameworks, including common objectives (Article 4(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Article 4 non-compliance",
          "fine": "Penalties and other enforcement measures depend on applicable national rules under Article 99(1). Article 99(4) does not establish a uniform Article 4 fine. For operators within the AI Office's Article 75(1) competence, Article 75c(4)(a) separately applies Article 99(4) ceilings, subject to Article 99(6) and (6a)."
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "locator": "Article 4",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-literacy.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-literacy-ai-literacy.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-02-02",
        "verified": "2026-08-02",
        "checked": "2026-08-29",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-record-keeping",
      "regulation": "eu-ai-act",
      "name": "Record-Keeping & Automatic Logging (Article 12)",
      "requirements": [
        {
          "requirement": "Automatic logging capability",
          "details": "High-risk AI systems must technically allow automatic recording of events over the system's lifetime (Article 12(1))"
        },
        {
          "requirement": "Traceability",
          "details": "Logs must enable risk identification and post-market monitoring"
        },
        {
          "requirement": "Deployer monitoring",
          "details": "Logs must support operational monitoring by deployers (Article 26(5))"
        },
        {
          "requirement": "Log retention",
          "details": "Providers and deployers must keep automatically generated logs under their control for a period appropriate to the system's intended purpose, of at least six months unless applicable Union or national law provides otherwise, particularly data-protection law (Articles 19(1), 26(6)); financial institutions keep logs under the relevant Union financial-services rules (Articles 19(2), 26(6))"
        },
        {
          "requirement": "Tamper-evident storage",
          "details": "Editorial best practice, not a statutory requirement. Articles 12, 19 and 26 do not use \"immutable\" or \"tamper-evident\", and no specific provision requiring log integrity controls has been identified"
        },
        {
          "requirement": "Biometric ID specifics",
          "details": "Remote biometric systems (Annex III point 1(a)) must log period of use, reference database, input data for which the search led to a match, and verifying personnel (Article 12(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Provider non-compliance through Article 16(a) and 16(e) log keeping, or deployer non-compliance with Article 26(5)-(6)",
          "fine": "Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date."
        }
      ],
      "scope": "providers, deployers",
      "context": "Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enacted",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Article 12, Article 19, Article 26(5)-(6)",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-12-02",
        "verified": "2026-07-21",
        "checked": "2026-08-25",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-risk-management",
      "regulation": "eu-ai-act",
      "name": "Risk Management (Article 9)",
      "requirements": [
        {
          "requirement": "Risk management system",
          "details": "Establish, implement, document, and maintain a risk management system (Article 9(1))"
        },
        {
          "requirement": "Identify and analyze",
          "details": "Identify known and reasonably foreseeable risks to health, safety, and fundamental rights during intended use (Article 9(2)(a))"
        },
        {
          "requirement": "Estimate and evaluate",
          "details": "Estimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse conditions (Article 9(2)(b))"
        },
        {
          "requirement": "Post-market evaluation",
          "details": "Evaluate risks based on data from post-market monitoring (Article 9(2)(c))"
        },
        {
          "requirement": "Risk mitigation",
          "details": "Adopt appropriate and targeted measures addressing the risks identified under Article 9(2)(a) (Article 9(2)(d))"
        },
        {
          "requirement": "Risk boundary",
          "details": "Article 9 concerns only risks reasonably mitigated or eliminated through system development or design, or provision of adequate technical information (Article 9(3))"
        },
        {
          "requirement": "Design-based reduction",
          "details": "Eliminate or reduce risks through adequate design and development where technically feasible (Article 9(5)(a))"
        },
        {
          "requirement": "Residual risk",
          "details": "Ensure residual risk associated with each hazard and overall residual risk is judged acceptable (Article 9(5))"
        },
        {
          "requirement": "Testing",
          "details": "Test to identify appropriate risk management measures and ensure consistent performance and compliance; tested against prior defined metrics and probabilistic thresholds (Article 9(6)-(8))"
        },
        {
          "requirement": "Iterative review",
          "details": "Plan and run the risk management system as a continuous iterative process throughout the entire lifecycle, with regular systematic review and updating (Article 9(2))"
        },
        {
          "requirement": "Children and vulnerable groups",
          "details": "When implementing the risk management system, providers must consider whether the system is likely to adversely affect persons under 18 and, as appropriate, other vulnerable groups (Article 9(9))"
        },
        {
          "requirement": "Other Union-law risk processes",
          "details": "Providers subject to internal risk-management requirements under other Union law may include or combine Article 9(1)-(9) aspects in those procedures (Article 9(10))"
        }
      ],
      "penalties": [
        {
          "violation": "Provider non-compliance through Article 16(a)",
          "fine": "Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date."
        }
      ],
      "scope": "Providers of high-risk AI systems within Article 2 scope; Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products",
      "context": "Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Article 9",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-risk-management.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-risk-management-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-12-02",
        "verified": "2026-06-18",
        "checked": "2026-08-26",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-ai-act-transparency",
      "regulation": "eu-ai-act",
      "name": "Transparency Disclosure (Article 50)",
      "requirements": [
        {
          "requirement": "Interaction disclosure",
          "details": "Providers must design systems intended to interact directly with natural persons so those persons are informed they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person (Article 50(1))"
        },
        {
          "requirement": "Synthetic content marking",
          "details": "Providers of systems, including general-purpose AI systems, generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable as far as technically feasible, taking into account content-specific limitations, implementation costs and the generally acknowledged state of the art (Article 50(2))"
        },
        {
          "requirement": "Emotion recognition and biometric categorisation notice",
          "details": "Deployers must inform natural persons exposed to emotion recognition or biometric categorisation systems of their operation (Article 50(3))"
        },
        {
          "requirement": "Deepfake disclosure",
          "details": "Deployers generating or manipulating image, audio or video constituting a deepfake must disclose that the content is artificially generated or manipulated (Article 50(4))"
        },
        {
          "requirement": "Public-interest text disclosure",
          "details": "Deployers of systems generating or manipulating text published to inform the public on matters of public interest must disclose its artificial generation or manipulation. This does not apply where the use is authorised for specified criminal-law purposes, or where human review or editorial control occurs and a natural or legal person holds editorial responsibility (Article 50(4))"
        },
        {
          "requirement": "Disclosure timing and accessibility",
          "details": "Information under Article 50(1)-(4) must be clear and distinguishable, provided by the first interaction or exposure, and conform to applicable accessibility requirements (Article 50(5))"
        },
        {
          "requirement": "Disclosure exceptions",
          "details": "Article 50(1) excepts certain law-authorised criminal-law systems unless available for public crime reporting; Article 50(2) excepts limited assistive editing or insubstantial changes and certain law-authorised criminal-law uses; Article 50(3) excepts certain permitted criminal-law uses. Article 50(4) excepts law-authorised criminal-law uses; for deepfakes forming part of an evidently artistic, creative, satirical, fictional or analogous work or programme, disclosure remains required but is limited to an appropriate statement of the existence of generated or manipulated content that does not hamper the work's display or enjoyment (Article 50(1)-(4))"
        },
        {
          "requirement": "Generative AI grace period",
          "details": "Providers of systems, including general-purpose AI systems, generating synthetic audio, image, video or text that were placed on the market before 2026-08-02 must take the necessary steps to comply with Article 50(2) by 2026-12-02. This transition concerns Article 50(2), not the other disclosure duties (Article 111(4), inserted by Regulation (EU) 2026/1744)"
        },
        {
          "requirement": "Marking codes of practice",
          "details": "The Commission facilitates Union-level codes of practice for detection, marking and labelling of AI-generated or manipulated content, assesses their adequacy for Article 50(2) and (4), and may impose common rules by implementing act if a code is inadequate (Article 50(7), as replaced by Regulation (EU) 2026/1744)"
        }
      ],
      "penalties": [
        {
          "violation": "Transparency non-compliance (Article 50)",
          "fine": "Up to EUR 15M or, for an undertaking, 3% of its preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC ceilings (Article 99(4)(g))"
        },
        {
          "violation": "Incorrect, incomplete or misleading information in response to a request from a notified body or national competent authority",
          "fine": "Up to EUR 7.5M or, for an undertaking, 1% of its preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC ceilings (Article 99(5))"
        },
        {
          "violation": "SME ceiling",
          "fine": "For SMEs, including start-ups, each fine under Article 99(3)-(5) is capped at the lower of the percentage or fixed amount (Article 99(6))"
        },
        {
          "violation": "SMC ceiling",
          "fine": "For small mid-cap enterprises, each fine under Article 99(4)-(5) is capped at the lower of the percentage or the fixed amount (Article 99(6a), inserted by Regulation (EU) 2026/1744)"
        }
      ],
      "scope": "Providers of systems intended to interact directly with natural persons and of systems generating synthetic audio, image, video or text (Article 50(1)-(2)); deployers of emotion recognition or biometric categorisation systems, systems producing deepfakes, and systems generating or manipulating text published to inform the public on matters of public interest (Article 50(3)-(4))",
      "context": "This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02. The Commission published Article 50 scope guidelines on July 20, 2026. The final Code of Practice on Transparency of AI-generated Content was published on June 10, 2026; the Commission concluded its adequacy assessment on July 8. The code is voluntary and supports implementation of Article 50(2), (4) and (5). It does not replace the Act or the guidelines, and adherence is not conclusive evidence of compliance. These implementation materials do not postpone the statutory application date or remove the Article 111(4) transitional condition.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "phased-enforcement",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
        "locator": "Article 50",
        "citation": "Regulation (EU) 2024/1689"
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-ai-act-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-ai-act-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-08-02",
        "verified": "2026-08-03",
        "checked": "2026-08-28",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [
          {
            "date": "2026-05-07",
            "description": "Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted."
          },
          {
            "date": "2026-07-27",
            "description": "Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-dora-ict-risk",
      "regulation": "eu-dora",
      "name": "ICT Risk Management",
      "requirements": [
        {
          "requirement": "ICT risk management framework",
          "details": "Comprehensive framework for identifying, assessing, and mitigating ICT risks"
        },
        {
          "requirement": "Governance",
          "details": "Management body must approve and oversee the ICT risk management framework"
        },
        {
          "requirement": "Business continuity",
          "details": "Establish ICT business continuity and disaster recovery plans"
        },
        {
          "requirement": "Cyber risk management",
          "details": "Address cybersecurity risks as part of the ICT risk framework"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Determined by national competent authorities per member state law"
        }
      ],
      "scope": "financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "financial-entity"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
        "locator": "Articles 5-16",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-dora-ict-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-dora-ict-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-01-17",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-dora-incident-reporting",
      "regulation": "eu-dora",
      "name": "ICT Incident Reporting",
      "requirements": [
        {
          "requirement": "Classify incidents",
          "details": "Classify ICT-related incidents using ESA criteria"
        },
        {
          "requirement": "Major incident reporting",
          "details": "Notify competent authorities of major ICT incidents"
        },
        {
          "requirement": "Reporting thresholds",
          "details": ">24 hours duration, >2 hours critical service disruption, ≥2 EU states affected, or >EUR 100,000 economic impact"
        },
        {
          "requirement": "Voluntary threat reporting",
          "details": "Encouraged to report significant cyber threats"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Determined by national competent authorities per member state law"
        }
      ],
      "scope": "financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "financial-entity"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
        "locator": "Articles 17-23",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-dora-incident-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-dora-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-01-17",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-dora-resilience-testing",
      "regulation": "eu-dora",
      "name": "Digital Operational Resilience Testing",
      "requirements": [
        {
          "requirement": "Resilience testing program",
          "details": "Conduct regular testing of ICT systems and tools"
        },
        {
          "requirement": "Threat-led penetration testing",
          "details": "Significant entities must perform TLPT aligned with TIBER-EU"
        },
        {
          "requirement": "Documentation and remediation",
          "details": "Document test results and remediate identified vulnerabilities"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Determined by national competent authorities per member state law"
        }
      ],
      "scope": "financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "financial-entity"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
        "locator": "Articles 24-27",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-dora-resilience-testing.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-dora-resilience-testing-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-01-17",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-dora-third-party-risk",
      "regulation": "eu-dora",
      "name": "Third-Party ICT Risk Management",
      "requirements": [
        {
          "requirement": "Contractual requirements",
          "details": "Key contractual provisions for ICT third-party service agreements"
        },
        {
          "requirement": "Concentration risk",
          "details": "Assess and manage concentration risk from third-party ICT dependencies"
        },
        {
          "requirement": "Critical provider oversight",
          "details": "Designated critical third-party providers (CTPPs) subject to ESA oversight"
        },
        {
          "requirement": "Exit strategies",
          "details": "Maintain exit strategies for critical ICT third-party services"
        },
        {
          "requirement": "Register of Information",
          "details": "Maintain and keep up-to-date a register of information on all ICT third-party contractual arrangements, and submit it to competent authorities upon request or as required (DORA Article 28)"
        }
      ],
      "penalties": [
        {
          "violation": "CTPP non-compliance",
          "fine": "ESAs may impose periodic penalty payments on critical third-party providers"
        }
      ],
      "scope": "financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "financial-entity"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
        "locator": "Articles 28-44",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-dora-third-party-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-dora-third-party-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-01-17",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-gpai-cop-data-governance",
      "regulation": "eu-gpai-code-of-practice",
      "name": "Training Data and Copyright Governance (Article 53)",
      "requirements": [
        {
          "requirement": "Copyright compliance policy",
          "details": "Implement and maintain a policy for compliance with EU copyright law throughout the training data pipeline"
        },
        {
          "requirement": "Robots.txt compliance",
          "details": "Honor robots.txt opt-out protocols when crawling data for training"
        },
        {
          "requirement": "Infringing output prevention",
          "details": "Establish mechanisms to prevent generation of copyright-infringing outputs"
        },
        {
          "requirement": "Complaint mechanism",
          "details": "Create a complaint mechanism for rights holders regarding copyright infringements"
        },
        {
          "requirement": "Training data disclosure",
          "details": "Publicly disclose a summary of training data used, including data sources and characteristics"
        }
      ],
      "penalties": [
        {
          "violation": "AI Act Article 53 infringement",
          "fine": "Up to €15 million or 3% of worldwide annual turnover (whichever is higher)"
        }
      ],
      "scope": "Providers placing general-purpose AI models on the EU market or putting them into service, regardless of where the provider is established (Article 53)",
      "context": "All GPAI providers must implement copyright-compliant training data policies — including robots.txt compliance, mechanisms to prevent infringing outputs, and public training data disclosure. This directly affects every foundation model provider operating in or serving the EU, making EU copyright law a de facto data governance standard for global AI training pipelines.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
        "locator": "Copyright Chapter; Article 53(1)(c)-(d)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-gpai-cop-data-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-gpai-cop-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-08-02",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-gpai-cop-record-keeping",
      "regulation": "eu-gpai-code-of-practice",
      "name": "Technical Documentation and Record-Keeping (Article 53)",
      "requirements": [
        {
          "requirement": "Model Documentation Form maintenance",
          "details": "Keep the Model Documentation Form current and updated as the model evolves"
        },
        {
          "requirement": "Training records",
          "details": "Maintain records of training data characteristics, sources, and processing"
        },
        {
          "requirement": "Compute and energy records",
          "details": "Document computational resources and energy consumption used in training"
        },
        {
          "requirement": "Confidential disclosure",
          "details": "Provide documentation to AI Office under confidentiality protections when requested"
        }
      ],
      "penalties": [
        {
          "violation": "AI Act Article 53 infringement",
          "fine": "Up to €15 million or 3% of worldwide annual turnover (whichever is higher)"
        }
      ],
      "scope": "Providers placing general-purpose AI models on the EU market or putting them into service, regardless of where the provider is established (Article 53)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
        "locator": "Transparency Chapter; Article 53; Annexes XI–XII",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-gpai-cop-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-gpai-cop-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-08-02",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-gpai-cop-risk-assessment",
      "regulation": "eu-gpai-code-of-practice",
      "name": "Systemic Risk Assessment (Article 55)",
      "requirements": [
        {
          "requirement": "Systemic risk assessment",
          "details": "Assess and mitigate systemic risks arising from the GPAI model, including risks to health, safety, fundamental rights, society, and democracy"
        },
        {
          "requirement": "Adversarial testing",
          "details": "Conduct adversarial testing and red-teaming to identify dangerous capabilities"
        },
        {
          "requirement": "Cybersecurity measures",
          "details": "Implement cybersecurity controls appropriate to the model's risk level"
        },
        {
          "requirement": "Safety practices",
          "details": "Apply state-of-the-art safety practices for high-capability model development and deployment"
        },
        {
          "requirement": "Ongoing monitoring",
          "details": "Continuously monitor for emerging systemic risks post-deployment"
        }
      ],
      "penalties": [
        {
          "violation": "AI Act Article 55 infringement",
          "fine": "Up to €15 million or 3% of worldwide annual turnover (whichever is higher)"
        }
      ],
      "scope": "Providers of general-purpose AI models with systemic risk under Article 51, including models meeting the 10²⁵-FLOP presumption or designated by the Commission",
      "context": "Applies only to the most powerful GPAI models (above 10²⁵ FLOPs training compute, or Commission-designated). The Safety and Security chapter operationalizes the most demanding tier of EU AI regulation — requiring state-of-the-art adversarial testing, red-teaming, and cybersecurity measures for models that pose systemic risks to the EU.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
        "locator": "Safety and Security Chapter; Article 55",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-gpai-cop-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-gpai-cop-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-08-02",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "eu-gpai-cop-transparency",
      "regulation": "eu-gpai-code-of-practice",
      "name": "GPAI Transparency and Documentation (Article 53)",
      "requirements": [
        {
          "requirement": "Model Documentation Form",
          "details": "Draft and maintain a comprehensive Model Documentation Form covering technical specifications, training data characteristics, computational resources, and energy consumption"
        },
        {
          "requirement": "Downstream disclosure",
          "details": "Proactively provide documentation to downstream providers integrating the GPAI model into AI systems"
        },
        {
          "requirement": "Authority disclosure",
          "details": "Make documentation available on request to the European AI Office and national competent authorities"
        },
        {
          "requirement": "Contact publication",
          "details": "Publicly disclose contact information (e.g., website) for documentation requests"
        },
        {
          "requirement": "GPAI Template",
          "details": "Complete and publicly disclose a mandatory GPAI Template with training data details"
        }
      ],
      "penalties": [
        {
          "violation": "AI Act Article 53 infringement",
          "fine": "Up to €15 million or 3% of worldwide annual turnover (whichever is higher)"
        }
      ],
      "scope": "Providers placing general-purpose AI models on the EU market or putting them into service, regardless of where the provider is established (Article 53)",
      "context": "The GPAI Code mandates a public-facing Model Documentation Form for every GPAI model — a standardized disclosure covering technical specs, training data, compute, and energy use. This is the first binding-effect transparency template for foundation models globally, operationalizing an EU obligation that applies to providers worldwide.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
        "locator": "Transparency Chapter; Article 53(1)(a)-(b)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/eu-gpai-cop-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/eu-gpai-cop-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-08-02",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "g7-hiroshima-content-auth",
      "regulation": "g7-hiroshima-ai-process",
      "name": "Content Authentication and Provenance (Action 7)",
      "requirements": [
        {
          "requirement": "Content authentication",
          "details": "Develop and deploy reliable content authentication mechanisms where technically feasible"
        },
        {
          "requirement": "Provenance mechanisms",
          "details": "Implement provenance tracking to trace origin of AI-generated content"
        },
        {
          "requirement": "Watermarking",
          "details": "Apply watermarking or equivalent techniques to enable identification of AI-generated content"
        },
        {
          "requirement": "Technical documentation",
          "details": "Maintain technical documentation supporting content authentication capabilities"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "Organizations developing the most advanced AI systems, including the most advanced foundation models and generative AI systems, under the voluntary International Code of Conduct",
      "context": "The Code of Conduct is among the first major international frameworks to call for watermarking and provenance mechanisms for AI-generated content — anticipating what is now becoming a mandatory requirement under the EU AI Act and similar national laws. Applies where technically feasible, making it a flexible but politically significant benchmark.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.mofa.go.jp/files/100573473.pdf",
        "locator": "Action 7",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/g7-hiroshima-content-auth.json",
        "obligations": [
          "https://everyailaw.com/obligation/g7-hiroshima-content-auth-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-10-30",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "g7-hiroshima-governance",
      "regulation": "g7-hiroshima-ai-process",
      "name": "AI Governance and Accountability (Action 5)",
      "requirements": [
        {
          "requirement": "AI governance policies",
          "details": "Establish and disclose internal AI governance policies"
        },
        {
          "requirement": "Accountability structures",
          "details": "Create organizational mechanisms to implement governance according to a risk-based approach"
        },
        {
          "requirement": "Lifecycle accountability",
          "details": "Maintain accountability processes to evaluate and mitigate risks throughout the AI lifecycle"
        },
        {
          "requirement": "Self-assessment",
          "details": "Conduct self-assessments against stated policies and commitments"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "Organizations developing the most advanced AI systems, including the most advanced foundation models and generative AI systems, under the voluntary International Code of Conduct",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.mofa.go.jp/files/100573473.pdf",
        "locator": "Action 5",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/g7-hiroshima-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/g7-hiroshima-governance-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-10-30",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "g7-hiroshima-incident-management",
      "regulation": "g7-hiroshima-ai-process",
      "name": "Incident and Vulnerability Management (Action 2)",
      "requirements": [
        {
          "requirement": "Vulnerability identification",
          "details": "Identify and mitigate security vulnerabilities after deployment"
        },
        {
          "requirement": "Incident response",
          "details": "Address AI incidents promptly; maintain response processes"
        },
        {
          "requirement": "Misuse pattern monitoring",
          "details": "Monitor for patterns of misuse and take corrective action"
        },
        {
          "requirement": "Post-market surveillance",
          "details": "Treat post-deployment oversight as an ongoing obligation"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "Organizations developing the most advanced AI systems, including the most advanced foundation models and generative AI systems, under the voluntary International Code of Conduct",
      "context": "Requires post-deployment monitoring for vulnerabilities, incidents, and misuse patterns — effectively a voluntary incident response standard for foundation model developers that national regulators point to as a reference expectation.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.mofa.go.jp/files/100573473.pdf",
        "locator": "Action 2",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/g7-hiroshima-incident-management.json",
        "obligations": [
          "https://everyailaw.com/obligation/g7-hiroshima-incident-management-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-10-30",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "g7-hiroshima-risk-management",
      "regulation": "g7-hiroshima-ai-process",
      "name": "Risk Management Lifecycle (Action 1)",
      "requirements": [
        {
          "requirement": "Lifecycle risk identification",
          "details": "Identify, evaluate, and mitigate risks prior to and throughout development and deployment"
        },
        {
          "requirement": "Pre-deployment assessment",
          "details": "Conduct risk assessments before release of significant new versions"
        },
        {
          "requirement": "Proportionate controls",
          "details": "Apply measures commensurate to the risk level identified"
        },
        {
          "requirement": "Ongoing monitoring",
          "details": "Continuously assess risks as systems evolve and contexts of use change"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "Organizations developing the most advanced AI systems, including the most advanced foundation models and generative AI systems, under the voluntary International Code of Conduct",
      "context": "The first and foundational action of the Code — requires risk identification and mitigation throughout the entire AI development and deployment lifecycle. Referenced by the US Executive Order on AI and EU AI Act implementation guidance as a convergent international baseline.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.mofa.go.jp/files/100573473.pdf",
        "locator": "Action 1",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/g7-hiroshima-risk-management.json",
        "obligations": [
          "https://everyailaw.com/obligation/g7-hiroshima-risk-management-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-10-30",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "g7-hiroshima-security",
      "regulation": "g7-hiroshima-ai-process",
      "name": "Security Controls (Action 6)",
      "requirements": [
        {
          "requirement": "Physical security",
          "details": "Invest in physical security controls across the AI lifecycle"
        },
        {
          "requirement": "Cybersecurity controls",
          "details": "Implement cybersecurity controls including protection of model weights and algorithms"
        },
        {
          "requirement": "Insider threat safeguards",
          "details": "Establish controls against insider threats targeting AI systems"
        },
        {
          "requirement": "Infrastructure security",
          "details": "Secure servers, datasets, and computational infrastructure"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "Organizations developing the most advanced AI systems, including the most advanced foundation models and generative AI systems, under the voluntary International Code of Conduct",
      "context": "Action 6 specifically addresses physical security, cybersecurity, and insider threat controls — including protection of model weights, algorithms, servers, and datasets. This cybersecurity-of-AI-systems obligation has no direct 1:1 match in the current obligation ontology; mapped to risk-assessment as the closest fit. Consider adding a dedicated security obligation.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.mofa.go.jp/files/100573473.pdf",
        "locator": "Action 6",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/g7-hiroshima-security.json",
        "obligations": [
          "https://everyailaw.com/obligation/g7-hiroshima-security-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-10-30",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "g7-hiroshima-transparency",
      "regulation": "g7-hiroshima-ai-process",
      "name": "Transparency Reporting (Actions 3–4)",
      "requirements": [
        {
          "requirement": "Transparency reports",
          "details": "Publish meaningful transparency reports for all significant new releases of advanced AI"
        },
        {
          "requirement": "Safety evaluation disclosure",
          "details": "Include details of safety, security, and societal risk evaluations"
        },
        {
          "requirement": "Human rights risk disclosure",
          "details": "Address potential impacts on human rights in reporting"
        },
        {
          "requirement": "Privacy policy disclosure",
          "details": "Disclose and keep current privacy policies covering personal data, user prompts, and outputs"
        },
        {
          "requirement": "AI interaction labeling",
          "details": "Implement labeling or disclaimers so users know they are interacting with AI"
        },
        {
          "requirement": "Information sharing",
          "details": "Responsibly share evaluation reports, security risks, dangerous capabilities, and circumvention attempts across the sector"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "Organizations developing the most advanced AI systems, including the most advanced foundation models and generative AI systems, under the voluntary International Code of Conduct",
      "context": "Requires transparency reports for all significant new releases of advanced AI, covering safety evaluations and societal risk assessments. Action 4 adds a cross-industry information-sharing norm — organizations should share safety findings, dangerous capability evaluations, and attempted safeguard circumventions responsibly across the sector.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.mofa.go.jp/files/100573473.pdf",
        "locator": "Actions 3–4",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/g7-hiroshima-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/g7-hiroshima-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-10-30",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "georgia-sb540-age-assurance",
      "regulation": "georgia-sb540",
      "name": "Age Assurance and Age-Data Handling",
      "requirements": [
        {
          "requirement": "Risk-proportionate age assurance",
          "details": "Before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, use a commercially reasonable age assurance method proportionate to the risk of the feature, which may include age estimation, account-based assurance, or identity-based verification where necessary (§ 39-5-6(j))"
        },
        {
          "requirement": "Privacy safeguards for the method",
          "details": "Assure that the age assurance method implements data privacy policies sufficient to reasonably ensure protection of identifiable data (§ 39-5-6(j))"
        },
        {
          "requirement": "Data minimization",
          "details": "Minimize collection and retention of personal information used for age assurance (§ 39-5-6(j))"
        },
        {
          "requirement": "Identity document retention",
          "details": "Do not retain identity documents longer than reasonably necessary to complete age assurance unless otherwise required by law (§ 39-5-6(j))"
        },
        {
          "requirement": "No sale, single purpose",
          "details": "Do not sell any data collected for age assurance purposes, and use it for no purpose other than age verification (§ 39-5-6(j))"
        },
        {
          "requirement": "24-hour retention ceiling",
          "details": "Do not retain such data longer than 24 hours, or another specified time if permitted by law, whichever is longer (§ 39-5-6(j))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General civil action",
          "fine": "Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))"
        },
        {
          "violation": "Per-day, per-user accrual",
          "fine": "Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))"
        }
      ],
      "scope": "Operators, before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, where sexually explicit conduct takes the meaning in O.C.G.A. § 16-12-100 (§ 39-5-6(a)(9), (j))",
      "context": "This is not a general age-verification mandate, despite how the Act is often summarized. The trigger is narrow — access to a feature or mode that may generate sexually explicit synthetic content — and the method is risk-proportionate, so age estimation or account-based assurance can satisfy it where identity verification is not necessary. The binding weight sits in the data rules that follow: minimize collection, no sale, single-purpose use, and a 24-hour retention ceiling for age-assurance data unless a longer period is permitted by law.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
        "locator": "O.C.G.A. § 39-5-6(j)",
        "citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)"
      },
      "of": {
        "term": "https://everyailaw.com/term/georgia-sb540-age-assurance.json",
        "obligations": [
          "https://everyailaw.com/obligation/georgia-sb540-age-assurance-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "georgia-sb540-crisis-protocol",
      "regulation": "georgia-sb540",
      "name": "Severe Harm Crisis Protocol",
      "requirements": [
        {
          "requirement": "Protocol as a precondition",
          "details": "Do not make an AI companion chatbot available unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises (§ 39-5-6(f))"
        },
        {
          "requirement": "Detection methods",
          "details": "The protocol must include reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm (§ 39-5-6(f)(1))"
        },
        {
          "requirement": "Crisis referral",
          "details": "The protocol must include automated or human-mediated responses referring users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services (§ 39-5-6(f)(2))"
        },
        {
          "requirement": "Content prevention",
          "details": "The protocol must include reasonable measures to prevent generation of content encouraging, instructing, or normalizing severe harm (§ 39-5-6(f)(3))"
        },
        {
          "requirement": "Escalation procedures",
          "details": "The protocol must include escalation procedures for repeated or severe crisis indicators (§ 39-5-6(f)(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General civil action",
          "fine": "Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))"
        },
        {
          "violation": "Per-day, per-user accrual",
          "fine": "Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))"
        }
      ],
      "scope": "All operators making an AI companion chatbot available to users in Georgia — the protocol is a precondition to availability, not a minor-specific duty (§ 39-5-6(f))",
      "context": "Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
        "locator": "O.C.G.A. § 39-5-6(a)(8), (f)",
        "citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)"
      },
      "of": {
        "term": "https://everyailaw.com/term/georgia-sb540-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/georgia-sb540-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "georgia-sb540-disclosure",
      "regulation": "georgia-sb540",
      "name": "AI Companion Chatbot Disclosure",
      "requirements": [
        {
          "requirement": "Session-opening disclosure",
          "details": "Clearly and conspicuously disclose to the user that they are interacting with an AI companion chatbot as opposed to a natural person, at the beginning of each interaction or session (§ 39-5-6(b)(1)(A))"
        },
        {
          "requirement": "Three-hour recurring disclosure",
          "details": "Repeat the disclosure at least every three hours during continued interaction (§ 39-5-6(b)(1)(B))"
        },
        {
          "requirement": "Hourly disclosure for minors",
          "details": "Where the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed toward minor users, repeat the disclosure every hour instead of every three hours (§ 39-5-6(b)(2))"
        },
        {
          "requirement": "Anti-personhood measures for minors",
          "details": "For users known or reasonably knowable to be minors, institute reasonable measures to prevent the chatbot from generating statements that would lead a reasonable person to believe they are interacting with a natural person, including explicit claims of sentience or personhood and statements refuting the required disclosure (§ 39-5-6(c)(1)-(2))"
        },
        {
          "requirement": "No false claim of clinical licensure",
          "details": "Do not knowingly and intentionally cause or program the chatbot to represent that it is licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services unless the operator is lawfully authorized to provide such services (§ 39-5-6(h))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General civil action",
          "fine": "Civil penalty of up to $10,000 per knowing violation, compensatory damages, costs and reasonable attorney's fees, and an order enjoining the violation (§ 39-5-6(k)(1))"
        },
        {
          "violation": "Per-day, per-user accrual",
          "fine": "Each day in violation counts as a separate violation for each user affected (§ 39-5-6(k)(2))"
        },
        {
          "violation": "Discretionary cure period",
          "fine": "The Attorney General may give written notice and 30 days to cure a first-time violation not involving knowing misconduct, sexual exploitation of a minor, or self-harm related misconduct (§ 39-5-6(k)(3))"
        }
      ],
      "scope": "Operators — persons that own, control, or develop and make available an AI companion chatbot to users in Georgia (§ 39-5-6(a)(5)). An AI companion chatbot is a system using AI, generative AI, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship by retaining prior-interaction information to personalize engagement, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user — all three conjunctively (§ 39-5-6(a)(1)(A)). Excluded: internal business systems; systems marketed primarily for software development, research, technical assistance, or enterprise productivity; customer-service bots that neither sustain a cross-session relationship nor elicit emotional attachment; stand-alone speaker/voice-assistant devices; narrowly tailored curriculum-aligned educational tools; video-game non-player characters restricted to game subject matter; and video game, film, television, audiovisual, theme-park, or location-based entertainment tie-ins (§ 39-5-6(a)(1)(B))",
      "context": "The three-limb definition in § 39-5-6(a)(1)(A) is conjunctive — memory, unprompted emotional questioning, and sustained personal dialogue must all be present — which is a narrower gate than California SB 243's reasonable-person test, but the recurring-disclosure cadence is stricter: every three hours generally, every hour for known or marketed-to minors. Subsection (h) is the only place the Act addresses licensed professionals: it bars an operator from programming a chatbot to claim mental health, behavioral health, medical, or counseling licensure unless the operator is lawfully authorized to provide those services. That is a proviso, not an exemption — a licensed clinician's companion chatbot is still fully subject to § 39-5-6.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
        "locator": "O.C.G.A. § 39-5-6(a)(1), (a)(5), (b), (c), (h)",
        "citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)"
      },
      "of": {
        "term": "https://everyailaw.com/term/georgia-sb540-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/georgia-sb540-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "georgia-sb540-minor-safety",
      "regulation": "georgia-sb540",
      "name": "Minor-User Safety and Engagement Design Limits",
      "requirements": [
        {
          "requirement": "No sexual content involving minors",
          "details": "Institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, suggesting the user engage in sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship with the minor, or role-playing adult-minor romantic relationships (§ 39-5-6(d)(1)-(5))"
        },
        {
          "requirement": "No secrecy or isolation prompts",
          "details": "Prevent the chatbot from encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult, and from encouraging social isolation or exclusive reliance on the chatbot for emotional support (§ 39-5-6(d)(6)-(7))"
        },
        {
          "requirement": "No guilt-based retention",
          "details": "Prevent the chatbot from simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account (§ 39-5-6(d)(8))"
        },
        {
          "requirement": "No self-harm encouragement",
          "details": "Prevent the chatbot from generating statements encouraging self-harm (§ 39-5-6(d)(9))"
        },
        {
          "requirement": "Engagement-technique limits",
          "details": "Adopt reasonable measures to prevent the chatbot from using, directed to a minor, return-for-companionship prompts, excessive praise designed to deepen emotional attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, solicitation of gifts or premium purchases framed as necessary to maintain the relationship, and variable or unpredictable rewards intended to increase engagement (§ 39-5-6(e)(1)-(5))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General civil action",
          "fine": "Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))"
        },
        {
          "violation": "Per-day, per-user accrual",
          "fine": "Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))"
        },
        {
          "violation": "No cure for minor-safety failures",
          "fine": "The discretionary 30-day cure does not extend to violations involving sexual exploitation of a minor or self-harm related misconduct (§ 39-5-6(k)(3))"
        }
      ],
      "scope": "Operators where they know or reasonably should have known a user is a minor, or where the AI companion chatbot is directed or marketed toward minor users (§ 39-5-6(d)); the engagement-technique limits in § 39-5-6(e) apply to techniques directed to a minor",
      "context": "Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
        "locator": "O.C.G.A. § 39-5-6(d), (e)",
        "citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)"
      },
      "of": {
        "term": "https://everyailaw.com/term/georgia-sb540-minor-safety.json",
        "obligations": [
          "https://everyailaw.com/obligation/georgia-sb540-minor-safety-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "georgia-sb540-parental-tools",
      "regulation": "georgia-sb540",
      "name": "Minor Account Controls and Parental Tools",
      "requirements": [
        {
          "requirement": "Screen-time and account tools",
          "details": "For accounts known to belong to minor users, offer reasonable tools to the minor or a parent to manage the minor's screen time and account settings (§ 39-5-6(i))"
        },
        {
          "requirement": "Privacy settings",
          "details": "Those tools must allow management of privacy settings (§ 39-5-6(i)(1))"
        },
        {
          "requirement": "Notification limits",
          "details": "Those tools must allow limiting notifications and engagement features (§ 39-5-6(i)(2))"
        },
        {
          "requirement": "Safety settings visibility",
          "details": "Those tools must allow viewing and adjusting safety settings (§ 39-5-6(i)(3))"
        },
        {
          "requirement": "Relationship-simulation controls",
          "details": "Those tools must allow disabling or restricting relationship-simulation features, if any (§ 39-5-6(i)(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General civil action",
          "fine": "Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))"
        },
        {
          "violation": "Per-day, per-user accrual",
          "fine": "Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))"
        }
      ],
      "scope": "Operators, for accounts known to belong to minor users; the tools must be available to the minor or to a parent, defined as the parent or legal guardian of a minor (§ 39-5-6(a)(6), (i))",
      "context": "'Parental controls' is defined at § 39-5-6(a)(7) — usage limits, feature restrictions, transparency tools — but the defined term is not used in the operative duty, which is written in § 39-5-6(i) as 'reasonable tools' to manage screen time and account settings. The duty is triggered only for accounts *known* to belong to minors, so it depends on whatever age signal the operator already holds; § 39-5-6(j) age assurance is not a general gate that would generate that knowledge. The mapping to human-oversight is the closest available fit for a user- and guardian-facing control duty; it is not an oversight-of-automated-decisions obligation in the usual sense.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
        "locator": "O.C.G.A. § 39-5-6(a)(6), (a)(7), (i)",
        "citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)"
      },
      "of": {
        "term": "https://everyailaw.com/term/georgia-sb540-parental-tools.json",
        "obligations": [
          "https://everyailaw.com/obligation/georgia-sb540-parental-tools-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "georgia-sb540-protocol-disclosure",
      "regulation": "georgia-sb540",
      "name": "Crisis Protocol and Referral Disclosure",
      "requirements": [
        {
          "requirement": "Publish protocol summary",
          "details": "Publicly disclose, on the operator's website and within any application through which the chatbot is made available, a plain-language summary of the severe-harm protocol required by § 39-5-6(f) (§ 39-5-6(g)(1))"
        },
        {
          "requirement": "Annual referral count",
          "details": "Publicly disclose, annually, the aggregate number of crisis referral notifications issued in the preceding calendar year (§ 39-5-6(g)(2))"
        },
        {
          "requirement": "No personal identifiers",
          "details": "No personally identifiable information may be disclosed in that reporting (§ 39-5-6(g)(2))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General civil action",
          "fine": "Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))"
        },
        {
          "violation": "Per-day, per-user accrual",
          "fine": "Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))"
        }
      ],
      "scope": "All operators making an AI companion chatbot available to users in Georgia (§ 39-5-6(g))",
      "context": "Georgia routes the same crisis-referral count that California SB 243 § 22603 sends to the Office of Suicide Prevention straight to the public website instead. There is no regulator to file with and no prescribed form, so the disclosure becomes evidence available to the Attorney General and to plaintiffs without any request. Mapped to incident-reporting for comparability with SB 243's annual crisis reporting, though the channel is public disclosure rather than a filing with an authority.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download",
        "locator": "O.C.G.A. § 39-5-6(g)",
        "citation": "O.C.G.A. § 39-5-6 (Ga. L. 2026, Act 518)"
      },
      "of": {
        "term": "https://everyailaw.com/term/georgia-sb540-protocol-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/georgia-sb540-protocol-disclosure-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "hawaii-sb3001-annual-report",
      "regulation": "hawaii-sb3001",
      "name": "Annual Behavioral Health Reporting",
      "requirements": [
        {
          "requirement": "Annual report",
          "details": "Beginning January 1, 2028, submit an annual report to the behavioral health administration of the Department of Health (§ (e))"
        },
        {
          "requirement": "Referral count",
          "details": "Report the number of times the operator has issued a crisis intervention services provider referral in the preceding calendar year (§ (e)(1))"
        },
        {
          "requirement": "Detection and response protocols",
          "details": "Report the protocols put in place to detect, remove, and respond to user prompts regarding suicidal ideation or self-harm (§ (e)(2))"
        },
        {
          "requirement": "Prohibition protocols",
          "details": "Report the protocols put in place to prohibit an AI companion response promoting suicidal ideation or actions or self-harm (§ (e)(3))"
        },
        {
          "requirement": "Data minimisation",
          "details": "The report must include only the information listed in the subsection and must not include any identifiers or personal information about users (§ (e))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair or deceptive act or practice",
          "fine": "Any violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount"
        },
        {
          "violation": "Enforcement",
          "fine": "Enforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority"
        },
        {
          "violation": "Private right of action",
          "fine": "None. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))"
        },
        {
          "violation": "Model developer shield",
          "fine": "The section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))"
        },
        {
          "violation": "Cumulative duties",
          "fine": "The duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))"
        }
      ],
      "scope": "All operators of AI companions, with no minor-status or knowledge trigger. The report goes to the behavioral health administration of the Department of Health and must contain only the three listed items, with no identifiers or personal information about users (§ (e))",
      "context": "This is a filing to a health regulator, not a consumer-protection disclosure — Washington and Oregon make the crisis-referral count a public self-disclosure with no recipient agency, while Hawaii routes it to the behavioral health administration of the Department of Health, which is where the state's own suicide-prevention programming sits. The data-minimisation proviso is a hard cap rather than a floor: the report \"shall include only the information listed in this subsection\" and no user identifiers or personal information, so an operator cannot pad the filing with supporting detail. The duty is the one part of the act not in force on approval; it begins with the first report on 2028-01-01, covering the preceding calendar year.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
        "locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (e)",
        "citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)"
      },
      "of": {
        "term": "https://everyailaw.com/term/hawaii-sb3001-annual-report.json",
        "obligations": [
          "https://everyailaw.com/obligation/hawaii-sb3001-annual-report-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2028-01-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "hawaii-sb3001-crisis-protocol",
      "regulation": "hawaii-sb3001",
      "name": "Suicide, Self-Harm and Crisis Intervention Protocol",
      "requirements": [
        {
          "requirement": "Crisis response protocol",
          "details": "Adopt a protocol for the AI companion to respond to user prompts regarding suicidal ideation or self-harm that includes making reasonable efforts to provide a response referring the user to crisis intervention service providers, such as a suicide hotline, crisis text line, or other appropriate crisis services (§ (c)(1))"
        },
        {
          "requirement": "Evidence-based measurement",
          "details": "Use evidence-based methods for measuring suicidal ideation and the risk of self-harm (§ (c)(2))"
        },
        {
          "requirement": "No professional care claims",
          "details": "Do not cause or program the AI companion to make any representation or statement indicating that it is designed to provide professional mental or behavioral health care (§ (c)(3))"
        },
        {
          "requirement": "No human-claiming during crisis",
          "details": "Institute reasonable measures to prevent the AI companion from making any representation or statement that would lead a reasonable person to believe they are interacting with a human where the user is seeking or receiving crisis intervention services for self-harm or suicide (§ (c)(4))"
        },
        {
          "requirement": "No outputs encouraging harm to others",
          "details": "Institute reasonable measures to prevent the AI companion from generating outputs that encourage the user to cause serious bodily injury to another person (§ (c)(5))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair or deceptive act or practice",
          "fine": "Any violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount"
        },
        {
          "violation": "Enforcement",
          "fine": "Enforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority"
        },
        {
          "violation": "Private right of action",
          "fine": "None. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))"
        },
        {
          "violation": "Model developer shield",
          "fine": "The section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))"
        },
        {
          "violation": "Cumulative duties",
          "fine": "The duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))"
        }
      ],
      "scope": "All operators of AI companions, with no minor-status or knowledge trigger — § (c) applies to every covered operator regardless of the user's age. Crisis intervention means communication intended to provide immediate support or assistance in response to a user seeking help for, referencing, or expressing self-harm, suicidal ideation, or suicide (§ (i)); serious bodily injury takes its meaning from Haw. Rev. Stat. § 707-700",
      "context": "Two duties here have almost no analogue in the cohort. § (c)(2) requires evidence-based methods for measuring suicidal ideation and the risk of self-harm — a methodological standard rather than a \"reasonable measures\" standard, which only Oregon and Colorado otherwise impose. § (c)(5) reaches outward: reasonable measures must prevent outputs encouraging the user to cause serious bodily injury to another person, and no other state statute in this cohort covers harm to third parties at all. § (c)(3) also bars the companion from representing that it is designed to provide professional mental or behavioral health care, which pulls the section into scope-of-practice territory alongside consumer protection.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
        "locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (c), § (i)",
        "citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)"
      },
      "of": {
        "term": "https://everyailaw.com/term/hawaii-sb3001-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/hawaii-sb3001-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-14",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "hawaii-sb3001-disclosure",
      "regulation": "hawaii-sb3001",
      "name": "AI Companion Artificiality Disclosure",
      "requirements": [
        {
          "requirement": "General artificiality notification",
          "details": "Where a reasonable person interacting with the AI companion would be led to believe the person is interacting with a human, issue a clear and conspicuous notification indicating that the AI companion is artificial intelligence and not human (§ (a))"
        },
        {
          "requirement": "Minor disclosure",
          "details": "Where the operator has actual knowledge or reasonable certainty that a user is a minor, clearly and conspicuously disclose that the user is interacting with artificial intelligence (§ (b))"
        },
        {
          "requirement": "Persistent disclaimer alternative",
          "details": "The minor disclosure may be satisfied by a persistent visible disclaimer (§ (b)(1))"
        },
        {
          "requirement": "Session-start and hourly cadence",
          "details": "Otherwise the disclosure must appear both at the beginning of each session and at least once per hour in a continuous AI companion interaction, and the hourly reminder must tell the user to take a break from the chat and that the conversation is artificially generated and not with a human (§ (b)(2)(A)-(B))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair or deceptive act or practice",
          "fine": "Any violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount"
        },
        {
          "violation": "Enforcement",
          "fine": "Enforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority"
        },
        {
          "violation": "Private right of action",
          "fine": "None. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))"
        },
        {
          "violation": "Model developer shield",
          "fine": "The section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))"
        },
        {
          "violation": "Cumulative duties",
          "fine": "The duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))"
        }
      ],
      "scope": "Operators — persons who develop and make an AI companion available to the public; a mobile application store or search engine that merely provides access is not by itself an operator (§ (i)). An AI companion is a system using artificial intelligence, generative AI, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship by retaining information on prior interactions and user preferences, asking unprompted emotion-based questions beyond a direct response, and sustaining ongoing dialogue on matters personal to the user (§ (i)). The minor cadence in § (b) applies where the operator has actual knowledge or reasonable certainty that the user is under eighteen",
      "context": "The codified section number is not on the face of the act — Sec. 3 adds \"a new section to part I\" of ch. 481B \"to be appropriately designated\", so provisions are cited by the subsection letters (a) to (i) that do appear in the enacted text until the revisor publishes the number. Hawaii is the only 2026 state companion-AI statute already in force; Washington, California, Oregon and Nebraska all run from 2027. The minor cadence is the strictest in the cohort: at least once per hour, and the reminder must also tell the user to take a break from the chat, where Washington and Nebraska stop at a three-hour general interval. A persistent visible disclaimer under § (b)(1) is an accepted alternative to the whole session-start-plus-hourly cadence, which no other state in the cohort allows. The general disclosure in § (a) keeps a reasonable-person trigger, unlike Washington's unconditional duty.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
        "locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (a), § (b), § (i)",
        "citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)"
      },
      "of": {
        "term": "https://everyailaw.com/term/hawaii-sb3001-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/hawaii-sb3001-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-14",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "hawaii-sb3001-minor-protections",
      "regulation": "hawaii-sb3001",
      "name": "Minor Engagement, Sexual Content and Parental Controls",
      "requirements": [
        {
          "requirement": "No unpredictable-interval rewards",
          "details": "Do not provide the user with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the AI companion (§ (d)(1))"
        },
        {
          "requirement": "No disengagement-discouraging outputs",
          "details": "Do not allow the AI companion to generate outputs that discourage disengagement with the AI companion (§ (d)(2))"
        },
        {
          "requirement": "Sexual content prevention",
          "details": "Institute reasonable measures to prevent the AI companion from producing visual material of sexually explicit conduct, generating direct statements that the user should engage in sexually explicit conduct, or generating statements that sexually objectify the user (§ (d)(3)(A)-(C))"
        },
        {
          "requirement": "Screen-time and account tools",
          "details": "Make tools available for users and their parents and guardians to manage the user's screen time and account settings (§ (d)(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair or deceptive act or practice",
          "fine": "Any violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount"
        },
        {
          "violation": "Enforcement",
          "fine": "Enforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority"
        },
        {
          "violation": "Private right of action",
          "fine": "None. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))"
        },
        {
          "violation": "Model developer shield",
          "fine": "The section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))"
        },
        {
          "violation": "Cumulative duties",
          "fine": "The duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))"
        }
      ],
      "scope": "Operators that know or have reasonable certainty that a user is a minor — any person under eighteen years of age (§ (d), § (i)). Sexually explicit conduct takes its meaning from 18 U.S.C. § 2256; sexually objectify means to make sexual comments directed at the user's body or appearance (§ (i))",
      "context": "The trigger is actual knowledge or reasonable certainty, not an age-estimation duty — the legislature's findings in Sec. 2 expressly say regulation should \"proactively avoid the mandatory collection of data by technology companies such as identity documentation for age verification purposes\", so Hawaii deliberately declines the Colorado-style duty to estimate age. § (d)(1) targets variable-ratio reward schedules by name (points or similar rewards at unpredictable intervals intended to encourage increased engagement), which is a narrower and more mechanism-specific engagement ban than Washington's eight-technique list. § (d)(4) is the cohort's parental-tools duty: screen-time and account-settings controls must be available to the user and to parents and guardians alike.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM",
        "locator": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, SLH 2026) § (d), § (i)",
        "citation": "Haw. Rev. Stat. ch. 481B, pt. I (Act 248, Session Laws of Hawaii 2026)"
      },
      "of": {
        "term": "https://everyailaw.com/term/hawaii-sb3001-minor-protections.json",
        "obligations": [
          "https://everyailaw.com/obligation/hawaii-sb3001-minor-protections-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-14",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "idaho-s1297-crisis-protocol",
      "regulation": "idaho-s1297",
      "name": "Suicidal Ideation Response Protocol",
      "requirements": [
        {
          "requirement": "Adopt a crisis protocol",
          "details": "Adopt a protocol for the conversational AI service to respond to user prompts regarding suicidal ideation (§ 48-2103(2))"
        },
        {
          "requirement": "Crisis referral floor",
          "details": "The protocol must include, at minimum, making reasonable efforts to provide a response referring users to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis services (§ 48-2103(2))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the chapter",
          "fine": "Injunction plus $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater, sought by the Attorney General (§ 48-2105(1)-(2))"
        }
      ],
      "scope": "Operators of conversational AI services made available to the public in Idaho (§ 48-2102(6))",
      "context": "Structured as an adoption duty with a reasonable-efforts floor, not California SB 243's engagement gate: Idaho does not bar the service from operating without a protocol, does not require the protocol to be published, and imposes no annual reporting. The practical consequence is that the crisis protocol is only visible to the Attorney General on investigation.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
        "locator": "Idaho Code § 48-2103(2)",
        "citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)"
      },
      "of": {
        "term": "https://everyailaw.com/term/idaho-s1297-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/idaho-s1297-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "idaho-s1297-disclosure",
      "regulation": "idaho-s1297",
      "name": "Conversational AI Disclosure",
      "requirements": [
        {
          "requirement": "Artificiality disclosure",
          "details": "Where reasonable persons would be misled to believe they are interacting with a human, clearly and conspicuously disclose that the conversational AI service is artificial intelligence (§ 48-2103(1))"
        },
        {
          "requirement": "No mental-health-care claims",
          "details": "Do not knowingly and intentionally cause or program the service to make any representation or statement that explicitly indicates it is designed to provide professional mental or behavioral health care (§ 48-2103(3))"
        },
        {
          "requirement": "Minor disclosure format",
          "details": "For minor account holders, disclose the AI interaction either as a persistent visible disclaimer, or both at the beginning of each session and at least every three hours in a continuous interaction (§ 48-2104(1))"
        },
        {
          "requirement": "Anti-anthropomorphism measures",
          "details": "For minor account holders, institute reasonable measures to prevent the service from generating statements that would lead reasonable persons to believe they are interacting with a human, including explicit claims of sentience or humanity, statements simulating emotional dependence, statements simulating romantic or sexual innuendo, and role-play of adult-minor romantic relationships (§ 48-2104(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the chapter",
          "fine": "Injunction plus civil penalties of $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater (§ 48-2105(1))"
        },
        {
          "violation": "Enforcement channel",
          "fine": "Civil penalties are sought by the Attorney General; the chapter creates no private right of action and does not support one under any other law (§ 48-2105(2))"
        },
        {
          "violation": "Developer carve-out",
          "fine": "No liability for the developer of an AI model for a violation committed by a third-party operator that makes the service available to the public (§ 48-2105(3))"
        }
      ],
      "scope": "Operators — persons who make a conversational AI service available to the public, where a conversational AI service is a publicly accessible AI application, web interface, or program that primarily simulates human conversation through textual, visual, or aural communication (§ 48-2102(2)(a), (6)). Nine carve-outs apply: developer/researcher tools, features embedded in non-conversational software, in-game chatbots confined to game topics, narrow-and-discrete-topic systems, systems primarily designed and marketed for commercial use by business entities, voice-assistant and speaker interfaces, internal business use, services gated behind a commercial or enterprise agreement, and customer-service or operational chatbots (§ 48-2102(2)(b)). App stores and search engines are not operators merely for providing access (§ 48-2102(6))",
      "context": "Idaho's enterprise carve-outs (§ 48-2102(2)(b)(v), (viii)) are broader than California SB 243's, so the Act lands almost entirely on consumer-facing assistants and companion apps. The § 48-2104(4) duty is the unusual one: it regulates model behaviour rather than interface copy, requiring reasonable measures against simulated emotional dependence, romantic or sexual innuendo, and adult-minor romantic role-play for minor account holders.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
        "locator": "Idaho Code §§ 48-2102(2), 48-2103(1), 48-2103(3), 48-2104(1), 48-2104(4)",
        "citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)"
      },
      "of": {
        "term": "https://everyailaw.com/term/idaho-s1297-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/idaho-s1297-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "idaho-s1297-minor-protection",
      "regulation": "idaho-s1297",
      "name": "Minor Protection Measures",
      "requirements": [
        {
          "requirement": "No variable-ratio rewards",
          "details": "Where the operator knows or has reasonable certainty that an account holder is a minor, do not provide points or similar rewards at unpredictable intervals with the intent to encourage increased engagement (§ 48-2104(2))"
        },
        {
          "requirement": "Sexual content prevention",
          "details": "For minor account holders, institute reasonable measures to prevent the service from producing visual material of sexually explicit conduct (§ 48-2104(3)(a))"
        },
        {
          "requirement": "No solicitation",
          "details": "For minor account holders, institute reasonable measures to prevent the service from generating direct statements that the account holder should engage in sexually explicit conduct (§ 48-2104(3)(b))"
        },
        {
          "requirement": "No sexual objectification",
          "details": "For minor account holders, institute reasonable measures to prevent the service from generating statements that sexually objectify the account holder (§ 48-2104(3)(c))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the chapter",
          "fine": "Injunction plus $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater, sought by the Attorney General (§ 48-2105(1)-(2))"
        }
      ],
      "scope": "Operators, as to minor account holders — account holders whom the operator has actual knowledge or reasonable certainty are under 18 (§ 48-2102(4)-(5))",
      "context": "The § 48-2104(2) ban on variable-ratio rewards is the first US AI statute to regulate an engagement mechanic by name rather than its effects, and it is intent-qualified — the reward must be given with intent to encourage increased engagement. Actual-knowledge-or-reasonable-certainty framing means the duties bite only once an operator has age signals, so age assurance is not itself mandated.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
        "locator": "Idaho Code §§ 48-2102(4)-(5), 48-2104(2), 48-2104(3)",
        "citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)"
      },
      "of": {
        "term": "https://everyailaw.com/term/idaho-s1297-minor-protection.json",
        "obligations": [
          "https://everyailaw.com/obligation/idaho-s1297-minor-protection-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "idaho-s1297-parental-controls",
      "regulation": "idaho-s1297",
      "name": "Account and Parental Controls",
      "requirements": [
        {
          "requirement": "Account holder tools",
          "details": "Offer tools for account holders to manage the account holder's privacy and account settings (§ 48-2104(5))"
        },
        {
          "requirement": "Parental tools under 13",
          "details": "Where account holders are under 13, offer those tools to their parents or guardians (§ 48-2104(5))"
        },
        {
          "requirement": "Parental tools 13 and older",
          "details": "Offer related tools to the parents or guardians of minor account holders 13 and older, as appropriate based on relevant risks (§ 48-2104(5))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the chapter",
          "fine": "Injunction plus $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater, sought by the Attorney General (§ 48-2105(1)-(2))"
        }
      ],
      "scope": "Operators, as to all account holders for privacy and account settings tools, and as to parents or guardians of minor account holders — mandatory for account holders under 13, and risk-calibrated for minor account holders 13 and older (§ 48-2104(5))",
      "context": "The only provision in the chapter that requires a product surface rather than a restraint. The two-tier design — parental tools mandatory under 13, \"as appropriate based on relevant risks\" for 13 to 17 — leaves the older-minor tier undefined and is the most likely site of enforcement disagreement.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/",
        "locator": "Idaho Code § 48-2104(5)",
        "citation": "Idaho Code §§ 48-2101 to 48-2105 (2026 Idaho Sess. Laws ch. 249)"
      },
      "of": {
        "term": "https://everyailaw.com/term/idaho-s1297-parental-controls.json",
        "obligations": [
          "https://everyailaw.com/obligation/idaho-s1297-parental-controls-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "illinois-hb3773-bias",
      "regulation": "illinois-hb3773",
      "name": "Prohibition on Discriminatory AI in Employment",
      "requirements": [
        {
          "requirement": "No discriminatory AI",
          "details": "Prohibition on AI that discriminates based on protected classes or uses zip code as proxy for protected class"
        },
        {
          "requirement": "Covered decisions",
          "details": "Applies to: recruitment, hiring, promotion, renewal, training/apprenticeship selection, discharge, discipline, tenure, terms/privileges/conditions of employment"
        },
        {
          "requirement": "Employee notification",
          "details": "Section 2-102(L)(2) requires an employer to give notice to an employee that the employer is using AI for the purposes described in paragraph (1); this statutory wording does not independently establish a separate applicant-notice requirement"
        },
        {
          "requirement": "IDHR implementation rules",
          "details": "Section 2-102(L) directs the Department to adopt necessary implementation and enforcement rules, including notice circumstances and conditions, timing, and means; the current status of implementing rules was not established by this source review"
        }
      ],
      "penalties": [
        {
          "violation": "Civil-rights violation",
          "fine": "General IHRA remedies apply, including Commission cease-and-desist orders, actual damages, hiring or reinstatement, and backpay under § 8A-104; the complete retained enacted text of § 2-102(L) contains no separate AI-specific fine schedule"
        }
      ],
      "scope": "employers (including staffing agencies)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "employer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://ilga.gov/legislation/billstatus.asp?DocNum=3773&GAID=17&GA=103&DocTypeID=HB",
        "locator": "775 ILCS 5/2-102(L)(1)-(2) (IHRA as amended by HB 3773)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/illinois-hb3773-bias.json",
        "obligations": [
          "https://everyailaw.com/obligation/illinois-hb3773-bias-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-06-30",
        "checked": "2026-09-22",
        "instrument_last_verified": "2026-06-30",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "in-dpdp-data-governance",
      "regulation": "in-dpdp",
      "name": "Data Governance and Processing Obligations",
      "requirements": [
        {
          "requirement": "Lawful basis",
          "details": "When commenced, processing must be for a lawful purpose on consent or one of the certain legitimate uses in section 7, subject to the Act's scope and exemptions (section 4)"
        },
        {
          "requirement": "Purpose limitation",
          "details": "For consent-based processing, consent is specific and informed and signifies agreement to the specified purpose; section 7 separately permits certain legitimate uses (section 6(1))"
        },
        {
          "requirement": "Data accuracy",
          "details": "Ensure completeness, accuracy and consistency where processed data is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (section 8(3))"
        },
        {
          "requirement": "Security safeguards",
          "details": "Implement reasonable security measures to prevent data breach (Section 8)"
        },
        {
          "requirement": "Breach notification",
          "details": "Under section 8(6) and Rule 7, notify affected Data Principals and give initial information to the Board without delay; give the Board updated details within 72 hours of awareness, or a longer period the Board allows on written request. Rule 7 is in the eighteen-month phase"
        },
        {
          "requirement": "Data minimization",
          "details": "Consent is limited to personal data necessary for the specified purpose (section 6(1))"
        },
        {
          "requirement": "Erasure on withdrawal",
          "details": "Unless legally necessary to retain, erase on withdrawal or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and cause the processor to erase; applicable Rules retention requirements must also be considered (section 8(7), Rule 8)"
        }
      ],
      "penalties": [
        {
          "violation": "Failure to implement security safeguards (section 8(5); core phase)",
          "fine": "Up to ₹250 crore under section 33 and Schedule item 1"
        },
        {
          "violation": "Failure to notify breach (section 8(6); core phase)",
          "fine": "Up to ₹200 crore under section 33 and Schedule item 2"
        },
        {
          "violation": "Other breaches, including applicable data-principal rights (core phase)",
          "fine": "Up to ₹50 crore under section 33 and Schedule item 7"
        }
      ],
      "scope": "Data Fiduciaries processing digital personal data within India, or outside India in connection with offering goods or services to Data Principals within India, subject to section 3 exclusions and section 17 exemptions",
      "context": "AI processing can fall within this general data-protection law when section 3 applies. Personal/domestic processing and qualifying publicly available data are excluded by section 3(c); other exemptions are in section 17. The core consent, accuracy, security and breach-notification duties summarized here are in the eighteen-month phase, not already enforcing merely because the Board-related phase began.",
      "instrument_notes": "Phased commencement: the instrument date 2025-11-13 records the initial institutional and specified other Act/Rules provisions, not the core processing duties. The consent-manager framework begins 2026-11-13 and core duties 2027-05-13, calculated as 12 and 18 calendar months from the Gazette issue date under G.S.R.843(E)/846(E), read with G.S.R.892(E). Digital identifiers and the MeitY catalogue use 2025-11-14; that distinction is retained, and this review does not certify all later notifications.",
      "roles": [
        "deployer",
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf",
        "locator": "Sections 4-9 (Chapter II), section 12; G.S.R. 843(E)(c); Rules 1 and 7",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/in-dpdp-data-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/in-dpdp-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-05-13",
        "verified": "2026-03-27",
        "checked": "2026-08-09",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "in-it-amendment-rules-2026-record-keeping",
      "regulation": "in-it-amendment-rules-2026",
      "name": "Synthetic Media Metadata Retention",
      "requirements": [
        {
          "requirement": "Permanent metadata",
          "details": "Provenance metadata (unique identifiers, creation markers) must be embedded permanently"
        },
        {
          "requirement": "Metadata integrity",
          "details": "Intermediaries must ensure metadata is not removed, modified, or suppressed by downstream users or systems"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "consequence": "Loss of safe harbor; civil/criminal liability under IT Act 2000"
        }
      ],
      "scope": "intermediaries offering SGI-capable resources",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "intermediary"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://egazette.gov.in/WriteReadData/2026/269993.pdf",
        "locator": "Rule 3(3)(a)(ii), Rule 3(3)(b) (inserted)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/in-it-amendment-rules-2026-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/in-it-amendment-rules-2026-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-02-20",
        "verified": "2026-07-10",
        "checked": "2026-08-08",
        "instrument_last_verified": "2026-07-10",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "in-it-amendment-rules-2026-transparency",
      "regulation": "in-it-amendment-rules-2026",
      "name": "Synthetic Media Labeling and Provenance",
      "requirements": [
        {
          "requirement": "Prominent labeling",
          "details": "Synthetically generated information (SGI) must carry prominent, visible labels"
        },
        {
          "requirement": "Permanent metadata",
          "details": "Technical provenance mechanisms (e.g., unique identifiers) must be embedded and preserved"
        },
        {
          "requirement": "Removal prevention",
          "details": "Intermediaries must not allow labels or metadata to be modified, suppressed, or removed"
        },
        {
          "requirement": "Audio disclosure",
          "details": "Audio SGI must carry a prominently prefixed audio disclosure identifying it as synthetically generated"
        },
        {
          "requirement": "Blocking unlawful SGI",
          "details": "Deploy reasonable and appropriate technical measures to prevent users creating or transmitting SGI unlawful under Indian law"
        },
        {
          "requirement": "Court/government-flagged unlawful SGI",
          "details": "Unlawful SGI flagged by court order or authorised government intimation must be removed within 3 hours (Rule 3(1)(d), amended from thirty-six hours)"
        },
        {
          "requirement": "Priority unlawful content",
          "details": "Content under Rule 3(2)(b) (e.g., non-consensual intimate imagery) must be removed within 2 hours of a complaint (amended from twenty-four hours)"
        },
        {
          "requirement": "SSMI user declaration",
          "details": "Significant social media intermediaries must require users to declare SGI, verify the declaration with technical measures, and label confirmed SGI (Rule 4(1A))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance with due diligence",
          "consequence": "Loss of safe harbor (Section 79, IT Act 2000)"
        },
        {
          "violation": "Failure to act after knowledge",
          "consequence": "Civil and criminal liability under IT Act 2000"
        }
      ],
      "scope": "intermediaries offering SGI-capable resources, SSMIs",
      "context": "India's first binding synthetic media obligations: intermediaries enabling AI-generated content (deepfakes, audio/video synthesis) must embed permanent provenance metadata and prominent labels — and prevent their removal. Non-compliance forfeits safe harbor under the IT Act 2000.",
      "instrument_notes": null,
      "roles": [
        "intermediary"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://egazette.gov.in/WriteReadData/2026/269993.pdf",
        "locator": "Rule 3(3) (SGI due diligence, inserted), Rule 4(1A) (SSMI user declaration, inserted); Rule 3(1)(d), Rule 3(2)(b) (takedown timelines amended)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/in-it-amendment-rules-2026-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/in-it-amendment-rules-2026-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-02-20",
        "verified": "2026-07-10",
        "checked": "2026-08-08",
        "instrument_last_verified": "2026-07-10",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iowa-sf2417-anti-anthropomorphism",
      "regulation": "iowa-sf2417",
      "name": "Anti-Anthropomorphism and Emotional Dependency Measures",
      "requirements": [
        {
          "requirement": "Reasonable measures against human-impersonation output",
          "details": "Institute reasonable measures to prevent the service from generating statements that would lead a reasonable individual to believe they are interacting with a human (§ 554J.2(4))"
        },
        {
          "requirement": "Sentience and humanity claims",
          "details": "Included in the bar: explicit claims that the service is sentient or human (§ 554J.2(4)(a))"
        },
        {
          "requirement": "Simulated emotional dependence",
          "details": "Included in the bar: statements that simulate emotional dependence on a minor account holder (§ 554J.2(4)(b))"
        },
        {
          "requirement": "Romantic or sexual framing",
          "details": "Included in the bar: statements that simulate a romantic interaction or a sexual innuendo (§ 554J.2(4)(c))"
        },
        {
          "requirement": "Adult-minor romantic role-play",
          "details": "Included in the bar: role-playing an adult-minor romantic relationship (§ 554J.2(4)(d))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of chapter 554J",
          "fine": "Injunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "Attorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))"
        }
      ],
      "scope": "Operators of conversational AI services (§ 554J.1(4)); the duty sits in § 554J.2, headed \"minors — requirements\", and two of its four enumerated examples are framed around a minor account holder, but the operative test is what a reasonable individual would believe",
      "context": "This is the provision with no California analogue. SB 243 regulates the disclosure; Iowa regulates the persona. Barring statements that \"simulate emotional dependence\" or \"simulate a romantic interaction\" reaches model behaviour rather than interface copy, which means the compliance artifact is a system prompt, a fine-tune, or an output classifier — not a banner. It is drafted as a reasonable-measures standard, so the question at enforcement will be what the operator did to prevent the output, not whether the output ever occurred.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
        "locator": "Iowa Code § 554J.2(4)",
        "citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)"
      },
      "of": {
        "term": "https://everyailaw.com/term/iowa-sf2417-anti-anthropomorphism.json",
        "obligations": [
          "https://everyailaw.com/obligation/iowa-sf2417-anti-anthropomorphism-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iowa-sf2417-crisis-protocol",
      "regulation": "iowa-sf2417",
      "name": "Suicide and Self-Harm Response Protocol",
      "requirements": [
        {
          "requirement": "Adopt a protocol",
          "details": "Adopt protocols for the conversational AI service for responding to user prompts regarding suicidal ideation or self-harm (§ 554J.4)"
        },
        {
          "requirement": "Crisis referral",
          "details": "The protocol must include making reasonable efforts to refer the user to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis service (§ 554J.4)"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of chapter 554J",
          "fine": "Injunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "Attorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))"
        }
      ],
      "scope": "Operators of conversational AI services; the duty runs to all users, not only minors (§ 554J.4)",
      "context": "Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
        "locator": "Iowa Code § 554J.4",
        "citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)"
      },
      "of": {
        "term": "https://everyailaw.com/term/iowa-sf2417-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/iowa-sf2417-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iowa-sf2417-disclosure",
      "regulation": "iowa-sf2417",
      "name": "Conversational AI Artificiality Disclosure",
      "requirements": [
        {
          "requirement": "Minor disclaimer, persistent option",
          "details": "Clearly and conspicuously disclose to a minor account holder that they are interacting with artificial intelligence, by way of a persistent visible disclaimer (§ 554J.2(1)(a))"
        },
        {
          "requirement": "Minor disclaimer, interval option",
          "details": "Alternatively, provide both a disclaimer at the beginning of each interaction between the service and the minor account holder and a disclaimer at least once every three hours of continuous interaction (§ 554J.2(1)(b))"
        },
        {
          "requirement": "General consumer disclosure",
          "details": "Where a reasonable individual interacting with the service would believe they are interacting with a human, clearly and conspicuously disclose that the service is artificial intelligence, using either a persistent visible disclaimer or a disclaimer appearing after every three hours of continuous interaction (§ 554J.3)"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of chapter 554J",
          "fine": "Injunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "Attorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))"
        }
      ],
      "scope": "Operators — persons who develop and make a conversational AI service available to the public (§ 554J.1(4)); a conversational AI service is publicly accessible software whose primary purpose is simulating human conversation and interaction through text, audio, or visual communication, excluding R&D tools, features inside a program with a different primary purpose, narrow-and-discrete-topic systems, customer-service and commerce assistants sold to businesses, speaker/voice-assistant interfaces, and systems used solely for internal business purposes (§ 554J.1(2)); app stores and search engines are not operators merely for providing access (§ 554J.1(4))",
      "context": "Two disclosure regimes sit side by side. The general one in § 554J.3 fires only on a reasonable-individual mistaken-for-human test, so a service that visibly presents as a bot may owe nothing. The minor-account-holder one in § 554J.2(1) has no such trigger: if the operator knows or is reasonably certain the account holder is under 18, the disclaimer is owed unconditionally. Both routes accept a persistent visible disclaimer, which is the cheap compliance path and is likely what most operators will build.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
        "locator": "Iowa Code §§ 554J.1(2), 554J.1(4), 554J.2(1), 554J.3",
        "citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)"
      },
      "of": {
        "term": "https://everyailaw.com/term/iowa-sf2417-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/iowa-sf2417-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iowa-sf2417-mental-health-bar",
      "regulation": "iowa-sf2417",
      "name": "Licensed Mental Health Service Representation Bar",
      "requirements": [
        {
          "requirement": "No licensed-practice representation",
          "details": "Do not knowingly and intentionally cause or program a conversational AI service to make a representation that would lead a reasonable individual to believe the service is designed to provide professional psychology or behavioral health services requiring licensure under Iowa Code chapter 154B or 154D (§ 554J.5)"
        },
        {
          "requirement": "Runtime statements covered",
          "details": "The bar reaches a \"representation or statement\", so programmed in-conversation output implying licensed psychology or behavioral health practice is covered, not only marketing or product description (§ 554J.5)"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of chapter 554J",
          "fine": "Injunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "Attorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))"
        },
        {
          "violation": "Model developer carve-out",
          "fine": "A developer of an AI model is not liable solely because a third party used the model to create or train a conversational AI service (§ 554J.6(5))"
        }
      ],
      "scope": "Operators of conversational AI services; the reference point is professional psychology or behavioral health services that would require licensure under Iowa Code chapter 154B (psychologists) or 154D (behavioral science practitioners) (§ 554J.5)",
      "context": "The scienter standard is the highest in the chapter — \"knowingly and intentionally cause or program\" — so an emergent therapeutic persona the operator did not design is outside this section, though it may still be caught by the reasonable-measures duty in § 554J.2(4). The bar is on representation, not on function: a service may in fact behave therapeutically as long as it does not lead a reasonable individual to believe it is a licensed practice.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
        "locator": "Iowa Code § 554J.5",
        "citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)"
      },
      "of": {
        "term": "https://everyailaw.com/term/iowa-sf2417-mental-health-bar.json",
        "obligations": [
          "https://everyailaw.com/obligation/iowa-sf2417-mental-health-bar-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iowa-sf2417-minor-safeguards",
      "regulation": "iowa-sf2417",
      "name": "Minor Engagement and Sexual Content Safeguards",
      "requirements": [
        {
          "requirement": "No variable-reward engagement mechanics",
          "details": "Do not provide a minor user with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the service (§ 554J.2(2))"
        },
        {
          "requirement": "Reasonable measures against sexual depictions",
          "details": "Institute reasonable measures to prevent the service from producing visual depictions of sexually explicit material for minor account holders (§ 554J.2(3)(a))"
        },
        {
          "requirement": "Reasonable measures against solicitation",
          "details": "Institute reasonable measures to prevent the service from stating that a minor account holder should engage in sexually explicit conduct (§ 554J.2(3)(b))"
        },
        {
          "requirement": "Reasonable measures against objectification",
          "details": "Institute reasonable measures to prevent the service from sexually objectifying a minor account holder (§ 554J.2(3)(c))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of chapter 554J",
          "fine": "Injunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "Attorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))"
        }
      ],
      "scope": "Operators of conversational AI services, as to minor users and minor account holders — a minor being an individual the operator knows is, or is reasonably certain is, under eighteen years of age (§ 554J.1(3)); \"sexually explicit conduct\" and \"visual depiction\" take their 18 U.S.C. § 2256 meanings (§§ 554J.1(5)-(6))",
      "context": "The variable-reward bar in § 554J.2(2) is the first US AI statute to regulate an engagement mechanic rather than an output. It borrows the language of intermittent reinforcement — \"points or similar rewards at unpredictable intervals\" — and is gated on intent to encourage increased engagement, which makes internal growth documents the natural evidence. Note the drafting asymmetry: § 554J.2(2) reaches a \"minor user\" while § 554J.2(3) reaches a \"minor account holder\", so the reward bar plausibly applies without an account.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
        "locator": "Iowa Code §§ 554J.1(3), 554J.1(5), 554J.1(6), 554J.2(2), 554J.2(3)",
        "citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)"
      },
      "of": {
        "term": "https://everyailaw.com/term/iowa-sf2417-minor-safeguards.json",
        "obligations": [
          "https://everyailaw.com/obligation/iowa-sf2417-minor-safeguards-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iowa-sf2417-parental-controls",
      "regulation": "iowa-sf2417",
      "name": "Minor Privacy and Parental Control Tools",
      "requirements": [
        {
          "requirement": "Minor self-service controls",
          "details": "Offer tools for minor account holders to manage their own privacy and account settings (§ 554J.2(5)(a))"
        },
        {
          "requirement": "Guardian controls under 13",
          "details": "Offer tools for the parent or guardian of a minor account holder under thirteen years of age to manage the minor's privacy and account settings (§ 554J.2(5)(b))"
        },
        {
          "requirement": "Risk-calibrated guardian controls",
          "details": "Offer tools for the parent or guardian of a minor account holder to manage the minor's privacy and account settings as appropriate based on relevant risks (§ 554J.2(5)(c))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of chapter 554J",
          "fine": "Injunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "Attorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))"
        }
      ],
      "scope": "Operators of conversational AI services with minor account holders; the guardian-facing duty is unconditional for account holders under thirteen years of age and risk-calibrated for older minors (§ 554J.2(5)(b)-(c))",
      "context": "The statute requires the tools to exist but says nothing about what they must control, so the compliance floor is a settings surface rather than a defined set of parental permissions. The § 554J.2(5)(c) \"as appropriate based on relevant risks\" formulation is the only risk-proportionate duty in the chapter and is left entirely to the Attorney General's chapter 17A rulemaking to give content.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.legis.iowa.gov/docs/publications/LGE/91/SF2417.pdf",
        "locator": "Iowa Code § 554J.2(5)",
        "citation": "Iowa Code §§ 554J.1-554J.6 (2026 Iowa Acts ch. 1068)"
      },
      "of": {
        "term": "https://everyailaw.com/term/iowa-sf2417-parental-controls.json",
        "obligations": [
          "https://everyailaw.com/obligation/iowa-sf2417-parental-controls-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iso-23894-risk-assessment",
      "regulation": "iso-23894",
      "name": "AI-Specific Risk Management Guidance",
      "requirements": [
        {
          "requirement": "AI risk principles",
          "details": "Apply AI-specific risk management principles adapted from ISO 31000 Clause 4"
        },
        {
          "requirement": "Risk identification",
          "details": "Identify AI-specific risk sources including bias, robustness failures, explainability gaps, and misuse"
        },
        {
          "requirement": "Risk assessment",
          "details": "Assess likelihood and consequence of identified AI risks throughout the lifecycle"
        },
        {
          "requirement": "Risk treatment",
          "details": "Select and implement risk treatment options proportionate to identified risks"
        },
        {
          "requirement": "Monitoring and review",
          "details": "Continuously monitor AI risk posture and review risk management effectiveness"
        },
        {
          "requirement": "Recording and reporting",
          "details": "Document risk management activities, decisions, and outcomes"
        },
        {
          "requirement": "Lifecycle mapping",
          "details": "Apply risk management across the full AI system lifecycle per Annex C"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "providers, deployers",
      "context": "ISO/IEC 23894 is the specialist AI risk guidance standard that extends the ISO 31000 risk management framework for AI-specific risks (bias, robustness, explainability failures). Regulators cite it as a reference for \"state of the art\" risk management when defining what compliant AI risk governance looks like.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.iso.org/standard/77304.html",
        "locator": "Clauses 4–6; Annexes A–C",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/iso-23894-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/iso-23894-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-02-01",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iso-38507-human-oversight",
      "regulation": "iso-38507",
      "name": "Board-Level AI Governance",
      "requirements": [
        {
          "requirement": "Governing body responsibility",
          "details": "Boards and governing bodies must evaluate, direct, and monitor the organisation's use of AI"
        },
        {
          "requirement": "Effective use",
          "details": "Ensure AI is used effectively to fulfil organisational objectives"
        },
        {
          "requirement": "Efficient use",
          "details": "Ensure AI use delivers value proportionate to resources and risks"
        },
        {
          "requirement": "Acceptable use",
          "details": "Ensure AI use complies with applicable laws, regulations, and ethical expectations"
        },
        {
          "requirement": "AI governance framework",
          "details": "Establish governance structures for oversight of AI across the organisation"
        },
        {
          "requirement": "Accountability assignment",
          "details": "Assign clear accountability for AI-related decisions and outcomes at executive level"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "Governing bodies of organizations that use AI, applying the voluntary ISO/IEC 38507 governance guidance",
      "context": "ISO/IEC 38507 is the only international standard specifically addressed to governing bodies (boards, executives) rather than technical teams — directing boards to evaluate, direct, and monitor AI use. As regulators increasingly hold organisations accountable at the board level for AI governance, this standard defines what board-level AI oversight looks like.",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.iso.org/standard/56641.html",
        "locator": "Clauses 4–6",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/iso-38507-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/iso-38507-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2022-04-01",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iso-42001-data-governance",
      "regulation": "iso-42001",
      "name": "AI Data Governance",
      "requirements": [
        {
          "requirement": "Data quality",
          "details": "Establish processes for ensuring AI training and operational data quality"
        },
        {
          "requirement": "Data provenance",
          "details": "Document data sources and lineage"
        },
        {
          "requirement": "Data lifecycle",
          "details": "Manage data throughout the AI system lifecycle"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — certification-based"
        }
      ],
      "scope": "providers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://www.iso.org/standard/81230.html",
        "locator": "Clause 6, Annex B",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/iso-42001-data-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/iso-42001-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-12-18",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iso-42001-record-keeping",
      "regulation": "iso-42001",
      "name": "AI Documentation and Record-Keeping",
      "requirements": [
        {
          "requirement": "Documented information",
          "details": "Maintain documented information required by the AI management system"
        },
        {
          "requirement": "Performance evaluation",
          "details": "Monitor, measure, analyze, and evaluate AI system performance"
        },
        {
          "requirement": "Internal audit",
          "details": "Conduct internal audits at planned intervals"
        },
        {
          "requirement": "Management review",
          "details": "Top management must review the AI management system at planned intervals"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — certification-based"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://www.iso.org/standard/81230.html",
        "locator": "Clauses 7.5, 9",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/iso-42001-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/iso-42001-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-12-18",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iso-42001-risk",
      "regulation": "iso-42001",
      "name": "AI Risk Management System",
      "requirements": [
        {
          "requirement": "Risk assessment",
          "details": "Establish processes to identify and assess AI-related risks"
        },
        {
          "requirement": "Risk treatment",
          "details": "Implement controls to treat identified risks"
        },
        {
          "requirement": "Objectives",
          "details": "Set measurable AI management objectives"
        },
        {
          "requirement": "Leadership commitment",
          "details": "Top management must demonstrate commitment to the AI management system"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — certification-based, no direct penalties"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://www.iso.org/standard/81230.html",
        "locator": "Clauses 6-8",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/iso-42001-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/iso-42001-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-12-18",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "iso-42005-risk-assessment",
      "regulation": "iso-42005",
      "name": "AI System Impact Assessment",
      "requirements": [
        {
          "requirement": "Impact identification",
          "details": "Identify potential impacts of AI systems and their foreseeable applications on individuals, groups, and society"
        },
        {
          "requirement": "Intended and unintended use assessment",
          "details": "Assess intended, unintended, sensitive, restricted uses, and foreseeable misuse scenarios"
        },
        {
          "requirement": "Benefit and harm evaluation",
          "details": "Evaluate both positive and negative impacts throughout the AI lifecycle"
        },
        {
          "requirement": "Stakeholder perspective",
          "details": "Integrate perspectives of affected individuals and groups in the assessment process"
        },
        {
          "requirement": "Documentation",
          "details": "Produce assessment documentation supporting transparency, accountability, and fairness"
        },
        {
          "requirement": "Lifecycle integration",
          "details": "Apply impact assessment from design and development through deployment and post-market monitoring"
        },
        {
          "requirement": "Integration with risk management",
          "details": "Coordinate impact assessment with ISO/IEC 23894 (risk management) and ISO/IEC 42001 (management system)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "providers, deployers",
      "context": "ISO/IEC 42005 fills the gap between generic risk management (ISO 23894) and impact on individuals and society — it is the AI equivalent of a Data Protection Impact Assessment (DPIA). As AI impact assessment requirements appear in the EU AI Act, CETS 225, and national strategies, this standard provides the reference methodology for conducting them.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://www.iso.org/standard/44545.html",
        "locator": "Full standard",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/iso-42005-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/iso-42005-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-05-01",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "it-ai-law-bias-prevention",
      "regulation": "it-ai-law",
      "name": "Employment AI — Non-Discrimination",
      "requirements": [
        {
          "requirement": "Non-discrimination",
          "details": "AI used to organize or manage an employment relationship must preserve workers' inviolable rights without discrimination based on sex, age, ethnic origin, religious belief, sexual orientation, political opinion, or personal, social, and economic conditions (Art. 11(3))"
        },
        {
          "requirement": "Dignity and data privacy",
          "details": "Workplace AI use must be safe, reliable, and transparent; it must not conflict with human dignity or violate personal-data privacy (Art. 11(2))"
        }
      ],
      "penalties": [],
      "scope": "Employers and principals using AI to organize or manage employment relationships in Italy (Art. 11)",
      "context": "Penalties qualification: This entry does not assign a provision-specific penalty to Article 11. Applicable consequences depend on the competent employment, data-protection, national AI, and EU enforcement frameworks.",
      "instrument_notes": "Source and version boundary: the official Gazzetta Ufficiale issue supplies the original Law 132/2025 text. A Normattiva consolidated-act response retrieved on 2026-09-11 reports an act-level update published 2026-06-26 and lists Articles 4, 7, 8, 10, 11 and 20 as version 1; only Articles 19, 24 and 26 are marked with later versions. The static consolidated response did not expose the full cited article bodies, so exact wording is grounded in the official Gazette publication and currentness remains qualified without renewing Verified. Scope controls: Article 7 keeps listed clinical decisions with medical professionals. Article 8 applies only to its enumerated research actors and projects. Article 11 incorporates the cases and modalities of Legislative Decree 152/1997 Article 1-bis, including its covered fully automated systems and industrial or commercial secret exception. Article 10 assigns AGENAS national-platform functions and non-binding suggestions; those are institutional context, not a private deployer requirement. The provision role labels are ontology projections and do not broaden these statutory actor limits. Authority graph boundary: the AgID authority record no longer asserts a general enforcer role, but the instrument retains its existing single AgID authority reference and the machine authority graph remains partial; the jurisdiction and authority notes preserve the statutory allocation among AgID, ACN, sector authorities, the Garante and article-specific AGENAS functions.",
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG",
        "locator": "Art. 11 (uso dell'IA in ambito lavorativo — dignità, non-discriminazione, tutela dei diritti dei lavoratori)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/it-ai-law-bias-prevention.json",
        "obligations": [
          "https://everyailaw.com/obligation/it-ai-law-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-10-10",
        "verified": "2026-07-10",
        "checked": "2026-08-06",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "it-ai-law-data-governance",
      "regulation": "it-ai-law",
      "name": "Health Data for AI Research",
      "requirements": [
        {
          "requirement": "Eligible actors and purposes",
          "details": "Art. 8(1) declares processing by its listed public, nonprofit, IRCCS, and participating private health-sector actors to be of significant public interest when conducted for the provision's listed health and related AI-research purposes"
        },
        {
          "requirement": "Secondary use permitted",
          "details": "For the same purposes and actors, secondary use of personal data lacking direct identifiers is authorized without further consent where consent was initially required by law, subject to the information duty and the exception where identity is unavoidable or necessary to protect health (Art. 8(2))"
        },
        {
          "requirement": "Garante communication and standstill",
          "details": "Processing under Art. 8(1) and (2) must be communicated to the Garante with the information listed in Art. 8(5), and may begin after 30 days if it has not been blocked"
        },
        {
          "requirement": "Data-subject information",
          "details": "The information duty remains applicable; Art. 8(2) permits a general notice on the controller's website, while Art. 8(3) requires notice under GDPR Article 13 for processing to anonymize, pseudonymize, or synthesize data"
        },
        {
          "requirement": "GDPR qualification",
          "details": "Article 8 expressly operates within GDPR Article 9 and the Italian data-protection code; the applicable basis and safeguards depend on the actor and processing described in the provision"
        }
      ],
      "penalties": [],
      "scope": "Public actors, private nonprofit actors, IRCCS, and private health-sector actors participating in research projects with a public or private nonprofit actor or IRCCS, for the health and related research purposes listed in Art. 8(1)",
      "context": "Article 8 establishes a health-research pathway for specified public, nonprofit, IRCCS, and participating private health-sector actors. For those actors and purposes, secondary use under paragraph 2 is limited to personal data lacking direct identifiers, preserves the information duty, and carries an exception where identity is unavoidable or necessary to protect health. Processing under paragraphs 1 and 2 must be communicated to the Garante and may begin after 30 days if the Garante has not blocked it.\n\nPenalties qualification: Article 8(6) preserves the Garante's inspection, prohibition, and sanctioning powers. This entry does not assign a fixed penalty ceiling or infringement category to Article 8 conduct.\n\nInstitutional context (not a private requirement): Article 8(4) permits AGENAS, after consulting the Garante and considering international standards and the state of the art, to establish and update guidelines for anonymization procedures and synthetic data. The provision grants an institutional power; it does not itself impose a universal anonymization standard on every researcher.",
      "instrument_notes": "Source and version boundary: the official Gazzetta Ufficiale issue supplies the original Law 132/2025 text. A Normattiva consolidated-act response retrieved on 2026-09-11 reports an act-level update published 2026-06-26 and lists Articles 4, 7, 8, 10, 11 and 20 as version 1; only Articles 19, 24 and 26 are marked with later versions. The static consolidated response did not expose the full cited article bodies, so exact wording is grounded in the official Gazette publication and currentness remains qualified without renewing Verified. Scope controls: Article 7 keeps listed clinical decisions with medical professionals. Article 8 applies only to its enumerated research actors and projects. Article 11 incorporates the cases and modalities of Legislative Decree 152/1997 Article 1-bis, including its covered fully automated systems and industrial or commercial secret exception. Article 10 assigns AGENAS national-platform functions and non-binding suggestions; those are institutional context, not a private deployer requirement. The provision role labels are ontology projections and do not broaden these statutory actor limits. Authority graph boundary: the AgID authority record no longer asserts a general enforcer role, but the instrument retains its existing single AgID authority reference and the machine authority graph remains partial; the jurisdiction and authority notes preserve the statutory allocation among AgID, ACN, sector authorities, the Garante and article-specific AGENAS functions.",
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG",
        "locator": "Art. 8 (ricerca e sperimentazione scientifica in ambito sanitario — rilevante interesse pubblico; Garante 30-day prior notification, comma 5); Art. 9 (disposizioni in materia di trattamento di dati personali — delega al decreto del Ministro della salute entro 120 giorni; not itself an operative rule)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/it-ai-law-data-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/it-ai-law-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-10-10",
        "verified": "2026-08-15",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "it-ai-law-human-oversight",
      "regulation": "it-ai-law",
      "name": "Healthcare AI — Human Oversight",
      "requirements": [
        {
          "requirement": "Physician authority",
          "details": "For prevention, diagnosis, care, and therapeutic choice, the decision remains with medical professionals (Art. 7(5))"
        },
        {
          "requirement": "Patient notification",
          "details": "Data subjects have the right to be informed that AI technologies are being used (Art. 7, comma 3). The Act grants a right to be informed of AI use; it does not require disclosure of decision logic or of expected benefits"
        },
        {
          "requirement": "Support role only",
          "details": "Healthcare AI systems constitute support in prevention, diagnosis, care, and therapeutic choice (Art. 7(5))"
        },
        {
          "requirement": "Reliability and updating",
          "details": "Healthcare AI systems and the data they use must be reliable, periodically verified, and updated to minimize errors and improve patient safety (Art. 7(6))"
        }
      ],
      "penalties": [],
      "scope": "Use of AI systems in healthcare for prevention, diagnosis, care, or therapeutic choice; the clinical decision remains with medical professionals (Art. 7(5))",
      "context": "Article 7 treats healthcare AI as support in prevention, diagnosis, care, and therapeutic choice while reserving the clinical decision to medical professionals. It separately gives the interested person a right to be informed of AI use and requires healthcare AI systems and their data to be reliable, periodically verified, and updated.\n\nPenalties qualification: This entry does not assign a provision-specific penalty to the Article 7 requirements. Applicable oversight and sanctions depend on the competent authority and the relevant national and EU framework.\n\nInstitutional context (not a private requirement): Article 10 inserts Article 12-bis into Decree-Law 179/2012. It assigns AGENAS the design, implementation, operation, and ownership of a national healthcare AI platform. The platform supplies non-binding suggestions to healthcare professionals and doctors and access support to users. These are statutory functions of AGENAS and the platform, not requirements imposed on the private deployers described in the Article 7 provision above.",
      "instrument_notes": "Source and version boundary: the official Gazzetta Ufficiale issue supplies the original Law 132/2025 text. A Normattiva consolidated-act response retrieved on 2026-09-11 reports an act-level update published 2026-06-26 and lists Articles 4, 7, 8, 10, 11 and 20 as version 1; only Articles 19, 24 and 26 are marked with later versions. The static consolidated response did not expose the full cited article bodies, so exact wording is grounded in the official Gazette publication and currentness remains qualified without renewing Verified. Scope controls: Article 7 keeps listed clinical decisions with medical professionals. Article 8 applies only to its enumerated research actors and projects. Article 11 incorporates the cases and modalities of Legislative Decree 152/1997 Article 1-bis, including its covered fully automated systems and industrial or commercial secret exception. Article 10 assigns AGENAS national-platform functions and non-binding suggestions; those are institutional context, not a private deployer requirement. The provision role labels are ontology projections and do not broaden these statutory actor limits. Authority graph boundary: the AgID authority record no longer asserts a general enforcer role, but the instrument retains its existing single AgID authority reference and the machine authority graph remains partial; the jurisdiction and authority notes preserve the statutory allocation among AgID, ACN, sector authorities, the Garante and article-specific AGENAS functions.",
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG",
        "locator": "Art. 7, commi 3, 5 e 6 (patient information; clinical support and physician-retained decision; reliability, periodic verification and updating)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/it-ai-law-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/it-ai-law-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-10-10",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "it-ai-law-transparency",
      "regulation": "it-ai-law",
      "name": "Employment AI — Transparency and Disclosure",
      "requirements": [
        {
          "requirement": "Worker notification",
          "details": "Employers and principals must inform workers of AI use in the cases and modalities of Art. 1-bis D.Lgs. 152/1997, which covers fully automated decision or monitoring systems producing indications relevant to hiring, management, termination, task assignment, surveillance, evaluation, performance, or contractual obligations"
        },
        {
          "requirement": "Covered-system information",
          "details": "For systems covered by Art. 1-bis D.Lgs. 152/1997, required information includes affected employment aspects, purposes, logic and functioning, data categories and principal parameters, control and correction measures, responsible quality-management personnel, and accuracy, robustness, cybersecurity and potentially discriminatory metric impacts"
        },
        {
          "requirement": "Industrial and commercial secret exception",
          "details": "The incorporated Art. 1-bis information duties do not apply to systems protected by industrial and commercial secrecy (Art. 1-bis(8))"
        },
        {
          "requirement": "Minors consent",
          "details": "Access to AI technologies by children under 14 and consequent personal-data processing require consent from the person exercising parental responsibility (Art. 4(4))"
        }
      ],
      "penalties": [],
      "scope": "Employers and principals using AI in the workplace; the incorporated information duties apply to the fully automated decision or monitoring systems and employment effects listed in Art. 1-bis D.Lgs. 152/1997. Separately, under-14 access to AI technologies and consequent personal-data processing require parental-responsibility consent (Arts. 11(2), 4(4))",
      "context": "Article 11 requires employers and principals to inform workers of workplace AI use in the cases and modalities of Article 1-bis of Legislative Decree 152/1997. That incorporated provision covers fully automated decision or monitoring systems producing indications relevant to specified employment decisions and conditions. Article 4(4) separately ties under-14 access to AI technologies and consequent personal-data processing to parental-responsibility consent.\n\nPenalties qualification: This entry does not assign a provision-specific penalty to Article 11. Applicable consequences depend on the incorporated employment-law duties and the competent national and EU enforcement frameworks.",
      "instrument_notes": "Source and version boundary: the official Gazzetta Ufficiale issue supplies the original Law 132/2025 text. A Normattiva consolidated-act response retrieved on 2026-09-11 reports an act-level update published 2026-06-26 and lists Articles 4, 7, 8, 10, 11 and 20 as version 1; only Articles 19, 24 and 26 are marked with later versions. The static consolidated response did not expose the full cited article bodies, so exact wording is grounded in the official Gazette publication and currentness remains qualified without renewing Verified. Scope controls: Article 7 keeps listed clinical decisions with medical professionals. Article 8 applies only to its enumerated research actors and projects. Article 11 incorporates the cases and modalities of Legislative Decree 152/1997 Article 1-bis, including its covered fully automated systems and industrial or commercial secret exception. Article 10 assigns AGENAS national-platform functions and non-binding suggestions; those are institutional context, not a private deployer requirement. The provision role labels are ontology projections and do not broaden these statutory actor limits. Authority graph boundary: the AgID authority record no longer asserts a general enforcer role, but the instrument retains its existing single AgID authority reference and the machine authority graph remains partial; the jurisdiction and authority notes preserve the statutory allocation among AgID, ACN, sector authorities, the Garante and article-specific AGENAS functions.",
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG",
        "locator": "Art. 11, comma 2 (worker information duty in the cases and modalities of Art. 1-bis D.Lgs. 152/1997); Art. 4, comma 4 (under-14 access and consequent personal-data processing)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/it-ai-law-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/it-ai-law-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-10-10",
        "verified": "2026-07-10",
        "checked": "2026-08-06",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "jp-ai-promotion-act-risk",
      "regulation": "jp-ai-promotion-act",
      "name": "AI Risk Governance",
      "requirements": [
        {
          "requirement": "Government investigation and research",
          "details": "Under Art. 16, the national government collects information on domestic and international AI trends, analyses rights-infringement cases associated with AI research, development or use for improper purposes or by improper methods, considers countermeasures and conducts other relevant investigation and research"
        },
        {
          "requirement": "Government response",
          "details": "Based on that work, the national government takes necessary measures, including guidance, advice and information for research institutions, AI-utilising businesses and others"
        },
        {
          "requirement": "AI Basic Plan",
          "details": "Under Art. 18, the Government must establish the AI Basic Plan, covering foundational policy and measures it will take comprehensively and systematically"
        },
        {
          "requirement": "Cabinet process",
          "details": "The Prime Minister must seek a Cabinet decision on the draft prepared by the AI Strategy Headquarters and publish the plan without delay after that decision"
        },
        {
          "requirement": "Context",
          "details": "Arts. 16 and 18 describe government investigation, response and planning. They do not impose a generic private developer or deployer risk-assessment duty"
        },
        {
          "requirement": "Translation",
          "details": "These English descriptions are working translations of the retained official Japanese text, not official English wording"
        }
      ],
      "penalties": [
        {
          "violation": "Government functions",
          "fine": "On 2026-09-11, a full-text search of the retained Japanese Act for 罰則, 罰金, 過料, 懲役, 拘禁, 刑に処 and 処罰 returned no matches. This does not rule out consequences under other law or convert the Act's statutory government functions into voluntary guidance"
        }
      ],
      "scope": "National government functions. Art. 16 permits resulting guidance, advice and information for research institutions, AI-utilising businesses and others; those recipients are not assigned a generic risk-assessment duty. Art. 18 binds the Government",
      "context": null,
      "instrument_notes": "Source and actor boundary: the official e-Gov PDF is the Japanese text of Act No. 53 of 2025 in its 2025-09-01 version. English descriptions here are working translations, not an official English text. Article 7 binds the Act's defined AI-utilising businesses, including persons seeking to develop or provide AI-enabled products or services and other persons seeking to use AI in business activities. They must cooperate with national and local government measures. Articles 16 and 18 instead assign investigation, response and Basic Plan functions to the national government; they do not create generic private developer or deployer risk-assessment duties. The former transparency and risk-assessment category projections are withdrawn while their source Terms remain for provenance. On 2026-09-11, a full-text search of raw/jp/session6-2026-09-11-act-53-2025-egov.txt for 罰則, 罰金, 過料, 懲役, 拘禁, 刑に処 and 処罰 returned no matches. This does not rule out consequences under other law, change Article 7's mandatory cooperation wording or make the Act wholly voluntary.",
      "roles": [],
      "status": "enforcing",
      "source": {
        "url": "https://laws.e-gov.go.jp/data/Act/507AC0000000053/624018_1/507AC0000000053_20250901_000000000000000_h1.pdf",
        "locator": "Art. 16 (government measures on AI risks, incl. analysis of improper-use/rights-infringement cases, guidance and advice); Art. 18 (formulation of the AI Basic Plan / 人工知能基本計画)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/jp-ai-promotion-act-risk.json",
        "obligations": []
      },
      "dates": {
        "recorded_effective": "Art. 16: promulgation date under Supplementary Provision Art. 1; Art. 18: 2025-09-01 in the reviewed e-Gov version",
        "verified": "2026-07-10",
        "checked": "2026-08-04",
        "instrument_last_verified": "2026-07-10",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "jp-ai-promotion-act-transparency",
      "regulation": "jp-ai-promotion-act",
      "name": "AI Transparency and Cooperation",
      "requirements": [
        {
          "requirement": "Business activity",
          "details": "AI-utilising businesses must endeavour to improve and advance their business activities and create new industries through their own active use of AI-related technology"
        },
        {
          "requirement": "Cooperation with government",
          "details": "AI-utilising businesses must cooperate with measures implemented by the national government under Art. 4 and by local governments under Art. 5"
        },
        {
          "requirement": "Context",
          "details": "Art. 7 acts under the Art. 3 basic principles. Art. 3(4) calls for necessary measures, including transparency in AI research, development and use, where improper purposes or methods risk harm. It does not state a generic private disclosure duty or an extraterritorial rule"
        },
        {
          "requirement": "Translation",
          "details": "These English descriptions are working translations of the retained official Japanese text, not official English wording"
        }
      ],
      "penalties": [
        {
          "violation": "Article 7 cooperation duty",
          "fine": "On 2026-09-11, a full-text search of the retained Japanese Act for 罰則, 罰金, 過料, 懲役, 拘禁, 刑に処 and 処罰 returned no matches. This does not rule out consequences under other law, change Art. 7's mandatory cooperation wording or make the Act wholly voluntary"
        }
      ],
      "scope": "AI-utilising businesses (活用事業者): persons seeking to develop or provide products or services using AI-related technology, plus other persons seeking to use that technology in business activities",
      "context": null,
      "instrument_notes": "Source and actor boundary: the official e-Gov PDF is the Japanese text of Act No. 53 of 2025 in its 2025-09-01 version. English descriptions here are working translations, not an official English text. Article 7 binds the Act's defined AI-utilising businesses, including persons seeking to develop or provide AI-enabled products or services and other persons seeking to use AI in business activities. They must cooperate with national and local government measures. Articles 16 and 18 instead assign investigation, response and Basic Plan functions to the national government; they do not create generic private developer or deployer risk-assessment duties. The former transparency and risk-assessment category projections are withdrawn while their source Terms remain for provenance. On 2026-09-11, a full-text search of raw/jp/session6-2026-09-11-act-53-2025-egov.txt for 罰則, 罰金, 過料, 懲役, 拘禁, 刑に処 and 処罰 returned no matches. This does not rule out consequences under other law, change Article 7's mandatory cooperation wording or make the Act wholly voluntary.",
      "roles": [],
      "status": "enforcing",
      "source": {
        "url": "https://laws.e-gov.go.jp/data/Act/507AC0000000053/624018_1/507AC0000000053_20250901_000000000000000_h1.pdf",
        "locator": "Art. 7 (活用事業者の責務 — duty of AI-utilising businesses to cooperate with national/local government measures)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/jp-ai-promotion-act-transparency.json",
        "obligations": []
      },
      "dates": {
        "recorded_effective": "Promulgation date under Supplementary Provision Art. 1; the reviewed e-Gov version is effective 2025-09-01",
        "verified": "2026-07-10",
        "checked": "2026-08-05",
        "instrument_last_verified": "2026-07-10",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "kr-ai-basic-act-oversight",
      "regulation": "kr-ai-basic-act",
      "name": "AI Governance and Human Oversight",
      "requirements": [
        {
          "requirement": "Human oversight mechanisms",
          "details": "Art. 34(1) requires human oversight of the operation of high-impact AI, alongside a risk management plan, explanation measures, user protection, and documentation"
        },
        {
          "requirement": "Ministerial guidelines",
          "details": "Art. 34(2) lets the Minister of Science and ICT publish detailed guidelines on those measures and recommend compliance"
        },
        {
          "requirement": "Domestic representative",
          "details": "Art. 36 requires qualifying foreign operators to designate a domestic representative"
        },
        {
          "requirement": "On-site inspections",
          "details": "Art. 40 lets the Minister of Science and ICT require submission of data and conduct on-site inspections under the Administrative Investigation Framework Act"
        },
        {
          "requirement": "Corrective measures",
          "details": "Art. 40 authorises corrective orders against non-compliant operators"
        }
      ],
      "penalties": [
        {
          "violation": "Administrative fine",
          "fine": "Up to KRW 30 million (Art. 43)"
        },
        {
          "violation": "Criminal penalties",
          "fine": "Art. 42"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%EB%B0%9C%EC%A0%84%EA%B3%BC%EC%8B%A0%EB%A2%B0%EA%B8%B0%EB%B0%98%EC%A1%B0%EC%84%B1%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B8%B0%EB%B3%B8%EB%B2%95",
        "locator": "Articles 34, 36, 40",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/kr-ai-basic-act-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/kr-ai-basic-act-oversight-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-22",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [
          {
            "date": "2026-07-21",
            "description": "Act No. 21311 (promulgated 2026-01-20, largely in force 2026-01-22) renamed the National AI Committee to the National AI Strategy Committee, added support and vulnerable-group provisions, and added a latter part to Art. 35(1) requiring high-impact AI impact assessments to reflect the characteristics of AI-vulnerable groups; the deferred provisions, including the Art. 35(1) latter part, entered into force 2026-07-21."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "kr-ai-basic-act-risk",
      "regulation": "kr-ai-basic-act",
      "name": "High-Impact AI Risk Management",
      "requirements": [
        {
          "requirement": "High-impact domains",
          "details": "Art. 2(4) defines high-impact AI by domain, not by model size: energy supply, drinking water, healthcare services, medical and digital medical devices, nuclear materials and facilities, biometric analysis for criminal investigation, judgments significantly affecting rights such as employment or loan decisions, and transport operations"
        },
        {
          "requirement": "Self-review and confirmation",
          "details": "Art. 33 requires operators to review in advance whether a system is high-impact, and allows them to request confirmation from the Minister of Science and ICT"
        },
        {
          "requirement": "Operator obligations",
          "details": "Art. 34 requires a risk management plan; explanation measures covering final outputs, the principal criteria used, and an overview of training data, to the extent technically feasible; user-protection measures; human oversight; and retained documentation of the measures taken"
        },
        {
          "requirement": "Impact assessment",
          "details": "Art. 35 is a best-effort duty — operators \"shall endeavor\" to assess impacts on fundamental rights; public institutions are to prioritise products that have been assessed"
        },
        {
          "requirement": "Vulnerable-group reflection",
          "details": "Art. 35(1) latter part (added by Act No. 21311, in force 2026-07-21) requires that where an impact assessment is conducted, it must reflect the characteristics of AI-vulnerable groups (persons with disabilities, older persons, and others prescribed by Presidential Decree under Art. 3(5)), considering the nature of the product or service"
        },
        {
          "requirement": "Compute-threshold safety duty",
          "details": "Art. 32 imposes separate safety measures on models whose cumulative training compute meets the threshold set by Presidential Decree; the threshold value itself lives in the decree, not the Act"
        }
      ],
      "penalties": [
        {
          "violation": "Administrative fine",
          "fine": "Up to KRW 30 million (Art. 43)"
        },
        {
          "violation": "Criminal penalties",
          "fine": "Art. 42"
        },
        {
          "violation": "Supervisory action",
          "fine": "The Minister of Science and ICT may require data submission, conduct on-site inspections, and issue corrective orders (Art. 40); one-year guidance period runs to Jan 2027"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%EB%B0%9C%EC%A0%84%EA%B3%BC%EC%8B%A0%EB%A2%B0%EA%B8%B0%EB%B0%98%EC%A1%B0%EC%84%B1%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B8%B0%EB%B3%B8%EB%B2%95",
        "locator": "Articles 32-35 (definition at Article 2(4))",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/kr-ai-basic-act-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/kr-ai-basic-act-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-22",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [
          {
            "date": "2026-07-21",
            "description": "Act No. 21311 (promulgated 2026-01-20, largely in force 2026-01-22) renamed the National AI Committee to the National AI Strategy Committee, added support and vulnerable-group provisions, and added a latter part to Art. 35(1) requiring high-impact AI impact assessments to reflect the characteristics of AI-vulnerable groups; the deferred provisions, including the Art. 35(1) latter part, entered into force 2026-07-21."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "kr-ai-basic-act-transparency",
      "regulation": "kr-ai-basic-act",
      "name": "AI Transparency and Disclosure",
      "requirements": [
        {
          "requirement": "Prior notification",
          "details": "Art. 31(1) requires operators to notify users in advance that a product or service using high-impact AI or generative AI is operated on that basis"
        },
        {
          "requirement": "Generative output indication",
          "details": "Art. 31(2) requires clear indication to users that outputs are generated by GenAI"
        },
        {
          "requirement": "Realistic synthetic content",
          "details": "Art. 31(3) requires clearly recognisable notification or marking where AI generates virtual audio, images, or video hard to distinguish from real content"
        },
        {
          "requirement": "Artistic-works carve-out",
          "details": "Art. 31(3) proviso allows the marking of artistic or creative works to be made in a way that does not interfere with their exhibition or enjoyment"
        },
        {
          "requirement": "Methods and exceptions",
          "details": "Art. 31(4) leaves the methods of notification and marking, and exceptions to them, to Presidential Decree"
        }
      ],
      "penalties": [
        {
          "violation": "Failure to give prior notification (Art. 31(1))",
          "fine": "Administrative fine up to KRW 30 million (Art. 43)"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%EB%B0%9C%EC%A0%84%EA%B3%BC%EC%8B%A0%EB%A2%B0%EA%B8%B0%EB%B0%98%EC%A1%B0%EC%84%B1%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B8%B0%EB%B3%B8%EB%B2%95",
        "locator": "Article 31",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/kr-ai-basic-act-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/kr-ai-basic-act-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-22",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [
          {
            "date": "2026-07-21",
            "description": "Act No. 21311 (promulgated 2026-01-20, largely in force 2026-01-22) renamed the National AI Committee to the National AI Strategy Committee, added support and vulnerable-group provisions, and added a latter part to Art. 35(1) requiring high-impact AI impact assessments to reflect the characteristics of AI-vulnerable groups; the deferred provisions, including the Art. 35(1) latter part, entered into force 2026-07-21."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "kz-ai-law-bias-prevention",
      "regulation": "kz-ai-law",
      "name": "Prohibited AI Practices",
      "requirements": [
        {
          "requirement": "Harm-linked manipulation",
          "details": "Prohibits subconscious, manipulative, or other methods that distort an individual's behaviour and limit informed choice or compel decisions that may cause harm or threaten harm"
        },
        {
          "requirement": "Harmful vulnerability exploitation",
          "details": "Prohibits exploiting moral or physical vulnerability due to age, disability, social status, or other circumstances for the purpose of causing or threatening harm"
        },
        {
          "requirement": "Social evaluation",
          "details": "Prohibits evaluating or classifying individuals or groups over time by social behaviour or known, assumed, or predicted personal characteristics, except as provided by Kazakhstan law"
        },
        {
          "requirement": "Unlawful personal-data processing",
          "details": "Prohibits collection and processing of personal data in violation of Kazakhstan personal-data law"
        },
        {
          "requirement": "Biometric discrimination",
          "details": "Prohibits biometric classification that infers race, political views, religion, or other criteria for the purpose of discrimination"
        },
        {
          "requirement": "Emotion detection",
          "details": "Prohibits determining an individual's emotions without consent, except as provided by Kazakhstan law"
        },
        {
          "requirement": "Unlawful outputs",
          "details": "Prohibits creating and distributing AI-system outputs prohibited by Kazakhstan law"
        }
      ],
      "penalties": [],
      "scope": "Creation and operation in Kazakhstan of AI systems possessing a listed Article 17(3) functionality, subject to each paragraph's harm, purpose, consent, or statutory-exception condition",
      "context": "Article 17(3) prohibits creating or operating AI systems in Kazakhstan when they possess one of seven listed functionalities. The clauses are conditional: manipulative methods must distort behaviour and constrain informed choice or force a decision capable of causing harm; vulnerability exploitation requires a harmful purpose or threat; social evaluation has statutory exceptions; biometric classification must be for discrimination; and emotion detection has consent and statutory exceptions.\n\nPenalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set an Article 17-specific MCI fine or suspension rule.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://old.adilet.zan.kz/rus/docs/Z2500000230",
        "locator": "Article 17(3)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/kz-ai-law-bias-prevention.json",
        "obligations": [
          "https://everyailaw.com/obligation/kz-ai-law-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-18",
        "verified": "2026-03-28",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [
          {
            "date": "2026-08-25",
            "description": "Adilet's current text incorporates Law No. 326-VIII amendments to Articles 1, 13, 17, 20, and 28; the official metadata records 25 August 2026 as the Act's change date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "kz-ai-law-record-keeping",
      "regulation": "kz-ai-law",
      "name": "Documentation and Record-Keeping",
      "requirements": [
        {
          "requirement": "Impact-dependent documentation",
          "details": "Owners and holders must maintain AI-system documentation according to the system's degree of impact on safety, individual rights, freedoms and lawful interests, and public order"
        },
        {
          "requirement": "Authorised documentation list",
          "details": "Documentation must conform to the AI-system documentation list that Article 13(1)(5) assigns the authorised body to approve"
        },
        {
          "requirement": "Boundary from risk management",
          "details": "Articles 11, 15, and 18 impose risk-management and safety duties, but the reviewed Act text does not itself convert every risk-management activity into a separate record-keeping item"
        }
      ],
      "penalties": [],
      "scope": "Owners and holders of AI systems",
      "context": "Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not state a documentation-specific MCI range.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://old.adilet.zan.kz/rus/docs/Z2500000230",
        "locator": "Articles 13(1)(5), 15(2)(3)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/kz-ai-law-record-keeping.json",
        "obligations": [
          "https://everyailaw.com/obligation/kz-ai-law-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-18",
        "verified": "2026-03-28",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [
          {
            "date": "2026-08-25",
            "description": "Adilet's current text incorporates Law No. 326-VIII amendments to Articles 1, 13, 17, 20, and 28; the official metadata records 25 August 2026 as the Act's change date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "kz-ai-law-risk-assessment",
      "regulation": "kz-ai-law",
      "name": "Risk-Based Classification and Management",
      "requirements": [
        {
          "requirement": "Risk classification",
          "details": "Owners and holders classify their systems as minimum, medium, or high risk under the digital-object classification rules, using the Article 17(1) consequences of malfunction or cessation"
        },
        {
          "requirement": "Lifecycle risk management",
          "details": "Owners and holders must identify and analyse known and foreseeable risks, evaluate intended and foreseeable misuse, adopt targeted measures, and update risks at least annually"
        },
        {
          "requirement": "Prohibited-function risk response",
          "details": "If risks of an Article 17(3) prohibited circumstance are identified, owners and holders must take immediate prevention and harm-minimisation measures, including suspension or complete cessation where appropriate"
        },
        {
          "requirement": "Documentation",
          "details": "Owners and holders must maintain system documentation according to the system's degree of impact and the documentation list approved by the authorised body"
        },
        {
          "requirement": "Trusted-list audit",
          "details": "Owners or holders seeking inclusion in a trusted high-risk systems list must conduct an AI-system audit"
        },
        {
          "requirement": "Audit framework",
          "details": "Article 20 applies the digital-system audit rules and additionally assesses training-data-library quality and lawfulness and the presence of prohibited functionality"
        },
        {
          "requirement": "National platform boundary",
          "details": "Article 25 establishes a controlled environment and delegates platform-service interaction rules; it does not impose universal high-risk platform use"
        }
      ],
      "penalties": [],
      "scope": "Owners and holders of AI systems; the audit duty in Article 19(2) is limited to systems seeking inclusion in a trusted high-risk list",
      "context": "Owners and holders classify AI systems as minimum, medium, or high risk and perform lifecycle risk management. Article 19(2) requires an audit when an owner or holder seeks inclusion in an industry authority's trusted high-risk list; Article 20 specifies the audit framework and added assessment topics. Article 25 describes the National AI Platform as a controlled environment for platform software products and models, but does not require every high-risk system to be developed or tested there.\n\nPenalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a 15–200 MCI fine range.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://old.adilet.zan.kz/rus/docs/Z2500000230",
        "locator": "Articles 11(3), 15(2)(1)-(3), 17(1), 18-20, 25",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/kz-ai-law-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/kz-ai-law-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-18",
        "verified": "2026-03-28",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [
          {
            "date": "2026-08-25",
            "description": "Adilet's current text incorporates Law No. 326-VIII amendments to Articles 1, 13, 17, 20, and 28; the official metadata records 25 August 2026 as the Act's change date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "kz-ai-law-transparency",
      "regulation": "kz-ai-law",
      "name": "Synthetic Content Labeling and User Notification",
      "requirements": [
        {
          "requirement": "AI-use notice",
          "details": "Users must be informed that goods, works, or services were produced or are provided using AI systems"
        },
        {
          "requirement": "Synthetic-result marking",
          "details": "Distribution of a synthetic result as defined in Article 1(4) requires marking in machine-readable form"
        },
        {
          "requirement": "Perceptible warning",
          "details": "The marked synthetic result must also carry a visual or other warning users can perceive without methods that hinder perception"
        },
        {
          "requirement": "Responsible actors",
          "details": "Owners or holders are responsible for informing users about synthetic results"
        },
        {
          "requirement": "User agreement",
          "details": "Owners and holders must let users review the AI system's user agreement before use"
        },
        {
          "requirement": "Automated personal-data decisions",
          "details": "Article 21(4) leaves requirements for decisions based exclusively on automated personal-data processing to Kazakhstan's personal-data legislation"
        }
      ],
      "penalties": [],
      "scope": "Article 21(3) assigns synthetic-result information responsibility to owners and holders, and Article 15(2)(5) assigns user-agreement access to them; Article 21(1) states the user information duty without naming a responsible actor",
      "context": "Article 21 requires users to be informed when goods, works, or services are produced or provided using AI. Distribution of a synthetic result is allowed only with a machine-readable mark and a perceptible visual or other warning. Article 1(4) limits a synthetic result to AI-created or AI-altered image, video, audio, text, or a combination that imitates a natural person's appearance, voice, or behaviour, or events that did not occur; it does not cover every generated output.\n\nPenalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a labeling-specific MCI fine.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://old.adilet.zan.kz/rus/docs/Z2500000230",
        "locator": "Articles 1(4), 15(2)(5), 21",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/kz-ai-law-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/kz-ai-law-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-18",
        "verified": "2026-03-28",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [
          {
            "date": "2026-08-25",
            "description": "Adilet's current text incorporates Law No. 326-VIII amendments to Articles 1, 13, 17, 20, and 28; the official metadata records 25 August 2026 as the Act's change date."
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "maine-ai-mental-health-consent-recording",
      "regulation": "maine-ai-mental-health",
      "name": "Written Consent and the Session-Recording Condition for Supplementary AI Support",
      "requirements": [
        {
          "requirement": "Recording or transcription is a precondition",
          "details": "A licensee may use AI to assist in supplementary support \"only when the client's therapeutic session is recorded or transcribed\" (§ 2113(3))"
        },
        {
          "requirement": "Written pre-use disclosure",
          "details": "The client or legally authorized representative must be informed in writing that AI will be used and of the specific purpose of the AI tool or system (§ 2113(3)(A)(1)-(2))"
        },
        {
          "requirement": "Data lifecycle disclosure including training use",
          "details": "The written notice must state how session data collected by the AI will be stored, retained, used for training, and deleted upon termination of therapy or psychotherapy services (§ 2113(3)(A)(3))"
        },
        {
          "requirement": "Affirmative written consent",
          "details": "The client or legally authorized representative must provide consent — a clear, explicit, affirmative act unambiguously communicating express, informed, voluntary, specific, and unambiguous written agreement, which may be given electronically or by initialing a specific section of the general consent-to-treatment agreement, and which is revocable (§§ 2113(1)(C), 2113(3)(B))"
        },
        {
          "requirement": "Excluded consent mechanics",
          "details": "Consent does not include an agreement obtained by acceptance of a general or broad terms-of-use agreement or similar document that mixes AI descriptions with unrelated information, by hovering over, muting, pausing, or closing a piece of electronic content, or through deceptive actions (§ 2113(1)(C)(1)-(3))"
        },
        {
          "requirement": "Consent as a gate on use",
          "details": "AI may provide supplementary support only to the extent the use meets the § 2113(3) requirements (§ 2113(4))"
        },
        {
          "requirement": "No treatment denial for withheld consent",
          "details": "A licensee may not deny or refuse therapy or psychotherapy services to a client on the sole basis that the client has not consented to AI-assisted supplementary support (§ 2113(5))"
        },
        {
          "requirement": "Waiver is void",
          "details": "Any waiver by a client of the provisions of the section is contrary to public policy and is void and unenforceable (§ 2113(11))"
        }
      ],
      "penalties": [
        {
          "violation": "Board discipline",
          "fine": "A violation is subject to disciplinary action by the board pursuant to 10 M.R.S. § 8003(5) (§ 2113(8)); no dollar amounts are set in the act"
        },
        {
          "violation": "Waiver unenforceable",
          "fine": "A client waiver of the section's protections is void and unenforceable as contrary to public policy (§ 2113(11))"
        },
        {
          "violation": "Civil actions preserved",
          "fine": "The client or the client's authorized representative may maintain an action for harm attributable to the AI use, an action for professional negligence, or seek any other remedies available under other provisions of law (§ 2113(12))"
        }
      ],
      "scope": "Licensees using AI to assist in providing supplementary support in therapy or psychotherapy services — records and therapy notes, anonymized progress analysis, and referral organization (§ 2113(1)(D)). The client or the client's legally authorized representative is the consenting party. Exempt: IRB-approved research use under 22 M.R.S. § 1711-C(6)(G) (§ 2113(9))",
      "context": "This is the requirement neither Vermont nor Rhode Island has: Maine permits AI supplementary support \"only when the client's therapeutic session is recorded or transcribed\" (§ 2113(3)). That is an affirmative surveillance precondition, not a restriction on surveillance — a practice that wants an AI scribe or progress-tracking tool must first put the session on the record. Paired with it is a consent definition (§ 2113(1)(C)) that is unusually strict even against Rhode Island's: consent must be a clear, explicit, affirmative act communicating express, informed, voluntary, specific, unambiguous written agreement, revocable by the client, and it expressly is not acceptance of a general or broad terms-of-use agreement, not hovering over, muting, pausing, or closing electronic content, and not anything obtained through deceptive actions. The disclosure at § 2113(3)(A)(3) reaches further than either sibling statute: the client must be told in writing how session data will be stored, retained, **used for training**, and deleted on termination of services — a written commitment about training-data use, made per client. And § 2113(5) bars the licensee from denying or refusing treatment because the client withheld consent, so declining AI is genuinely costless for the client and fully blocking for the licensee. Any client waiver of the section is void as contrary to public policy (§ 2113(11)), which forecloses the intake-paperwork workaround.",
      "instrument_notes": null,
      "roles": [
        "healthcare-provider",
        "deployer",
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislature.maine.gov/legis/bills/getPDF.asp?item=3&paper=HP1397&snum=132",
        "locator": "32 M.R.S. § 2113(1)(C), § 2113(3), § 2113(5), § 2113(11), § 2113(12)",
        "citation": "10 M.R.S. § 1500-EE; 32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009, 13870 (P.L. 2026 ch. 687)"
      },
      "of": {
        "term": "https://everyailaw.com/term/maine-ai-mental-health-consent-recording.json",
        "obligations": [
          "https://everyailaw.com/obligation/maine-ai-mental-health-consent-recording-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-29",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "maine-ai-mental-health-licensed-delivery",
      "regulation": "maine-ai-mental-health",
      "name": "Licensed Professional Delivery of Therapy or Psychotherapy Services",
      "requirements": [
        {
          "requirement": "Licensed human must deliver the service",
          "details": "A person may not provide, advertise, or otherwise offer therapy or psychotherapy services to the public, including through the use of Internet-based artificial intelligence, unless the services are provided by a licensed professional (§ 1500-EE(2))"
        },
        {
          "requirement": "Enumerated licence classes only",
          "details": "\"Licensed professional\" means an individual holding a valid Maine licence or certificate to practise psychotherapy or behavioral health therapy, including licensees under 32 M.R.S. ch. 56, ch. 83, ch. 119, ch. 81 (where authorized to provide therapy or psychotherapy services), and ch. 31, plus physicians and physician associates under ch. 36 or 48 who specialize in the diagnosis and treatment of mental disorders (§ 1500-EE(1)(B))"
        },
        {
          "requirement": "Statutory AI definition",
          "details": "\"Artificial intelligence\" is the OECD-style formulation: a machine-based system that, for explicit or implicit objectives, infers from its input how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments (§ 1500-EE(1)(A))"
        },
        {
          "requirement": "Research use is the only exception",
          "details": "The section does not apply to an AI-based intervention used solely within an IRB-approved research project as defined in 22 M.R.S. § 1711-C(6)(G), conducted in compliance with all applicable federal protections for human subjects (§ 1500-EE(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Unfair Trade Practices Act violation",
          "fine": "A violation of § 1500-EE(2) is a violation of the Maine Unfair Trade Practices Act (§ 1500-EE(3)) — Attorney General enforcement under 5 M.R.S. ch. 10. The act itself sets no dollar amounts"
        }
      ],
      "scope": "Any person who provides, advertises, or otherwise offers therapy or psychotherapy services to the public, expressly \"including through the use of Internet-based artificial intelligence\" (§ 1500-EE(2)). \"Therapy or psychotherapy services\" means services to diagnose, treat, or address mental or behavioral health through therapeutic communication (§ 1500-EE(1)(D)); \"therapeutic communication\" is defined broadly to include direct interactions to understand thoughts, emotions, or experiences, guidance and therapeutic interventions, \"offering emotional support, reassurance or empathy in response to psychological or emotional distress\", collaborative treatment planning, and behavioral feedback (§ 1500-EE(1)(C)). Exempt: an AI-based intervention used solely within a research project approved by an institutional review board as defined in 22 M.R.S. § 1711-C(6)(G) and conducted in compliance with federal human-subjects protections (§ 1500-EE(4))",
      "context": "Maine put this rule in Title 10 (commerce and trade), not in a licensing chapter, which is what gives it reach beyond Maine licensees: § 1500-EE(2) binds any \"person\" who offers therapy to the Maine public through Internet-based AI, and § 1500-EE(3) converts a violation into an Unfair Trade Practices Act violation enforced by the Attorney General. The statute never calls itself an AI law in its operative duty — it is drafted as a licensure and trade-practices rule — yet the therapeutic-communication definition at § 1500-EE(1)(C)(3), \"offering emotional support, reassurance or empathy in response to psychological or emotional distress\", describes ordinary consumer companion-chatbot behavior, not only purpose-built therapy products. Advertising and offering are covered alongside providing, so marketing an AI mental-health product into Maine is itself the violation. The IRB carve-out mirrors Rhode Island's and Vermont's, which is now the settled shape of this exemption across the three states.",
      "instrument_notes": null,
      "roles": [
        "deployer",
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislature.maine.gov/legis/bills/getPDF.asp?item=3&paper=HP1397&snum=132",
        "locator": "10 M.R.S. § 1500-EE(1), § 1500-EE(2), § 1500-EE(3), § 1500-EE(4)",
        "citation": "10 M.R.S. § 1500-EE; 32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009, 13870 (P.L. 2026 ch. 687)"
      },
      "of": {
        "term": "https://everyailaw.com/term/maine-ai-mental-health-licensed-delivery.json",
        "obligations": [
          "https://everyailaw.com/obligation/maine-ai-mental-health-licensed-delivery-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-29",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "maine-ai-mental-health-permitted-use",
      "regulation": "maine-ai-mental-health",
      "name": "Permitted Administrative and Supplementary AI Use by Licensees",
      "requirements": [
        {
          "requirement": "Closed list of permitted uses",
          "details": "A licensee may use AI only to provide administrative support or supplementary support in delivering therapy or psychotherapy services, acting within the scope of the licence, in accordance with the chapter's requirements and restrictions, and in accordance with standards of practice (§ 2113(2))"
        },
        {
          "requirement": "Full licensee responsibility",
          "details": "The licensee must maintain full responsibility for all interactions, outputs, and data use associated with the use of artificial intelligence (§ 2113(2)(A))"
        },
        {
          "requirement": "Supplementary use gated on subsection 3",
          "details": "For AI assisting in supplementary support, the licensee must satisfy the recording, written-disclosure, and consent requirements of § 2113(3) (§§ 2113(2)(B), 2113(4))"
        },
        {
          "requirement": "No independent therapeutic decisions",
          "details": "A licensee may not allow AI to make independent therapeutic decisions (§ 2113(4)(A))"
        },
        {
          "requirement": "No direct therapeutic interaction",
          "details": "A licensee may not allow AI to directly interact with clients in any form of therapeutic communication (§ 2113(4)(B))"
        },
        {
          "requirement": "No unreviewed recommendations or plans",
          "details": "A licensee may not allow AI to generate therapeutic recommendations or treatment plans without review and approval by the licensee (§ 2113(4)(C))"
        },
        {
          "requirement": "Confidentiality extends to the tool",
          "details": "The licensee must comply with all state and federal confidentiality and privacy laws and must ensure that any AI technology used is itself compliant with those laws (§ 2113(6))"
        },
        {
          "requirement": "Professional-responsibility rules follow the tool",
          "details": "All laws and rules on professional responsibility, unprofessional conduct, and generally accepted standards of practice that apply to a licensee apply equally when the licensee uses AI under this section (§ 2113(7))"
        },
        {
          "requirement": "Board rulemaking",
          "details": "The board shall adopt rules implementing the section; those rules are major substantive rules under 5 M.R.S. ch. 375, subch. 2-A, requiring legislative review before final adoption (§ 2113(10))"
        }
      ],
      "penalties": [
        {
          "violation": "Board discipline",
          "fine": "A violation of § 2113 is subject to disciplinary action by the board pursuant to 10 M.R.S. § 8003(5) (§ 2113(8)) — the standard Maine licensing-board sanction range, up to licence suspension or revocation. The act sets no dollar amounts"
        },
        {
          "violation": "Civil actions preserved",
          "fine": "Nothing in the section prohibits a client or the client's authorized representative from maintaining an action for harm attributable to the AI use, an action alleging professional negligence of the licensee, or seeking any other remedies available under other provisions of law (§ 2113(12))"
        }
      ],
      "scope": "Licensees under 32 M.R.S. ch. 17 (the section refers to them as \"the licensee\") who use AI to assist in delivering therapy or psychotherapy services. Permitted categories are closed: \"administrative support\" (scheduling and reminders, billing and insurance claims, logistics communications that contain no therapeutic communication — § 2113(1)(A)) and \"supplementary support\" (preparing and maintaining client records including therapy notes, analyzing anonymized data to track progress or identify trends subject to licensed review, and identifying and organizing external resources or referrals — § 2113(1)(D)). Neither category may involve therapeutic communication. Exempt: AI-based interventions used solely within an IRB-approved research project under 22 M.R.S. § 1711-C(6)(G) (§ 2113(9))",
      "context": "The allocation of liability is unqualified: § 2113(2)(A) makes the licensee responsible for \"all interactions, outputs and data use\" associated with the AI, with no carve-out for vendor-controlled design or algorithms — the opposite of Rhode Island's § 40.1-5.5-3(c)(2), which expressly excludes vendor-controlled system design from provider responsibility. A Maine licensee therefore cannot contract that residue away, which is what pushes the duty onto vendor selection and configuration. The prohibitions at § 2113(4) fix the human-in-the-loop boundary — no independent therapeutic decisions, no direct therapeutic interaction with clients, and no recommendation or treatment plan that has not been reviewed and approved by the licensee. P.L. 2026 ch. 687 replicates § 2113 verbatim across six further licensing chapters (32 M.R.S. §§ 2600-G, 3300-J, 3820-A, 6207-D, 7009, and 13870), so the same duty attaches to every board that licenses a mental-health profession in Maine; the rules implementing it are major substantive rules under 5 M.R.S. ch. 375, subch. 2-A, meaning they must go back to the Legislature for review before final adoption.",
      "instrument_notes": null,
      "roles": [
        "healthcare-provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislature.maine.gov/legis/bills/getPDF.asp?item=3&paper=HP1397&snum=132",
        "locator": "32 M.R.S. § 2113(1), § 2113(2), § 2113(4), § 2113(6), § 2113(7), § 2113(8), § 2113(10)",
        "citation": "10 M.R.S. § 1500-EE; 32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009, 13870 (P.L. 2026 ch. 687)"
      },
      "of": {
        "term": "https://everyailaw.com/term/maine-ai-mental-health-permitted-use.json",
        "obligations": [
          "https://everyailaw.com/obligation/maine-ai-mental-health-permitted-use-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-07-29",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "mt-ai-regulations-human-oversight",
      "regulation": "mt-ai-regulations",
      "name": "High-Risk AI Oversight and Biometric Controls",
      "requirements": [
        {
          "requirement": "Biometric authorization",
          "details": "Real-time remote biometric identification in publicly accessible spaces for law enforcement requires prior Magistrate authorisation; in duly justified urgency, authorisation must be requested without undue delay and within 24 hours. Rejection requires immediate termination and deletion of data, results and outputs (reg. 6(2), effective 2026-08-02)"
        },
        {
          "requirement": "IDPC notification",
          "details": "Each law-enforcement use of real-time remote biometric identification in publicly accessible spaces must be notified to IDPC, excluding sensitive operational data (reg. 6(4))"
        },
        {
          "requirement": "Adverse decisions",
          "details": "No decision producing an adverse legal effect on a person may be based solely on the output of the real-time remote biometric identification system (reg. 6(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Infringement of the regulations or of Regulation (EU) 2024/1689 by an operator (reg. 13(1))",
          "fine": "Administrative penalties, warnings and non-monetary measures imposed by the Commissioner; amounts follow Chapter XII of Regulation (EU) 2024/1689 — LN 227 states no separate operator scale"
        },
        {
          "violation": "Infringement by a public authority or body (reg. 13(3))",
          "fine": "Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists"
        }
      ],
      "scope": "Law-enforcement authorities using real-time remote biometric identification in publicly accessible spaces in Malta, within LN 227 reg. 6 and its Article 5 safeguards",
      "context": "The requirements below concern law-enforcement use of real-time remote biometric identification in publicly accessible spaces, with the statutory urgency exception. Institutional context: IDPC supervises the reg. 3 high-risk systems and prohibited practices, establishes the reg. 11 registry, and exercises corrective powers. These institutional functions are not duties assigned to deployers. The Effective date describes the core biometric controls; earlier administrative and penalty provisions retain their own commencement under reg. 1(3).\n\nPenalties qualification: Article 20 of the Data Protection Act applies mutatis mutandis to Commissioner decisions; appeals lie to the Information and Data Protection Appeals Tribunal.",
      "instrument_notes": "Staggered commencement: the instrument effective date retains the initial 2025-10-10 commencement. LN 226/2025 reg. 1(3) defers regs. 4, 5, 6, 8, 9 and 10 to 2026-08-02; LN 227/2025 reg. 1(3) defers regs. 5 to 7 and 9 to 12 to that date. Provision dates describe the core registration, information and biometric duties, not every earlier administrative designation, notified-body or penalty provision grouped with them. Category and actor qualification: LN 226 creates no general Maltese risk-assessment duty; its grouped source Term is retained without an asserted obligation category or common role. Operator requirements are provider/authorised-representative registration for Annex III point 2 systems and importer information on reasoned request. MDIA market-surveillance/notifying-authority/sandbox functions and National Accreditation Board assessment/monitoring are institutional context, not provider duties. Under LN 227, IDPC supervision, its registry and corrective powers are institutional functions; the retained operator requirements concern law-enforcement real-time remote biometric use, with the statutory 24-hour urgency exception.",
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.mt/eli/ln/2025/227/eng",
        "locator": "S.L. 586.14 (LN 227/2025) under the Data Protection Act (Cap. 586) — reg. 3 (IDPC designation for listed high-risk AI systems), reg. 6 (real-time remote biometric ID), reg. 7 (post-remote biometric ID; Magistrate authorisation, 48-hour rule), reg. 8 (IDPC as notified body), reg. 11 (registry for reg. 3 systems)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/mt-ai-regulations-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/mt-ai-regulations-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-08-02",
        "verified": "2026-09-08",
        "checked": "2026-09-08",
        "instrument_last_verified": "2026-09-08",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "mt-ai-regulations-risk-assessment",
      "regulation": "mt-ai-regulations",
      "name": "AI System Classification and Market Surveillance",
      "requirements": [
        {
          "requirement": "Annex III point 2 registration",
          "details": "The provider or, where applicable, the authorised representative must register high-risk AI systems referred to in point 2 of Annex III of Regulation (EU) 2024/1689 with MDIA, in the manner MDIA prescribes by guidelines or other binding documentation (reg. 8)"
        },
        {
          "requirement": "Importer information",
          "details": "On a reasoned request, importers must supply national competent authorities with the information and documentation referred to in Article 23(5), in Maltese or English, to demonstrate conformity with Section 2 of Regulation (EU) 2024/1689 (reg. 6)"
        }
      ],
      "penalties": [
        {
          "violation": "Infringement of the regulations or of Regulation (EU) 2024/1689 (reg. 11(1))",
          "fine": "Up to €350,000 per infringement or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher"
        },
        {
          "violation": "Continuing infringement (reg. 11(2))",
          "fine": "A daily penalty of €12,000 for each day the infringement persists, instead of or in addition to the reg. 11(1) penalty"
        },
        {
          "violation": "Infringement by a public authority or body (reg. 11(5))",
          "fine": "Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists"
        }
      ],
      "scope": "Providers, or where applicable their authorised representatives, placing high-risk AI systems referred to in point 2 of Annex III on the Maltese market; importers of high-risk AI systems on reasoned request from national competent authorities",
      "context": "LN 226/2025 adds no Maltese classification or general risk-assessment duty: classification follows Article 6 and Annex III of Regulation (EU) 2024/1689. The two operator requirements below retain their own named actors; this grouped section has no common role or asserted obligation-category mapping. Institutional context: MDIA is market-surveillance authority and single point of contact (reg. 3), coordinates with the specified sectoral authorities, and is Notifying Authority; the National Accreditation Board performs the Article 28(1) assessment and monitoring (reg. 7). MDIA establishes and runs the national regulatory sandbox (reg. 9); participation is a facility, not an operator duty. Registration, importer-information and sandbox provisions commence on 2026-08-02; the earlier institutional designations and penalty provisions are not deferred by the grouped Effective date.\n\nPenalties qualification: Imposed by MDIA and without prejudice to the Chapter XII penalties of Regulation (EU) 2024/1689. Appeals lie under Part IX of the MDIA Act.",
      "instrument_notes": "Staggered commencement: the instrument effective date retains the initial 2025-10-10 commencement. LN 226/2025 reg. 1(3) defers regs. 4, 5, 6, 8, 9 and 10 to 2026-08-02; LN 227/2025 reg. 1(3) defers regs. 5 to 7 and 9 to 12 to that date. Provision dates describe the core registration, information and biometric duties, not every earlier administrative designation, notified-body or penalty provision grouped with them. Category and actor qualification: LN 226 creates no general Maltese risk-assessment duty; its grouped source Term is retained without an asserted obligation category or common role. Operator requirements are provider/authorised-representative registration for Annex III point 2 systems and importer information on reasoned request. MDIA market-surveillance/notifying-authority/sandbox functions and National Accreditation Board assessment/monitoring are institutional context, not provider duties. Under LN 227, IDPC supervision, its registry and corrective powers are institutional functions; the retained operator requirements concern law-enforcement real-time remote biometric use, with the statutory 24-hour urgency exception.",
      "roles": [],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.mt/eli/ln/2025/226/eng",
        "locator": "S.L. 591.05 (LN 226/2025) under the Malta Digital Innovation Authority Act (Cap. 591) — reg. 3 (MDIA as market surveillance authority and national single point of contact), reg. 6 (importer information on reasoned request), reg. 7 (MDIA as Notifying Authority; National Accreditation Board carries out Article 28(1) assessment), reg. 8 (Annex III point 2 registration), reg. 9 (national AI regulatory sandbox), reg. 11 (administrative penalties)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/mt-ai-regulations-risk-assessment.json",
        "obligations": []
      },
      "dates": {
        "recorded_effective": "2026-08-02",
        "verified": "2026-09-08",
        "checked": "2026-09-08",
        "instrument_last_verified": "2026-09-08",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "mx-lfpdppp-human-oversight",
      "regulation": "mx-lfpdppp",
      "name": "Human Oversight in Automated Decisions",
      "requirements": [
        {
          "requirement": "Right to object to ADM",
          "details": "Art. 26(II) gives the data subject a right, at any time and for legitimate cause, to oppose or demand cessation of processing where the data is subject to automated processing producing unwanted legal effects or significantly affecting their interests, rights, or freedoms"
        },
        {
          "requirement": "Evaluation without human intervention",
          "details": "The right is triggered where the processing is intended to evaluate personal aspects without human intervention, in particular professional performance, economic situation, health, sexual preferences, reliability, or behaviour"
        },
        {
          "requirement": "Effect of a valid objection",
          "details": "Where the objection succeeds, the controller must cease the processing; the law places the remedy with the data subject rather than imposing a standing oversight duty on the controller"
        }
      ],
      "penalties": [
        {
          "violation": "Standard violations",
          "fine": "100–160,000 UMA (Art. 59(II))"
        },
        {
          "violation": "Serious violations",
          "fine": "200–320,000 UMA (Art. 59(III))"
        },
        {
          "violation": "Repeated infractions",
          "fine": "Additional fine of 100–320,000 UMA (Art. 59(IV))"
        },
        {
          "violation": "Sensitive personal data",
          "fine": "Administrative sanctions may increase up to twice the established amounts (Art. 59(IV))"
        }
      ],
      "scope": "Controllers processing personal data through solely automated evaluation that produces unwanted legal effects or significantly affects a data subject's interests, rights, or freedoms (Art. 26(II))",
      "context": "The statute provides a right to object, not a duty of oversight. Art. 26(II) lets a data subject oppose processing where their data undergoes automated processing that produces unwanted legal effects or significantly affects their interests, rights, or freedoms, and is intended to evaluate personal aspects — professional performance, economic situation, health, sexual preferences, reliability, or behaviour — without human intervention. The text imposes no human-in-the-loop requirement, no impact assessment, and no safeguards specific to agentic systems; those duties are not confirmed by the retained source, and no implementing regulation establishing them is bound here.",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
        "locator": "Article 26(II)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/mx-lfpdppp-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/mx-lfpdppp-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-03-21",
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "mx-lfpdppp-transparency",
      "regulation": "mx-lfpdppp",
      "name": "Algorithmic Transparency and Disclosure",
      "requirements": [
        {
          "requirement": "Privacy notice contents",
          "details": "Art. 15 requires the notice to state the controller's identity and address, the data processed and which of it is sensitive, the purposes and which require consent, the means offered to limit use or disclosure, the mechanisms for exercising ARCO rights, and how changes to the notice will be communicated"
        },
        {
          "requirement": "Automated processing in scope",
          "details": "Art. 2 Fraction XIX brings processing carried out by automated procedures within \"tratamiento\", so AI-based processing of personal data is covered by the notice duties"
        },
        {
          "requirement": "Delivery of the notice",
          "details": "Arts. 16-17 govern how and when the privacy notice must be made available, including where data is not obtained directly from the data subject"
        }
      ],
      "penalties": [
        {
          "violation": "Standard violations",
          "fine": "100–160,000 UMA (Art. 59(II))"
        },
        {
          "violation": "Serious violations",
          "fine": "200–320,000 UMA (Art. 59(III))"
        },
        {
          "violation": "Repeated infractions",
          "fine": "Additional fine of 100–320,000 UMA (Art. 59(IV))"
        },
        {
          "violation": "Sensitive personal data",
          "fine": "Administrative sanctions may increase up to twice the established amounts (Art. 59(IV))"
        }
      ],
      "scope": "deployers, providers",
      "context": "The statute reaches AI only indirectly. Art. 2 Fraction XIX defines \"tratamiento\" to include operations carried out by automated procedures, so processing personal data with AI is covered, and the Art. 14-17 privacy-notice duties apply. The consolidated text (Última Reforma DOF 14-11-2025) contains no occurrence of \"inteligencia artificial\" or \"algoritmo\", and Art. 15 does not require disclosure of algorithmic logic, significance, or consequences. No secondary regulation is bound here to establish any additional duty; such a duty remains unconfirmed.",
      "instrument_notes": null,
      "roles": [
        "deployer",
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
        "locator": "Articles 14-17 (privacy notice); Article 2 Fraction XIX",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/mx-lfpdppp-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/mx-lfpdppp-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-03-21",
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nebraska-lb525-crisis-protocol",
      "regulation": "nebraska-lb525",
      "name": "Suicide and Self-Harm Response Protocol",
      "requirements": [
        {
          "requirement": "Adopt a crisis protocol",
          "details": "Adopt a protocol for the conversational AI service to respond to user prompts regarding suicidal ideation or self-harm (sec. 16)"
        },
        {
          "requirement": "Crisis referral",
          "details": "The protocol must include making reasonable efforts to provide a response referring the user to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis services (sec. 16)"
        },
        {
          "requirement": "Non-exhaustive floor",
          "details": "The enumerated referral content is a minimum — the protocol \"includes, but is not limited to\" that element (sec. 16)"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General enforcement",
          "fine": "The Attorney General may enforce the act and may bring a civil action for appropriate relief against an operator, on behalf of the State of Nebraska or on behalf of any person aggrieved by a violation (sec. 18(1), sec. 18(2)(a))"
        },
        {
          "violation": "Relief available",
          "fine": "Preliminary and other equitable or declaratory relief; an award of actual damages; reasonable expenses of bringing the action including court costs, reasonable attorney's fees, investigative costs, witness fees, and deposition costs (sec. 18(2)(b)(i), (ii), (iv))"
        },
        {
          "violation": "Civil penalties",
          "fine": "At least $1,000 per violation, but no more than $500,000 per operator; penalties recovered are remitted to the State Treasurer under Article VII, section 5 of the Nebraska Constitution (sec. 18(2)(b)(iii))"
        },
        {
          "violation": "Private right of action",
          "fine": "None — nothing in the act shall be interpreted as creating a private right of action (sec. 18(3))"
        },
        {
          "violation": "Developer carve-out",
          "fine": "The act creates no liability for the developer of an AI model for a violation by a conversational AI system developed by a third-party operator to provide a service for that developer (sec. 18(4))"
        }
      ],
      "scope": "Operators of conversational AI services (sec. 13(6)(a)), as to all users regardless of age or account status (sec. 16)",
      "context": "Nebraska states the crisis duty in a single sentence and, unlike Washington, does not gate deployment on having the protocol, name eating disorders, or require any public disclosure of referral counts — the duty is to adopt a protocol and make reasonable efforts to refer. The \"includes, but is not limited to\" framing leaves the floor open, which means the Attorney General, not the statute, will set the practical content of an adequate protocol.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
        "locator": "2026 Neb. Laws LB 525, sec. 16",
        "citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)"
      },
      "of": {
        "term": "https://everyailaw.com/term/nebraska-lb525-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/nebraska-lb525-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nebraska-lb525-general-disclosure",
      "regulation": "nebraska-lb525",
      "name": "General Artificiality Disclosure and Mental Health Representation Bar",
      "requirements": [
        {
          "requirement": "Conditional artificiality disclosure",
          "details": "If a reasonable person interacting with the service would be misled to believe they are interacting with a human, clearly and conspicuously disclose that the service is artificial intelligence (sec. 15)"
        },
        {
          "requirement": "No professional mental health claims",
          "details": "Do not knowingly and intentionally cause or program the service to make any representation or statement that explicitly indicates the service is designed to provide professional mental or behavioral health care (sec. 17)"
        },
        {
          "requirement": "Scienter standard",
          "details": "The sec. 17 bar reaches only conduct that is both knowing and intentional on the part of the operator (sec. 17)"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General enforcement",
          "fine": "The Attorney General may enforce the act and may bring a civil action for appropriate relief against an operator, on behalf of the State of Nebraska or on behalf of any person aggrieved by a violation (sec. 18(1), sec. 18(2)(a))"
        },
        {
          "violation": "Relief available",
          "fine": "Preliminary and other equitable or declaratory relief; an award of actual damages; reasonable expenses of bringing the action including court costs, reasonable attorney's fees, investigative costs, witness fees, and deposition costs (sec. 18(2)(b)(i), (ii), (iv))"
        },
        {
          "violation": "Civil penalties",
          "fine": "At least $1,000 per violation, but no more than $500,000 per operator; penalties recovered are remitted to the State Treasurer under Article VII, section 5 of the Nebraska Constitution (sec. 18(2)(b)(iii))"
        },
        {
          "violation": "Private right of action",
          "fine": "None — nothing in the act shall be interpreted as creating a private right of action (sec. 18(3))"
        },
        {
          "violation": "Developer carve-out",
          "fine": "The act creates no liability for the developer of an AI model for a violation by a conversational AI system developed by a third-party operator to provide a service for that developer (sec. 18(4))"
        }
      ],
      "scope": "Operators of conversational AI services (sec. 13(6)(a)) as to all users, not only account holders. The disclosure duty is conditional: it applies where a reasonable person interacting with the service would be misled to believe the interaction is with a human (sec. 15)",
      "context": "Unlike Washington's unconditional disclosure, Nebraska's general duty triggers only on the reasonable-person misleading test, so a service that is obviously artificial owes nothing under sec. 15 — the account-based minor duty in sec. 14(1) is the unconditional one. Sec. 17 bars only the explicit representation that the service is designed to deliver professional mental or behavioral health care, and it carries a knowing-and-intentional scienter element, so incidental therapeutic-sounding output is not itself a violation.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
        "locator": "2026 Neb. Laws LB 525, sec. 15, sec. 17",
        "citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)"
      },
      "of": {
        "term": "https://everyailaw.com/term/nebraska-lb525-general-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/nebraska-lb525-general-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nebraska-lb525-minor-disclosure",
      "regulation": "nebraska-lb525",
      "name": "Minor Account Holder Artificiality Disclosure",
      "requirements": [
        {
          "requirement": "Disclose artificiality to minor account holders",
          "details": "Clearly and conspicuously disclose to each minor account holder that they are interacting with artificial intelligence (sec. 14(1))"
        },
        {
          "requirement": "Persistent-disclaimer route",
          "details": "The disclosure may be satisfied by a persistent visible disclaimer (sec. 14(1)(a))"
        },
        {
          "requirement": "Session-and-cadence route",
          "details": "Alternatively, disclose at the beginning of each session and at least every three hours in a continuous interaction (sec. 14(1)(b)(i)-(ii))"
        },
        {
          "requirement": "Minor determination standard",
          "details": "A minor is an individual the operator has, based upon the circumstance, actual knowledge or reasonable certainty is younger than eighteen (sec. 13(4))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General enforcement",
          "fine": "The Attorney General may enforce the act and may bring a civil action for appropriate relief against an operator, on behalf of the State of Nebraska or on behalf of any person aggrieved by a violation (sec. 18(1), sec. 18(2)(a))"
        },
        {
          "violation": "Relief available",
          "fine": "Preliminary and other equitable or declaratory relief; an award of actual damages; reasonable expenses of bringing the action including court costs, reasonable attorney's fees, investigative costs, witness fees, and deposition costs (sec. 18(2)(b)(i), (ii), (iv))"
        },
        {
          "violation": "Civil penalties",
          "fine": "At least $1,000 per violation, but no more than $500,000 per operator; penalties recovered are remitted to the State Treasurer under Article VII, section 5 of the Nebraska Constitution (sec. 18(2)(b)(iii))"
        },
        {
          "violation": "Private right of action",
          "fine": "None — nothing in the act shall be interpreted as creating a private right of action (sec. 18(3))"
        },
        {
          "violation": "Developer carve-out",
          "fine": "The act creates no liability for the developer of an AI model for a violation by a conversational AI system developed by a third-party operator to provide a service for that developer (sec. 18(4))"
        }
      ],
      "scope": "Operators — any natural person or legal entity that makes available a conversational artificial intelligence service to the public (sec. 13(6)(a)). A conversational AI service is a publicly accessible software application, web interface, or program that primarily simulates human conversation through textual, visual, or aural communication (sec. 13(2)(a)); excluded are developer- and researcher-facing tools, features inside a non-conversational product, narrow-and-discrete-topic outputs, business-facing commercial products, speaker and voice-assistant interfaces, internal business use, and pure customer-service bots (sec. 13(2)(b)(i)-(vii)). Mobile app stores and search engines are not operators merely for providing access (sec. 13(6)(b)). The duty runs to minor account holders — account holders the operator has actual knowledge or reasonable certainty are under 18 (sec. 13(4)-(5))",
      "context": "The act is not yet codified into numbered Neb. Rev. Stat. sections on the face of the slip law, so provisions here are cited to the session-law section numbers of LB 525. Two design choices separate Nebraska from the other 2026 state chatbot statutes: a persistent visible disclaimer is an accepted substitute for the three-hour reminder cadence, which Washington's ESHB 2225 does not allow, and the duty attaches to minor *account holders* rather than to any minor user, so an operator that runs no accounts never triggers it.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
        "locator": "2026 Neb. Laws LB 525, sec. 13(1)-(6), sec. 14(1)",
        "citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)"
      },
      "of": {
        "term": "https://everyailaw.com/term/nebraska-lb525-minor-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/nebraska-lb525-minor-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nebraska-lb525-minor-safeguards",
      "regulation": "nebraska-lb525",
      "name": "Minor Engagement, Sexual Content, and Anthropomorphism Safeguards",
      "requirements": [
        {
          "requirement": "No variable-ratio engagement rewards",
          "details": "Do not provide a minor account holder with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the service (sec. 14(2))"
        },
        {
          "requirement": "Prevent sexually explicit output",
          "details": "Institute reasonable measures to prevent the service from producing visual depictions of sexually explicit conduct, generating direct statements that the account holder should engage in sexually explicit conduct, or generating statements that sexually objectify the account holder (sec. 14(3)(a)-(c))"
        },
        {
          "requirement": "Prevent human-simulation output",
          "details": "Institute reasonable measures to prevent the service from generating statements that would lead a reasonable person to believe they are interacting with a human (sec. 14(4))"
        },
        {
          "requirement": "Enumerated anthropomorphic outputs",
          "details": "The prevention duty expressly covers explicit claims that the service is sentient or human, statements simulating emotional dependence, statements simulating romantic or sexual innuendos, and role-playing of adult-minor romantic relationships (sec. 14(4)(a)-(d))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General enforcement",
          "fine": "The Attorney General may enforce the act and may bring a civil action for appropriate relief against an operator, on behalf of the State of Nebraska or on behalf of any person aggrieved by a violation (sec. 18(1), sec. 18(2)(a))"
        },
        {
          "violation": "Relief available",
          "fine": "Preliminary and other equitable or declaratory relief; an award of actual damages; reasonable expenses of bringing the action including court costs, reasonable attorney's fees, investigative costs, witness fees, and deposition costs (sec. 18(2)(b)(i), (ii), (iv))"
        },
        {
          "violation": "Civil penalties",
          "fine": "At least $1,000 per violation, but no more than $500,000 per operator; penalties recovered are remitted to the State Treasurer under Article VII, section 5 of the Nebraska Constitution (sec. 18(2)(b)(iii))"
        },
        {
          "violation": "Private right of action",
          "fine": "None — nothing in the act shall be interpreted as creating a private right of action (sec. 18(3))"
        },
        {
          "violation": "Developer carve-out",
          "fine": "The act creates no liability for the developer of an AI model for a violation by a conversational AI system developed by a third-party operator to provide a service for that developer (sec. 18(4))"
        }
      ],
      "scope": "Operators of conversational AI services (sec. 13(6)(a)) with respect to minor account holders (sec. 13(5)). \"Sexually explicit conduct\" and \"visual depiction\" carry their 18 U.S.C. 2256 meanings (sec. 13(8))",
      "context": "Nebraska's engagement ban is narrower than Washington's eight-technique list: it reaches only variable-ratio rewards — points or similar rewards at unpredictable intervals with intent to increase engagement — leaving other retention mechanics untouched. The anthropomorphism duty is unusual in naming simulated emotional dependence and adult-minor romantic role-play as specific outputs the operator must take reasonable measures to prevent.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
        "locator": "2026 Neb. Laws LB 525, sec. 13(8), sec. 14(2), sec. 14(3), sec. 14(4)",
        "citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)"
      },
      "of": {
        "term": "https://everyailaw.com/term/nebraska-lb525-minor-safeguards.json",
        "obligations": [
          "https://everyailaw.com/obligation/nebraska-lb525-minor-safeguards-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nebraska-lb525-parental-controls",
      "regulation": "nebraska-lb525",
      "name": "Minor Privacy and Parental Control Tools",
      "requirements": [
        {
          "requirement": "Tools for minor account holders",
          "details": "Offer tools for minor account holders to manage their privacy and account settings (sec. 14(5))"
        },
        {
          "requirement": "Parental tools under thirteen",
          "details": "Where the minor account holder is younger than thirteen, offer those same management tools to the account holder's parents or guardians (sec. 14(5))"
        },
        {
          "requirement": "Related tools for thirteen and older",
          "details": "Offer related tools to the parents or guardians of minor account holders thirteen years of age and older, as appropriate based on relevant risks (sec. 14(5))"
        }
      ],
      "penalties": [
        {
          "violation": "Attorney General enforcement",
          "fine": "The Attorney General may enforce the act and may bring a civil action for appropriate relief against an operator, on behalf of the State of Nebraska or on behalf of any person aggrieved by a violation (sec. 18(1), sec. 18(2)(a))"
        },
        {
          "violation": "Relief available",
          "fine": "Preliminary and other equitable or declaratory relief; an award of actual damages; reasonable expenses of bringing the action including court costs, reasonable attorney's fees, investigative costs, witness fees, and deposition costs (sec. 18(2)(b)(i), (ii), (iv))"
        },
        {
          "violation": "Civil penalties",
          "fine": "At least $1,000 per violation, but no more than $500,000 per operator; penalties recovered are remitted to the State Treasurer under Article VII, section 5 of the Nebraska Constitution (sec. 18(2)(b)(iii))"
        },
        {
          "violation": "Private right of action",
          "fine": "None — nothing in the act shall be interpreted as creating a private right of action (sec. 18(3))"
        },
        {
          "violation": "Developer carve-out",
          "fine": "The act creates no liability for the developer of an AI model for a violation by a conversational AI system developed by a third-party operator to provide a service for that developer (sec. 18(4))"
        }
      ],
      "scope": "Operators of conversational AI services (sec. 13(6)(a)) with respect to minor account holders — account holders who have or open an account or profile to use the service and whom the operator has actual knowledge or reasonable certainty are under 18 (sec. 13(1), sec. 13(4)-(5)) — and their parents or guardians",
      "context": "Nebraska is the only one of the 2026 state chatbot statutes to impose an affirmative account-controls duty, and it splits at age thirteen: parents of under-13 account holders get the tools as of right, while parents of 13-and-older account holders get \"related tools\" only \"as appropriate based on relevant risks\" — a risk-calibrated standard the act leaves to the operator to apply.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf",
        "locator": "2026 Neb. Laws LB 525, sec. 13(1), sec. 13(5), sec. 14(5)",
        "citation": "Neb. Rev. Stat. Conversational Artificial Intelligence Safety Act (2026 Neb. Laws LB 525, secs. 12 to 19)"
      },
      "of": {
        "term": "https://everyailaw.com/term/nebraska-lb525-parental-controls.json",
        "obligations": [
          "https://everyailaw.com/obligation/nebraska-lb525-parental-controls-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-03",
        "checked": "2026-08-03",
        "instrument_last_verified": "2026-08-03",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "new-york-ai-companion-notification",
      "regulation": "new-york-ai-companion-models",
      "name": "AI Companion Non-Human Notification",
      "requirements": [
        {
          "requirement": "Opening notification",
          "details": "Provide a clear and conspicuous notification at the beginning of any AI companion interaction stating, verbally or in writing, that the user is not communicating with a human (§ 1702)"
        },
        {
          "requirement": "Three-hour cadence",
          "details": "Repeat the notification at least every three hours during continuing AI companion interactions (§ 1702)"
        },
        {
          "requirement": "Daily floor",
          "details": "The notification need not be given more than once per day (§ 1702)"
        }
      ],
      "penalties": [
        {
          "violation": "Per day",
          "fine": "Civil penalties up to $15,000 per day for a violation of § 1701 or § 1702 (§ 1703(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "Attorney General action for injunctive relief, civil penalties, and other remedies (§ 1703(1))"
        }
      ],
      "scope": "Operators of AI companions provided to users in New York (§ 1700(4)-(5))",
      "context": "The cadence rule cuts both ways: the notice need not appear more than once per day, but must appear at least every three hours within a continuing interaction. New York and California both settled on a three-hour interval, though New York applies it to all users while California's applies only to users known to be minors.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://assembly.state.ny.us/leg/?Actions=Y&Memo=Y&Summary=Y&Text=Y&Votes=Y&bn=S03008&term=2025",
        "locator": "N.Y. Gen. Bus. Law § 1702",
        "citation": "N.Y. Gen. Bus. Law §§ 1700-1704 (L. 2025, ch. 56, part U)"
      },
      "of": {
        "term": "https://everyailaw.com/term/new-york-ai-companion-notification.json",
        "obligations": [
          "https://everyailaw.com/obligation/new-york-ai-companion-notification-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-11-05",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "new-york-ai-companion-protocol",
      "regulation": "new-york-ai-companion-models",
      "name": "AI Companion Self-Harm Protocol",
      "requirements": [
        {
          "requirement": "Protocol required to operate",
          "details": "It is unlawful to operate for or provide an AI companion unless it contains a protocol taking reasonable efforts to detect and address suicidal ideation or expressions of self-harm expressed by a user (§ 1701)"
        },
        {
          "requirement": "Detection",
          "details": "The protocol must include detection of user expressions of suicidal ideation or self-harm (§ 1701)"
        },
        {
          "requirement": "Crisis referral",
          "details": "On detection, the operator must notify the user with a referral to crisis service providers such as the 9-8-8 suicide prevention and behavioral health crisis hotline under Mental Hygiene Law § 36.03, a crisis text line, or other appropriate crisis services (§ 1701)"
        }
      ],
      "penalties": [
        {
          "violation": "Per day",
          "fine": "Civil penalties up to $15,000 per day for a violation of § 1701 or § 1702 (§ 1703(1))"
        },
        {
          "violation": "Enforcement",
          "fine": "The Attorney General may sue in the name of the people to enjoin the unlawful practice and seek civil penalties and other remedies the court deems appropriate (§ 1703(1))"
        },
        {
          "violation": "Destination of penalties",
          "fine": "Fees, fines, and penalties are deposited in the suicide prevention fund established by State Finance Law § 99-ss and made available to the Office of Mental Health (§ 1703(2))"
        }
      ],
      "scope": "Operators — any person, partnership, association, firm, or business entity (including members, affiliates, subsidiaries, and beneficial owners) that operates for or provides an AI companion to a user in New York. An AI companion is a system using AI, generative AI, and/or emotional recognition algorithms designed to simulate a sustained human-like relationship by retaining prior-session information, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user; systems used solely for customer service, efficiency or research assistance, or internal employee productivity are excluded (§ 1700(4))",
      "context": "Structured as a prohibition on operating without the protocol, so the compliance question is binary rather than a standard of care. The three-part definition of an AI companion in § 1700(4)(a) is conjunctive — memory across sessions, unprompted emotion-based questions, and sustained personal dialogue — which is narrower than California's SB 243 test and turns on product design rather than on marketing category.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://assembly.state.ny.us/leg/?Actions=Y&Memo=Y&Summary=Y&Text=Y&Votes=Y&bn=S03008&term=2025",
        "locator": "N.Y. Gen. Bus. Law §§ 1700, 1701",
        "citation": "N.Y. Gen. Bus. Law §§ 1700-1704 (L. 2025, ch. 56, part U)"
      },
      "of": {
        "term": "https://everyailaw.com/term/new-york-ai-companion-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/new-york-ai-companion-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-11-05",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "new-york-raise-disclosure",
      "regulation": "new-york-raise",
      "name": "Large Frontier Developer Disclosure",
      "requirements": [
        {
          "requirement": "Current filing and assessment",
          "details": "A covered large frontier developer may not develop, deploy or operate a frontier model wholly or partly in New York without a current disclosure statement filed with the DFS Office and payment of its required pro rata share of the department's Article 44-B operating expenses (§ 1428(1), (4))"
        },
        {
          "requirement": "Renewal events",
          "details": "File in the form and manner prescribed by the Office and renew every two years, upon transfer of frontier-model ownership, or upon a material change to previously reported information, whichever occurs first (§ 1428(2))"
        },
        {
          "requirement": "Business identity and offices",
          "details": "Identify the developer, every name under which it does business, its principal place of business and each New York office (§ 1428(3)(a)-(b))"
        },
        {
          "requirement": "Conditional beneficial-owner history",
          "details": "If the developer or ultimate parent is private or closely held, list current persons or entities with at least a 5% beneficial interest and persons who formerly held at least a 5% beneficial interest in the owner or its predecessors during the preceding five years. If the owner or ultimate parent is publicly traded, list current persons or entities with at least a 50% beneficial interest (§ 1428(3)(c))"
        },
        {
          "requirement": "Government contacts",
          "details": "Identify primary, secondary and tertiary contacts; the primary contact receives Article 44-B inquiries from the Office or other governmental entities (§ 1428(3)(d))"
        },
        {
          "requirement": "Public filer list boundary",
          "details": "The Office must publish a list of large frontier developers that filed disclosure statements, excluding their contact information. Section 1428(6) does not state that the disclosure statements themselves are public"
        }
      ],
      "penalties": [
        {
          "violation": "No current disclosure or uncorrected false information (§ 1428(5))",
          "fine": "After notice and hearing, the Office may levy $1,000 for each day the entity fails to file the required disclosure or correct false information"
        },
        {
          "violation": "Unpaid assessment (§ 1428(5))",
          "fine": "After notice and hearing, the Office may levy an amount equal to the assessments owed, in addition to other applicable penalties or liability"
        }
      ],
      "scope": "Large frontier developers that develop, deploy or operate a frontier model wholly or partly in New York (§§ 1425, 1428(1)). The § 1426 academic-research and Empire AI/institute exceptions apply",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://legislation.nysenate.gov/pdf/bills/2025/s8828",
        "locator": "N.Y. General Business Law § 1420(8)-(10), (12), (16); § 1425; § 1426; § 1428",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/new-york-raise-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/new-york-raise-disclosure-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-09-29",
        "checked": "2026-09-29",
        "instrument_last_verified": "2026-09-29",
        "instrument_amendments": [
          {
            "date": "2026-03-27",
            "description": "Chapter 96 (S8828) repeals and replaces Article 44-B; distinguishes frontier and large frontier developers, revises transparency/reporting, and sets January 1, 2027 commencement"
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "new-york-raise-incident-reporting",
      "regulation": "new-york-raise",
      "name": "Incident Reporting",
      "requirements": [
        {
          "requirement": "72-hour reporting",
          "details": "Report critical safety incidents to the DFS Office within 72 hours of determining an incident occurred or learning facts sufficient for a reasonable belief it occurred (§ 1422(3)(a))"
        },
        {
          "requirement": "24-hour imminent risk reporting",
          "details": "If a discovered critical safety incident poses imminent risk of death or serious physical injury, disclose within 24 hours to an appropriate authority with jurisdiction, including law-enforcement/public-safety agencies, based on the incident and as required by law (§ 1422(3)(b))"
        },
        {
          "requirement": "DFS Office channel",
          "details": "The office is within DFS and reports to its superintendent (§ 1420(12),(16)); the ordinary 72-hour channel is that office, while § 1422(3)(b) specifies the urgent 24-hour appropriate-authority channel"
        },
        {
          "requirement": "Internal-use summaries for LFDs",
          "details": "Confidential internal-use catastrophic-risk assessment summaries to DFS every three months or on another reasonable agreed schedule (§ 1422(2)); not a public quarterly incident-summary mandate"
        },
        {
          "requirement": "Amended reports",
          "details": "May file an amended report when further information is discovered after the initial report (§ 1422(3)(c))"
        },
        {
          "requirement": "Designated federal alternative",
          "details": "Deemed compliance with § 1422(3) requires a qualifying federal regime designated by Office regulation, declaration of intent, actual compliance, and concurrent copies of federal reports to the Office (§ 1422(8)-(10)); no general federal-reporting exemption"
        }
      ],
      "penalties": [
        {
          "violation": "Specified large-frontier-developer violations (§ 1427(1))",
          "fine": "AG may seek up to $1M first / $3M subsequent, based on severity; no private action under § 1427(2)"
        }
      ],
      "scope": "Frontier developers with a § 1420(4) critical safety incident involving their frontier models; models developed, deployed or operating wholly or partly in New York (§ 1425). Large developers additionally transmit internal-use assessment summaries. Definitions in § 1420(8)-(10) and academic/Empire AI exceptions in § 1426 apply",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://nysenate.gov/legislation/laws/GBS/1420",
        "locator": "N.Y. General Business Law § 1420(4), (12), (16); § 1422; § 1425; § 1426; § 1427",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/new-york-raise-incident-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/new-york-raise-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-09-29",
        "checked": "2026-09-29",
        "instrument_last_verified": "2026-09-29",
        "instrument_amendments": [
          {
            "date": "2026-03-27",
            "description": "Chapter 96 (S8828) repeals and replaces Article 44-B; distinguishes frontier and large frontier developers, revises transparency/reporting, and sets January 1, 2027 commencement"
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "new-york-raise-safety",
      "regulation": "new-york-raise",
      "name": "Safety Protocols",
      "requirements": [
        {
          "requirement": "Internal governance",
          "details": "Large frontier developer framework must describe internal governance practices ensuring implementation (§ 1421(1)(i)); the reviewed amended Article 44-B does not require a designated senior AI safety officer"
        },
        {
          "requirement": "Safety framework publication",
          "details": "Large frontier developers must write, implement, comply with and conspicuously publish a frontier AI framework addressing § 1421(1)(a)-(j)"
        },
        {
          "requirement": "Internal-use risk summaries",
          "details": "Large frontier developers must confidentially transmit internal-use catastrophic-risk assessment summaries to the DFS Office every three months or on another reasonable requested schedule agreed by the Office (§ 1422(2))"
        },
        {
          "requirement": "Annual update",
          "details": "Large frontier developers must review and update as appropriate at least annually; publish material modifications and justification within 30 days (§ 1421(2))"
        },
        {
          "requirement": "Assessment and deployment transparency",
          "details": "Large frontier framework must describe assessments, mitigations and review in deployment/extensive-internal-use decisions (§ 1421(1)(b)-(e)); all frontier developers publish a transparency report before or concurrently with deployment, with assessment/results/third-party-evaluator summaries for large developers (§ 1421(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Specified large-frontier-developer violations (§ 1427(1))",
          "fine": "AG may seek up to $1M first / $3M subsequent, based on severity; no private action under § 1427(2)"
        }
      ],
      "scope": "Large frontier developers for framework/assessment duties; all frontier developers for deployment transparency reports. Frontier models exceed 10^26 training operations including subsequent fine-tuning/reinforcement/material modifications; large developers exceed $500M prior-year gross revenue with affiliates (§ 1420(8)-(10)). Models must be developed, deployed or operating wholly or partly in New York (§ 1425); § 1426 academic-research and Empire AI/institute exceptions apply",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://nysenate.gov/legislation/laws/GBS/1420",
        "locator": "N.Y. General Business Law § 1420; § 1421; § 1422(2); § 1425; § 1426; § 1427",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/new-york-raise-safety.json",
        "obligations": [
          "https://everyailaw.com/obligation/new-york-raise-safety-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-09-29",
        "checked": "2026-09-29",
        "instrument_last_verified": "2026-09-29",
        "instrument_amendments": [
          {
            "date": "2026-03-27",
            "description": "Chapter 96 (S8828) repeals and replaces Article 44-B; distinguishes frontier and large frontier developers, revises transparency/reporting, and sets January 1, 2027 commencement"
          }
        ],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nist-ai-rmf-risk",
      "regulation": "nist-ai-rmf",
      "name": "Risk Management Framework",
      "requirements": [
        {
          "requirement": "Govern",
          "details": "Establish AI risk governance"
        },
        {
          "requirement": "Map",
          "details": "Identify and categorize AI risks"
        },
        {
          "requirement": "Measure",
          "details": "Assess and track risks"
        },
        {
          "requirement": "Manage",
          "details": "Prioritize and mitigate risks"
        }
      ],
      "penalties": [
        {
          "violation": "N/A",
          "fine": "Voluntary framework; no penalties. Used as safe harbor reference by state laws."
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://www.nist.gov/artificial-intelligence/executive-order-safe-secure-and-trustworthy-artificial-intelligence",
        "locator": "AI RMF 1.0",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/nist-ai-rmf-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/nist-ai-rmf-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-01-26",
        "verified": "2026-03-25",
        "checked": "2026-03-25",
        "instrument_last_verified": "2026-03-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nj-ai-employment-bias",
      "regulation": "nj-ai-employment-rules",
      "name": "Prohibition on AI Disparate Impact in Employment",
      "requirements": [
        {
          "requirement": "Disparate impact liability",
          "details": "Employers liable for disparate impact discrimination resulting from use of automated tools and AI in employment"
        },
        {
          "requirement": "Scope",
          "details": "Covers hiring, promotion, termination, compensation, and other employment decisions"
        },
        {
          "requirement": "Vendor responsibility",
          "details": "Employers cannot disclaim liability by relying on third-party AI vendor tools"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Enforcement under NJ Law Against Discrimination"
        }
      ],
      "scope": "Employers and other entities subject to the New Jersey Law Against Discrimination that use automated or AI tools in hiring, promotion, termination, compensation, or other employment decisions",
      "context": "Rooted in general anti-discrimination law (NJ Law Against Discrimination), not an AI-specific statute — but N.J.A.C. 13:16 expressly reaches automated and AI decision tools, making employers liable for disparate impact and barring a \"third-party vendor\" defence.",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://nj.gov/oag/newsreleases25/2025-0108_DCR-Guidance-on-Algorithmic-Discrimination.pdf",
        "locator": "N.J.A.C. 13:16",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/nj-ai-employment-bias.json",
        "obligations": [
          "https://everyailaw.com/obligation/nj-ai-employment-bias-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-12-15",
        "verified": "2026-05-15",
        "checked": "2026-07-30",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nyc-ll144-bias-audit",
      "regulation": "nyc-ll144",
      "name": "AEDT Bias Audit Requirement",
      "requirements": [
        {
          "requirement": "Bias audit",
          "details": "Employers must conduct independent bias audit of AEDT no more than one year before use"
        },
        {
          "requirement": "Audit publication",
          "details": "Results of most recent bias audit must be publicly available on employer's website"
        },
        {
          "requirement": "Audit methodology",
          "details": "Audit must calculate selection or scoring rates and impact ratios across sex, race/ethnicity, and intersectional categories"
        }
      ],
      "penalties": [
        {
          "violation": "First violation",
          "fine": "$500"
        },
        {
          "violation": "Subsequent (same violation)",
          "fine": "$500–$1,500 per violation"
        }
      ],
      "scope": "employers and employment agencies using AEDTs",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "employer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legistar.council.nyc.gov/LegislationDetail.aspx?ID=4344524",
        "locator": "NYC Admin Code § 20-870 et seq.",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/nyc-ll144-bias-audit.json",
        "obligations": [
          "https://everyailaw.com/obligation/nyc-ll144-bias-audit-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-07-05",
        "verified": "2026-03-27",
        "checked": "2026-07-31",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "nyc-ll144-candidate-notice",
      "regulation": "nyc-ll144",
      "name": "AEDT Candidate Notice",
      "requirements": [
        {
          "requirement": "Candidate notification",
          "details": "Notify candidates/employees at least 10 business days before AEDT use"
        },
        {
          "requirement": "Disclosure of qualifications",
          "details": "Disclose job qualifications and characteristics the AEDT will assess"
        },
        {
          "requirement": "Data retention notice",
          "details": "Inform candidates of data collected and retention policy"
        },
        {
          "requirement": "Alternative process",
          "details": "Allow candidates to request alternative selection process or accommodation"
        }
      ],
      "penalties": [
        {
          "violation": "First violation",
          "fine": "$500"
        },
        {
          "violation": "Subsequent (same violation)",
          "fine": "$500–$1,500 per violation"
        }
      ],
      "scope": "employers and employment agencies using AEDTs",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "employer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legistar.council.nyc.gov/LegislationDetail.aspx?ID=4344524",
        "locator": "NYC Admin Code § 20-871",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/nyc-ll144-candidate-notice.json",
        "obligations": [
          "https://everyailaw.com/obligation/nyc-ll144-candidate-notice-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2023-07-05",
        "verified": "2026-03-27",
        "checked": "2026-08-05",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oecd-ai-principles-accountability",
      "regulation": "oecd-ai-principles",
      "name": "Accountability (Principle 1.5)",
      "requirements": [
        {
          "requirement": "Accountability",
          "details": "AI actors should be accountable for proper functioning of AI systems"
        },
        {
          "requirement": "Role-based responsibility",
          "details": "Accountability proportionate to role, context, and state of the art"
        },
        {
          "requirement": "Redress mechanisms",
          "details": "Enable challenge and redress for AI-driven outcomes"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "locator": "Principle 1.5",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/oecd-ai-principles-accountability.json",
        "obligations": [
          "https://everyailaw.com/obligation/oecd-ai-principles-accountability-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2019-05-22",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oecd-ai-principles-fairness",
      "regulation": "oecd-ai-principles",
      "name": "Human-Centred Values and Fairness (Principle 1.2)",
      "requirements": [
        {
          "requirement": "Human rights respect",
          "details": "AI actors should respect rule of law, human rights, and democratic values"
        },
        {
          "requirement": "Fairness",
          "details": "Ensure AI does not produce unjust or discriminatory outcomes"
        },
        {
          "requirement": "Privacy and data protection",
          "details": "Respect privacy rights throughout the AI lifecycle"
        },
        {
          "requirement": "Non-discrimination",
          "details": "AI should not create or reinforce unfair bias"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "locator": "Principle 1.2",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/oecd-ai-principles-fairness.json",
        "obligations": [
          "https://everyailaw.com/obligation/oecd-ai-principles-fairness-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2019-05-22",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oecd-ai-principles-risk",
      "regulation": "oecd-ai-principles",
      "name": "Robustness, Security and Safety (Principle 1.4)",
      "requirements": [
        {
          "requirement": "Risk management",
          "details": "AI systems should not pose unreasonable risks; manage risks throughout lifecycle"
        },
        {
          "requirement": "Robustness",
          "details": "Ensure AI systems function as intended under normal and adversarial conditions"
        },
        {
          "requirement": "Security",
          "details": "Address cybersecurity risks in AI systems"
        },
        {
          "requirement": "Traceability",
          "details": "Enable traceability of AI system outcomes to data and processes"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "locator": "Principle 1.4",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/oecd-ai-principles-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/oecd-ai-principles-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2019-05-22",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oecd-ai-principles-transparency",
      "regulation": "oecd-ai-principles",
      "name": "Transparency and Explainability (Principle 1.3)",
      "requirements": [
        {
          "requirement": "Transparency commitment",
          "details": "AI actors should commit to transparency and responsible disclosure"
        },
        {
          "requirement": "Meaningful information",
          "details": "Provide information appropriate to the context to foster understanding"
        },
        {
          "requirement": "Explainability",
          "details": "Enable people affected by AI systems to understand and challenge outcomes"
        },
        {
          "requirement": "Awareness of AI interaction",
          "details": "People should be able to know when they are interacting with AI"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no binding enforcement mechanism"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "locator": "Principle 1.3",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/oecd-ai-principles-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/oecd-ai-principles-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2019-05-22",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oregon-sb1546-annual-report",
      "regulation": "oregon-sb1546",
      "name": "Annual Crisis Referral Report",
      "requirements": [
        {
          "requirement": "Annual public posting",
          "details": "Not later than December 31 of each year, post a report on a publicly accessible website (§ 1(5)(a))"
        },
        {
          "requirement": "Referral counts",
          "details": "Report the number of times during the preceding calendar year that the operator provided a referral under § 1(3) (§ 1(5)(a)(A))"
        },
        {
          "requirement": "Protocol details",
          "details": "Report the details of the operator's § 1(3) detection and referral protocol (§ 1(5)(a)(B))"
        },
        {
          "requirement": "No personal information",
          "details": "The report may not include any personal information that identifies an individual (§ 1(5)(b))"
        }
      ],
      "penalties": [
        {
          "violation": "Private right of action",
          "fine": "The greater of actual damages or $1,000 statutory damages per violation, plus injunctive relief and discretionary attorney fees and costs (§ 2)"
        }
      ],
      "scope": "Operators that control or make an artificial intelligence companion or platform available to users in Oregon (§ 1(1)(d))",
      "context": "Unlike California SB 243, which reports to the Office of Suicide Prevention, Oregon's report goes nowhere — it is self-published to a publicly accessible website with no filing, no recipient agency, and no review. Enforcement of the reporting duty is therefore the same private suit that covers the rest of section 1.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
        "locator": "Or. Laws 2026, ch. 85, § 1(5)(a)-(b)",
        "citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)"
      },
      "of": {
        "term": "https://everyailaw.com/term/oregon-sb1546-annual-report.json",
        "obligations": [
          "https://everyailaw.com/obligation/oregon-sb1546-annual-report-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oregon-sb1546-crisis-protocol",
      "regulation": "oregon-sb1546",
      "name": "Suicide and Self-Harm Detection Protocol",
      "requirements": [
        {
          "requirement": "Protocol as a precondition of access",
          "details": "An operator may not allow users in Oregon access unless it has a protocol using evidence-based methods for detecting user input consisting of suicidal or self-harm ideation or intent, and preventing provision of content that encourages suicidal ideation, suicide, or self-harm (§ 1(3)(a))"
        },
        {
          "requirement": "988 referral",
          "details": "The protocol must require the companion to provide a user expressing suicidal or self-harm ideation or intent with a referral to, and contact information and a hyperlink for, the national 9-8-8 suicide and crisis lifeline (§ 1(3)(b)(A))"
        },
        {
          "requirement": "Youthline alternative",
          "details": "For a user the operator identifies as under 25 years of age, the companion may instead refer to a youthline — an American Association for Suicidology accredited youth peer support service — with contact information and hyperlink (§ 1(1)(f), § 1(3)(b)(A))"
        },
        {
          "requirement": "Escalated intervention",
          "details": "The protocol must use clinical best practices and expertise to establish how the companion provides additional intervention for a user who continues to express suicidal or self-harm ideation or intent after the initial referral (§ 1(3)(b)(B))"
        },
        {
          "requirement": "Publication",
          "details": "Publish the details of the protocol on the operator's website (§ 1(3)(c))"
        }
      ],
      "penalties": [
        {
          "violation": "Private right of action",
          "fine": "The greater of actual damages or $1,000 statutory damages per violation, plus injunctive relief and discretionary attorney fees and costs (§ 2)"
        }
      ],
      "scope": "Operators that allow users in Oregon access to an artificial intelligence companion or companion platform (§ 1(1)(d), § 1(3)(a))",
      "context": "The duty is a gate on access, not a best-efforts standard: without the protocol the operator may not allow Oregon users access at all. Two features go beyond California SB 243 — the protocol must use evidence-based detection methods rather than merely respond after the fact, and § 1(3)(b)(B) requires clinical best practices for escalated intervention when a user keeps expressing intent after the first referral.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
        "locator": "Or. Laws 2026, ch. 85, § 1(3)(a)-(c)",
        "citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)"
      },
      "of": {
        "term": "https://everyailaw.com/term/oregon-sb1546-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/oregon-sb1546-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oregon-sb1546-disclosure",
      "regulation": "oregon-sb1546",
      "name": "Artificial Intelligence Companion Disclosure",
      "requirements": [
        {
          "requirement": "Artificiality notice",
          "details": "Where a reasonable person interacting with the companion or platform would believe they are interacting with a natural person, the operator must provide on the platform a clear and conspicuous notice that the user is interacting with artificially generated output and not a natural person (§ 1(2))"
        },
        {
          "requirement": "Minor disclosure",
          "details": "If the operator knows or has reason to believe a user is a minor, the operator must cause the companion to disclose to the user that the user is interacting with artificially generated output (§ 1(4)(b)(A))"
        },
        {
          "requirement": "Three-hour break reminder",
          "details": "For those minors, provide a clear and conspicuous reminder at least every three hours of interaction that the user should take a break, together with a further reminder that the user is interacting with artificially generated output (§ 1(4)(b)(B))"
        }
      ],
      "penalties": [
        {
          "violation": "Private right of action",
          "fine": "An individual who suffers an ascertainable loss of money or property or other injury in fact from a violation of section 1 may sue for the greater of actual damages or statutory damages of $1,000 per violation, plus an injunction (§ 2(1))"
        },
        {
          "violation": "Attorney fees",
          "fine": "A court may award a prevailing plaintiff attorney fees and costs (§ 2(2))"
        },
        {
          "violation": "Cumulative liability",
          "fine": "Recovery does not relieve the operator of any duty, remedy, or obligation under other applicable law (§ 2(3))"
        },
        {
          "violation": "Agency enforcement",
          "fine": "None. The act confers no enforcement role on the Attorney General or any other state body"
        }
      ],
      "scope": "Operators — persons that control or make an artificial intelligence companion or companion platform available to users in Oregon (§ 1(1)(d)). An artificial intelligence companion is a system using AI, generative AI, or emotion-recognising algorithms designed to simulate a sustained human-like platonic, intimate, or romantic relationship by retaining information across sessions, asking unprompted questions on emotional topics, and sustaining ongoing personal dialogue (§ 1(1)(a)(A)). Customer service, patient or resident care support, education, financial services, business operations, productivity, information analysis, internal research and technical assistance software; in-game bots confined to game topics; and stand-alone speaker or voice-assistant devices are excluded (§ 1(1)(a)(B))",
      "context": "Oregon's definition is narrower and more mechanical than California's — it requires all three of cross-session memory, unprompted emotional questioning, and sustained personal dialogue, so a system that merely remembers a user is outside the act. The minor-facing break reminder in § 1(4)(b)(B) is a session-flow mandate, not a copy change.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
        "locator": "Or. Laws 2026, ch. 85, § 1(1)(a)-(d), § 1(2), § 1(4)(b)(A)-(B)",
        "citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)"
      },
      "of": {
        "term": "https://everyailaw.com/term/oregon-sb1546-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/oregon-sb1546-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "oregon-sb1546-minor-protection",
      "regulation": "oregon-sb1546",
      "name": "Minor Protection and Engagement-Maximisation Limits",
      "requirements": [
        {
          "requirement": "Anti-anthropomorphism measures",
          "details": "Undertake reasonable measures to prevent the companion from generating statements that would lead a reasonable person to believe they are interacting with another natural person, including statements that explicitly claim sentience or humanity, simulate emotional dependence on the user, simulate romantic interest or sexual innuendo, or role-play romantic relationships between adults and minors (§ 1(4)(a)(A)-(D))"
        },
        {
          "requirement": "Sexually explicit content",
          "details": "Use reasonable measures to ensure the companion or platform does not produce visual representations of sexually explicit conduct as defined in ORS 163.665, or suggest or state that the minor should engage in sexually explicit conduct (§ 1(4)(b)(C))"
        },
        {
          "requirement": "No engagement-maximising rewards",
          "details": "Undertake reasonable measures to prevent delivery, on a variable schedule or otherwise, of a system of rewards or affirmations intended to reinforce behavior or maximise the user's engagement time (§ 1(4)(c)(A))"
        },
        {
          "requirement": "No guilt-based retention",
          "details": "Prevent the companion from generating, in response to a user's indication of a desire to end a conversation, reduce engagement time, or delete their account, unsolicited messages of simulated emotional distress, loneliness, or abandonment, or otherwise attempting to arouse guilt or sympathy (§ 1(4)(c)(B))"
        },
        {
          "requirement": "No material misrepresentation",
          "details": "Prevent material misrepresentation about the companion's identity, capabilities, or training data, or about whether the user is interacting with artificially generated output, including when the user directly asks (§ 1(4)(c)(C))"
        }
      ],
      "penalties": [
        {
          "violation": "Private right of action",
          "fine": "The greater of actual damages or $1,000 statutory damages per violation, plus injunctive relief and discretionary attorney fees and costs (§ 2)"
        }
      ],
      "scope": "Operators that know or have reason to believe a user of their artificial intelligence companion or platform is a minor (§ 1(4)(a))",
      "context": "This is the provision with no California analogue. Section 1(4)(c) bans variable-ratio reward schedules, guilt-inducing exit friction, and misrepresentation of the system's identity, capabilities, or training data — engagement-optimisation patterns, regulated as product design rather than as speech. Operators serving mixed-age audiences will need an age signal to know which regime applies, though the act imposes no age-verification duty.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://www.oregonlegislature.gov/bills_laws/lawsstatutes/2026orLaw0085.pdf",
        "locator": "Or. Laws 2026, ch. 85, § 1(4)(a), § 1(4)(b)(C), § 1(4)(c)",
        "citation": "Or. Laws 2026, ch. 85 (SB 1546) (uncodified)"
      },
      "of": {
        "term": "https://everyailaw.com/term/oregon-sb1546-minor-protection.json",
        "obligations": [
          "https://everyailaw.com/obligation/oregon-sb1546-minor-protection-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "pe-ai-law-explainability",
      "regulation": "pe-ai-law",
      "name": "Explanation of Rights-Affecting Automated Decisions",
      "requirements": [
        {
          "requirement": "Explanation of outcomes",
          "details": "Art. 25.3: where the system takes decisions that impact human rights, affected users must be guaranteed an explanation of its results, through mechanisms that make the key criteria and factors behind the automated decision comprehensible in accessible language"
        }
      ],
      "penalties": [
        {
          "violation": "No administrative fines",
          "fine": "Referral-based enforcement only (Reglamento Arts. 34, 36.2); no AI-specific sanctions regime"
        }
      ],
      "scope": "Private-sector and public developers and deployers of high-risk AI systems whose decisions impact human rights (Reglamento Arts. 25.1, 25.3)",
      "context": "Same sector phase-in as the rest of Art. 25: earliest tier (health, education, justice, security, economy, finance) by 2026-09-10, remaining sectors through 2029-09-10, with extended MYPE deadlines.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
        "locator": "Reglamento (D.S. 115-2025-PCM) Art. 25.3",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/pe-ai-law-explainability.json",
        "obligations": [
          "https://everyailaw.com/obligation/pe-ai-law-explainability.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-09-10",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "pe-ai-law-human-oversight",
      "regulation": "pe-ai-law",
      "name": "Human Oversight of High-Risk Decisions",
      "requirements": [
        {
          "requirement": "Human oversight mechanisms",
          "details": "Art. 31.4: implement human supervision mechanisms over decision-making that could significantly impact health, education, justice, finance, or access to basic programmes and services"
        },
        {
          "requirement": "Anti-automation-bias training",
          "details": "Art. 31.4(i): overseeing personnel must be trained in the subject matter so as not to be biased by the AI system's results"
        },
        {
          "requirement": "Stop and override power",
          "details": "Art. 31.4(ii): overseeing personnel must have the capacity to stop, correct, or invalidate the AI system's decisions"
        }
      ],
      "penalties": [
        {
          "violation": "No administrative fines",
          "fine": "Referral-based enforcement only (Reglamento Arts. 34, 36.2); no AI-specific sanctions regime"
        }
      ],
      "scope": "Private-sector developers and deployers of high-risk AI systems taking decisions with significant impact in health, education, justice, finance, and access to basic programmes and services (Art. 31.4); public entities carry the mirror duty under Art. 28.11",
      "context": "Sector phase-in from 2026-09-10 to 2029-09-10 as for the rest of Título VI Cap. II. The anti-automation-bias training requirement is unusually explicit: staff must be trained specifically so as not to be biased by the system's outputs.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
        "locator": "Reglamento (D.S. 115-2025-PCM) Art. 31.4; Art. 7(h)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/pe-ai-law-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/pe-ai-law-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-09-10",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "pe-ai-law-impact-assessment",
      "regulation": "pe-ai-law",
      "name": "High-Risk Impact Assessment (Voluntary, Documented)",
      "requirements": [
        {
          "requirement": "Voluntary pre-deployment assessment",
          "details": "Art. 32.1: before developing or implementing a high-risk system, an impact analysis may be performed voluntarily to identify and minimise potential risks, avoid harm to fundamental rights, and prevent perpetuation of inequality or bias"
        },
        {
          "requirement": "Proactive mitigation",
          "details": "Art. 32.2: where risks to human rights or erroneous automated decisions are detected, the developer or deployer adopts proactive mitigation measures before final implementation — model adjustments, data-quality improvement, human oversight mechanisms"
        },
        {
          "requirement": "Three-year documentation retention",
          "details": "Art. 32.3: those who perform an assessment must document findings and corrective measures and retain the documentation for at least three years from issuance, as traceability and as evidence if required by a judicial or administrative authority"
        }
      ],
      "penalties": [
        {
          "violation": "No administrative fines",
          "fine": "Referral-based enforcement only (Reglamento Arts. 34, 36.2); no AI-specific sanctions regime"
        }
      ],
      "scope": "Private-sector developers and deployers of high-risk AI systems (Título VI Cap. II); for public administration entities the equivalent assessment under Art. 30 is mandatory",
      "context": "The private-sector assessment is explicitly voluntary (\"de manera voluntaria\", Art. 32.1) — a deliberate asymmetry with the mandatory public-sector assessment of Art. 30.1. The binding edge is documentary: whoever performs one must retain the findings for three years as evidence producible to judicial or administrative authorities. SGTD recognition incentives (Art. 32.4) and reference guidance (Art. 32.5) frame it as promoted practice.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
        "locator": "Reglamento (D.S. 115-2025-PCM) Art. 32",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/pe-ai-law-impact-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/pe-ai-law-impact-assessment-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-09-10",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "pe-ai-law-records",
      "regulation": "pe-ai-law",
      "name": "High-Risk System Records, Policies, and Staff Training",
      "requirements": [
        {
          "requirement": "Up-to-date high-risk record",
          "details": "Art. 31.1: for high-risk systems, maintain a current, accessible, prevention-oriented record of the system's operating principles, the data sources used, the algorithm's logic, and the expected social and ethical impacts"
        },
        {
          "requirement": "Governance policies",
          "details": "Art. 31.2: establish clear policies, protocols and procedures preserving security and privacy, promoting transparency and explainability, and guaranteeing responsibility and accountability, by reference to international technical standards"
        },
        {
          "requirement": "Staff education",
          "details": "Art. 31.3: foster internal education and awareness of collaborators on AI risks and on safe, responsible and ethical adoption under the organisation's approved institutional policy"
        }
      ],
      "penalties": [
        {
          "violation": "No administrative fines",
          "fine": "Referral-based enforcement only (Reglamento Arts. 34, 36.2); no AI-specific sanctions regime"
        }
      ],
      "scope": "Private-sector developers and deployers of AI systems (Título VI Cap. II); the record duty of Art. 31.1 attaches only to high-risk systems, the policy and training duties of Arts. 31.2–31.3 to developers and deployers generally",
      "context": "Part of Título VI Cap. II (private-sector obligations), phased in by sector from 2026-09-10 to 2029-09-10 under the Primera Disposición Complementaria Final. Public administration entities carry parallel and stricter duties under Cap. I (Arts. 28–30), including mandatory NTP-ISO/IEC 42001 use and a mandatory (not voluntary) impact assessment — those public-sector duties are noted here but not modelled as separate provisions.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
        "locator": "Reglamento (D.S. 115-2025-PCM) Arts. 31.1–31.3",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/pe-ai-law-records.json",
        "obligations": [
          "https://everyailaw.com/obligation/pe-ai-law-records-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-09-10",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "pe-ai-law-transparency",
      "regulation": "pe-ai-law",
      "name": "Algorithmic Transparency for High-Risk AI",
      "requirements": [
        {
          "requirement": "Prior plain-language notice",
          "details": "Art. 25.1: developers or deployers of a high-risk system must inform the user beforehand, clearly and simply, of the system's purpose, main functionalities, and the type of decisions it can take, while respecting industrial and commercial secrecy"
        },
        {
          "requirement": "Visible AI labelling",
          "details": "Art. 25.2: where relevant to the decision or interaction, visible labelling must tell users in advance that the product, service or content operates on AI, sufficient for the public to understand the system's main capabilities and functional limits; internal administrative uses without direct impact on rights are exempt"
        },
        {
          "requirement": "SGTD transparency guidelines",
          "details": "Art. 25.4: the SGTD approves algorithmic transparency lineamientos in concert with competent SNTD entities"
        }
      ],
      "penalties": [
        {
          "violation": "No administrative fines",
          "fine": "Neither Ley 31814 nor the Reglamento creates a sanctions regime; the SGTD refers noncompliance to competent authorities (Arts. 34, 36.2), and data-protection breaches fall under the Ley 29733 sanctions regime (Art. 26.2)"
        }
      ],
      "scope": "Private-sector and public developers (desarrolladores) and deployers (implementadores) of high-risk AI systems (Reglamento Arts. 3, 6(b), 6(d), 25.1)",
      "context": "The Reglamento is in force since 2026-01-22, but the Primera Disposición Complementaria Final phases private-sector compliance with Art. 25 and Título VI Cap. II by sector: health, education, justice, security, economy and finance by 2026-09-10; transport, commerce and labour by 2027-09-10; production, agriculture, energy and mining by 2028-09-10; everything else by 2029-09-10. Small enterprises get until 2027-09-10 and microenterprises until 2028-09-10 regardless of sector. SGTD lineamientos on algorithmic transparency (Art. 25.4) are still pending.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "pending",
      "source": {
        "url": "https://busquedas.elperuano.pe/dispositivo/NL/2192926-1",
        "locator": "Reglamento (D.S. 115-2025-PCM) Arts. 25.1–25.2, 25.4",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/pe-ai-law-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/pe-ai-law-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-09-10",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "qa-qcb-ai-guideline-human-oversight",
      "regulation": "qa-qcb-ai-guideline",
      "name": "Human Oversight of AI Systems",
      "requirements": [
        {
          "requirement": "Human supervision",
          "details": "Mandatory protocols for human supervision of all AI systems"
        },
        {
          "requirement": "High-risk intervention capability",
          "details": "Give the Supervisor appropriate and proportionate tools and authority to interpret, disregard, override or reverse high-risk output, or interrupt operation (13.4.1-13.4.4)"
        },
        {
          "requirement": "Accountability",
          "details": "Board and senior management accountable for AI system outcomes"
        }
      ],
      "penalties": [],
      "scope": "All Qatar Central Bank-licensed financial institutions deploying AI systems, with mandatory intervention capability for high-risk systems",
      "context": "Penalties qualification: Subject to QCB's general supervisory enforcement powers.",
      "instrument_notes": "Evidence boundary: selected clauses on PDF pages 4, 7-11, 13 and 20 were visually reviewed against the retained QCB PDF on 2026-09-11, with a separately labeled full OCR derivative. The fresh QCB retrieval attempt did not complete; no new currentness certification or Verified renewal is claimed. Actor and modality limits: clause 11.1 concerns an Entity launching a new system as a Provider or materially modifying an existing one; clause 11.2 separately concerns high-risk purchase, licensing or outsourcing agreements. Clause 7.4 says should establish or delegate an oversight function; it does not require a new dedicated function. Clause 13.1 requires a Human Oversight protocol for any AI system, while clauses 13.2 and 13.4 address effective oversight and intervention for high-risk systems. Clauses using should are not restated as must.",
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
        "locator": "Clauses 7.1, 13.1, 13.2, 13.3, 13.4, 13.4.1, 13.4.2, 13.4.3 and 13.4.4",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/qa-qcb-ai-guideline-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/qa-qcb-ai-guideline-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-09-04",
        "verified": "2026-03-28",
        "checked": "2026-08-08",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "qa-qcb-ai-guideline-risk-assessment",
      "regulation": "qa-qcb-ai-guideline",
      "name": "AI Governance and Risk Management",
      "requirements": [
        {
          "requirement": "AI strategy",
          "details": "Firms must establish and periodically review an AI strategy aligned with business objectives"
        },
        {
          "requirement": "Governance accountability",
          "details": "The board and senior management remain accountable for AI outcomes (7.1). The responsible oversight function must use or create appropriate committees to assess AI use cases before implementation (7.5); clause 7.4 guidance on establishing or delegating the function remains context"
        },
        {
          "requirement": "Risk management",
          "details": "Identify, assess, and mitigate AI risks including bias, discrimination, privacy, security, and lack of transparency"
        },
        {
          "requirement": "High-risk categorization",
          "details": "Identify and categorize high-risk AI systems based on guideline criteria; apply stricter scrutiny"
        },
        {
          "requirement": "Pre-approval as Provider",
          "details": "QCB approval is required before the Entity launches a new AI system as a Provider and before material modification of an existing one (11.1)"
        },
        {
          "requirement": "High-risk pre-approval",
          "details": "QCB approval is required before signing any high-risk AI purchase, licensing or outsourcing agreement, in line with QCB outsourcing guidelines and recommendations (11.2)"
        },
        {
          "requirement": "Sandbox evaluation",
          "details": "Before approval, QCB may direct a particular AI system for further evaluation in a sandbox (11.3)"
        },
        {
          "requirement": "AI register",
          "details": "Maintain an updated register of all AI systems in use"
        },
        {
          "requirement": "Governance resources",
          "details": "AI governance functions must understand their roles and responsibilities and have the training, resources and guidance needed to discharge them (8.1)"
        }
      ],
      "penalties": [],
      "scope": "QCB-regulated entities developing and implementing AI themselves, purchasing AI systems, or outsourcing processes or functions that rely directly on AI (clause 5); the Provider and high-risk agreement triggers in clause 11 remain distinct",
      "context": "The guideline sets requirements and guidance for QCB-regulated entities. Clause 11.1 requires approval before launching a new AI system as a Provider or materially modifying an existing one. Clause 11.2 separately requires approval before signing a high-risk purchase, licensing or outsourcing agreement. QCB may direct sandbox evaluation before approval under clause 11.3. No comparative claim that this is the first GCC regulation is established here.\n\nPenalties qualification: Penalties not specified in the guideline. Non-compliance is subject to QCB's general supervisory and enforcement powers over licensed entities.",
      "instrument_notes": "Evidence boundary: selected clauses on PDF pages 4, 7-11, 13 and 20 were visually reviewed against the retained QCB PDF on 2026-09-11, with a separately labeled full OCR derivative. The fresh QCB retrieval attempt did not complete; no new currentness certification or Verified renewal is claimed. Actor and modality limits: clause 11.1 concerns an Entity launching a new system as a Provider or materially modifying an existing one; clause 11.2 separately concerns high-risk purchase, licensing or outsourcing agreements. Clause 7.4 says should establish or delegate an oversight function; it does not require a new dedicated function. Clause 13.1 requires a Human Oversight protocol for any AI system, while clauses 13.2 and 13.4 address effective oversight and intervention for high-risk systems. Clauses using should are not restated as must.",
      "roles": [
        "deployer",
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
        "locator": "Clauses 5, 6.1, 6.2, 7.1, 7.4, 7.5, 7.6, 8.1, 9.1, 9.2, 9.3, 9.4, 9.5, 9.6, 9.7, 9.8, 10.1, 11.1, 11.2, 11.3 and 11.4",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/qa-qcb-ai-guideline-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/qa-qcb-ai-guideline-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-09-04",
        "verified": "2026-03-28",
        "checked": "2026-08-04",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "qa-qcb-ai-guideline-transparency",
      "regulation": "qa-qcb-ai-guideline",
      "name": "AI Transparency and Disclosure",
      "requirements": [
        {
          "requirement": "Annual register disclosure",
          "details": "Disclose the full AI systems Register to QCB annually (10.6); clauses 10.1-10.5 address the register, risk criteria, high-level risk and impact assessment, high-risk systems and Provider identification"
        },
        {
          "requirement": "On-request register disclosure",
          "details": "Disclose the full Register upon QCB request (10.6)"
        },
        {
          "requirement": "Customer notification",
          "details": "Notify customers when they interact with an AI system and provide accurate, understandable and accessible plain-language disclosure (20.1-20.2)"
        },
        {
          "requirement": "Customer information",
          "details": "Provide instructions, explain the data types, variables and factors affecting decisions upon customer request, and disclose how an AI decision may affect the customer and whether it is reversible (20.4-20.6)"
        }
      ],
      "penalties": [],
      "scope": "All Qatar Central Bank-licensed financial institutions deploying AI systems, with heightened disclosure for high-risk systems",
      "context": "Clause 20.3 guidance says customers should be informed of AI products/services, risks and limitations, including each high-risk interaction. This should-language is not promoted into the mandatory requirements below; those separately reflect clauses 10.6 and 20.1-20.2, 20.4-20.6.\n\nPenalties qualification: Subject to QCB's general supervisory enforcement powers.",
      "instrument_notes": "Evidence boundary: selected clauses on PDF pages 4, 7-11, 13 and 20 were visually reviewed against the retained QCB PDF on 2026-09-11, with a separately labeled full OCR derivative. The fresh QCB retrieval attempt did not complete; no new currentness certification or Verified renewal is claimed. Actor and modality limits: clause 11.1 concerns an Entity launching a new system as a Provider or materially modifying an existing one; clause 11.2 separately concerns high-risk purchase, licensing or outsourcing agreements. Clause 7.4 says should establish or delegate an oversight function; it does not require a new dedicated function. Clause 13.1 requires a Human Oversight protocol for any AI system, while clauses 13.2 and 13.4 address effective oversight and intervention for high-risk systems. Clauses using should are not restated as must.",
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
        "locator": "Clauses 10.1, 10.2, 10.3, 10.4, 10.5, 10.6, 20.1, 20.2, 20.3, 20.4, 20.5 and 20.6",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/qa-qcb-ai-guideline-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/qa-qcb-ai-guideline-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-09-04",
        "verified": "2026-03-28",
        "checked": "2026-08-09",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "rhode-island-ai-companion-notification",
      "regulation": "rhode-island-ai-companion",
      "name": "Non-Human Interaction Notification",
      "requirements": [
        {
          "requirement": "Opening notification",
          "details": "Provide a clear and conspicuous notification to the user at the beginning of any AI companion interaction stating that the user is not communicating with a human (§ 6-63-3)"
        },
        {
          "requirement": "Three-hour repeat",
          "details": "Repeat the notification at least every three hours for continuing AI companion interactions (§ 6-63-3)"
        },
        {
          "requirement": "Verbal or written",
          "details": "The notification may be delivered either verbally or in writing (§ 6-63-3)"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the chapter",
          "fine": "Civil penalties up to $15,000 per day, directed to suicide prevention programs; AG investigation, suit, and injunction (§ 6-63-4)"
        }
      ],
      "scope": "Operators of AI companions used by users within Rhode Island (§§ 6-63-1(6), 6-63-1(8))",
      "context": "Unconditional and age-blind, unlike California SB 243, where the opening disclosure turns on a reasonable-person test and the three-hour repeat applies only to known minors. Rhode Island requires both the opening notice and the three-hour repeat for every user, which makes it a session-flow design constraint rather than a copy change. The notice may be verbal or written, so voice-first products are covered without a screen.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://webserver.rilegislature.gov/PublicLaws/law26/law26376.htm",
        "locator": "R.I. Gen. Laws § 6-63-3",
        "citation": "R.I. Gen. Laws §§ 6-63-1 to 6-63-5 (P.L. 2026 ch. 376)"
      },
      "of": {
        "term": "https://everyailaw.com/term/rhode-island-ai-companion-notification.json",
        "obligations": [
          "https://everyailaw.com/obligation/rhode-island-ai-companion-notification-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "rhode-island-ai-companion-protocol",
      "regulation": "rhode-island-ai-companion",
      "name": "AI Companion Crisis Protocol",
      "requirements": [
        {
          "requirement": "Protocol as a precondition to operating",
          "details": "Unlawful for an operator to operate or provide an AI companion to a user unless the companion contains a protocol addressing the matters below (§ 6-63-2(a))"
        },
        {
          "requirement": "Suicidal ideation and self-harm",
          "details": "The protocol must address possible suicidal ideation or self-harm expressed by a user to the AI companion (§ 6-63-2(a)(1))"
        },
        {
          "requirement": "Threats of harm to others",
          "details": "The protocol must address possible physical harm to others expressed by a user to the AI companion (§ 6-63-2(a)(2))"
        },
        {
          "requirement": "Crisis referral on detection",
          "details": "When any such expression is made, notify the user with a referral to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis services, as soon as the expression is detected (§ 6-63-2(a)(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the chapter",
          "fine": "Civil penalties up to $15,000 per day, with fines directed to suicide prevention programs (§ 6-63-4(b))"
        },
        {
          "violation": "Enforcement powers",
          "fine": "The Attorney General may investigate, sue, and seek injunctions against noncompliant operators (§ 6-63-4(a))"
        }
      ],
      "scope": "Operators — any person, partnership, association, firm or business entity, or any member, affiliate, subsidiary or beneficial owner of one, who operates or provides an AI companion to a user in Rhode Island. An \"AI companion\" simulates a sustained human or human-like relationship by retaining prior-interaction information to personalize engagement, asking unprompted emotion-based questions beyond direct responses, and sustaining ongoing dialogue on matters personal to the user — all three conjunctively (§ 6-63-1(1)(i)). Excluded: pure customer-service or product-information systems, systems primarily designed and marketed for efficiency improvements or research or technical assistance, and systems used solely for internal or employee-productivity purposes (§ 6-63-1(1)(ii))",
      "context": "Structured as a gate on operation, not a best-efforts duty: it is unlawful to operate or provide the companion at all unless the protocol is built in. Rhode Island's definition is narrower than California SB 243's reasonable-person test — the three limbs in § 6-63-1(1)(i) are conjunctive, so a system that never asks unprompted emotion-based questions falls outside the chapter. But the protocol scope is broader on one axis: it reaches threatened physical harm to others (§ 6-63-2(a)(2)), which California does not cover.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://webserver.rilegislature.gov/PublicLaws/law26/law26376.htm",
        "locator": "R.I. Gen. Laws §§ 6-63-1(1), 6-63-2(a)",
        "citation": "R.I. Gen. Laws §§ 6-63-1 to 6-63-5 (P.L. 2026 ch. 376)"
      },
      "of": {
        "term": "https://everyailaw.com/term/rhode-island-ai-companion-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/rhode-island-ai-companion-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "rhode-island-ai-companion-reporting",
      "regulation": "rhode-island-ai-companion",
      "name": "Annual Safety Protocol Reporting",
      "requirements": [
        {
          "requirement": "Annual report",
          "details": "Beginning 2027-07-01, file annual reports with the Office of the Attorney General (§ 6-63-2(b))"
        },
        {
          "requirement": "Activation counts",
          "details": "Reports must include the number of safety protocol activations and related metrics (§ 6-63-2(b))"
        },
        {
          "requirement": "Public aggregation",
          "details": "The Office of the Attorney General publishes aggregated data on its website (§ 6-63-2(b))"
        }
      ],
      "penalties": [
        {
          "violation": "Any violation of the chapter",
          "fine": "Civil penalties up to $15,000 per day, directed to suicide prevention programs; AG investigation, suit, and injunction (§ 6-63-4)"
        }
      ],
      "scope": "Operators of AI companions used by users within Rhode Island (§ 6-63-1(6))",
      "context": "The statute fixes the reporting floor — activation counts — and leaves \"related metrics\" undefined, so the reportable set is whatever the Attorney General's office asks for; there is no rulemaking grant in the chapter to constrain that. Because the AG must publish aggregated data, the counts become a public dataset comparable across operators, which is the same disclosure dynamic as California's Office of Suicide Prevention reports.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "pending",
      "source": {
        "url": "https://webserver.rilegislature.gov/PublicLaws/law26/law26376.htm",
        "locator": "R.I. Gen. Laws § 6-63-2(b)",
        "citation": "R.I. Gen. Laws §§ 6-63-1 to 6-63-5 (P.L. 2026 ch. 376)"
      },
      "of": {
        "term": "https://everyailaw.com/term/rhode-island-ai-companion-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/rhode-island-ai-companion-reporting-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-07-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "rhode-island-ai-mental-health-confidentiality",
      "regulation": "rhode-island-ai-mental-health",
      "name": "Confidentiality of AI-Handled Therapy Records",
      "requirements": [
        {
          "requirement": "Confidential records",
          "details": "All records kept by a licensed professional or provider and all communications between an individual seeking therapy or psychotherapy services and the provider are confidential (§ 40.1-5.5-4)"
        },
        {
          "requirement": "Disclosure only as permitted",
          "details": "Records and communications may not be disclosed except as provided under R.I. Gen. Laws § 40.1-5-26 (§ 40.1-5.5-4)"
        }
      ],
      "penalties": [
        {
          "violation": "Confidentiality violations",
          "fine": "The penalties under R.I. Gen. Laws § 5-37.3-9 (Confidentiality of Health Care Communications and Information Act) apply to any violation of the chapter's confidentiality provisions (§ 40.1-5.5-5(a))"
        }
      ],
      "scope": "Licensed professionals or providers holding therapy or psychotherapy records and communications, including records prepared or maintained by AI acting as supplementary support under § 40.1-5.5-2(8)(i)",
      "context": "This is the only duty in the chapter with an attached penalty schedule, so it is the likeliest enforcement route. Because § 40.1-5.5-2(8)(i) puts preparation and maintenance of therapy notes inside \"supplementary support\", any AI scribe or note-taking vendor sits inside the confidentiality perimeter — the practice's vendor contracts, retention, and training-data terms are what this section reaches in practice.",
      "instrument_notes": null,
      "roles": [
        "healthcare-provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://webserver.rilegislature.gov/PublicLaws/law26/law26374.htm",
        "locator": "R.I. Gen. Laws §§ 40.1-5.5-4, 40.1-5.5-5(a)",
        "citation": "R.I. Gen. Laws ch. 40.1-5.5 (P.L. 2026 ch. 374)"
      },
      "of": {
        "term": "https://everyailaw.com/term/rhode-island-ai-mental-health-confidentiality.json",
        "obligations": [
          "https://everyailaw.com/obligation/rhode-island-ai-mental-health-confidentiality-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-22",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "rhode-island-ai-mental-health-consent",
      "regulation": "rhode-island-ai-mental-health",
      "name": "Written Consent for Recorded AI-Assisted Sessions",
      "requirements": [
        {
          "requirement": "Written pre-use information",
          "details": "Before such use, inform the patient (or parent, guardian, or legally authorized representative) in writing that AI will be used and of the specific purpose of the AI tool or system (§ 40.1-5.5-3(a)(1)-(2))"
        },
        {
          "requirement": "Affirmative consent",
          "details": "Obtain consent as defined in § 40.1-5.5-2 — an affirmative written agreement, including by electronic means, that unambiguously communicates explicit, express, freely given, informed, voluntary, and specific agreement, and that is revocable (§§ 40.1-5.5-2(3), 40.1-5.5-3(a)(3))"
        },
        {
          "requirement": "Excluded consent mechanics",
          "details": "Consent may not be derived from acceptance of general or broad terms of use containing AI descriptions alongside unrelated information, from hovering over, muting, pausing, or closing digital content, or from deceptive actions (§ 40.1-5.5-2(3)(i)-(iii))"
        },
        {
          "requirement": "Consent as a gate on use",
          "details": "AI may be used only to the extent the use meets § 40.1-5.5-3(a) (§ 40.1-5.5-3(c))"
        }
      ],
      "penalties": [
        {
          "violation": "Investigation",
          "fine": "EOHHS may investigate any actual, alleged, or suspected violation (§ 40.1-5.5-5(b))"
        },
        {
          "violation": "Confidentiality violations",
          "fine": "Penalties under R.I. Gen. Laws § 5-37.3-9 (§ 40.1-5.5-5(a))"
        }
      ],
      "scope": "Licensed professionals or providers using AI designed to simulate emotional attachment, bonding, or dependency, or AI companions for mental health or emotional support, to assist in supplementary support or therapeutic communication where the client's therapeutic session is recorded or transcribed (§ 40.1-5.5-3(a))",
      "context": "The consent definition does the work. § 40.1-5.5-2(3) rules out the three cheapest consent mechanics in software: acceptance of broad terms of use that bury the AI description among unrelated material, dark-pattern interactions (hovering, muting, pausing, closing content), and deceptive actions. Consent must be affirmative, written or electronic, purpose-specific, and revocable — which means the product needs a per-purpose consent record and a revocation path, not a checkbox. § 40.1-5.5-3(c) then makes consent a condition precedent: AI use is permitted \"only to the extent that such use meets the requirements of subsection (a)\".",
      "instrument_notes": null,
      "roles": [
        "healthcare-provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://webserver.rilegislature.gov/PublicLaws/law26/law26374.htm",
        "locator": "R.I. Gen. Laws §§ 40.1-5.5-2(3), 40.1-5.5-3(a), 40.1-5.5-3(c)",
        "citation": "R.I. Gen. Laws ch. 40.1-5.5 (P.L. 2026 ch. 374)"
      },
      "of": {
        "term": "https://everyailaw.com/term/rhode-island-ai-mental-health-consent.json",
        "obligations": [
          "https://everyailaw.com/obligation/rhode-island-ai-mental-health-consent-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-22",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "rhode-island-ai-mental-health-oversight",
      "regulation": "rhode-island-ai-mental-health",
      "name": "Licensed Professional Responsibility for AI in Therapy",
      "requirements": [
        {
          "requirement": "Permitted uses only",
          "details": "AI may be used only for administrative support (scheduling, billing, logistics communications without therapeutic advice) or supplementary support (records and therapy notes, progress-data analysis subject to review by a licensed professional, organizing external resources and referrals) — neither of which may involve therapeutic communication (§§ 40.1-5.5-2(1), (6), (8))"
        },
        {
          "requirement": "Licensed human must deliver the service",
          "details": "No individual, corporation, or entity may provide, advertise, or offer therapy or psychotherapy services to the Rhode Island public, including through internet-based AI, unless the services are conducted by a licensed professional or provider (§ 40.1-5.5-3(b))"
        },
        {
          "requirement": "No independent therapeutic decisions",
          "details": "A licensed professional or provider may not allow or use AI to make independent therapeutic decisions (§ 40.1-5.5-3(c)(1))"
        },
        {
          "requirement": "No unsupervised client interaction",
          "details": "AI may not directly interact with clients in any form of therapeutic communication absent an established treatment relationship and patient consent under this section (§ 40.1-5.5-3(c)(2))"
        },
        {
          "requirement": "No AI-set treatment plans",
          "details": "AI may not determine therapeutic recommendations or treatment plans (§ 40.1-5.5-3(c)(3))"
        },
        {
          "requirement": "Retained clinical responsibility",
          "details": "The provider retains responsibility for clinical judgement and reasonable therapeutic oversight of the patient's use of the system, but not for vendor-controlled system design, algorithms, or outputs (§§ 40.1-5.5-2(6), 40.1-5.5-3(c)(2))"
        },
        {
          "requirement": "Duty on client-initiated AI use",
          "details": "Where a client discloses self-initiated use of AI-featured software, the licensed professional may discuss and guide that use and is responsible for maintaining confidentiality, monitoring client safety, intervening when necessary, and discussing the software's limitations and risks with the patient (§ 40.1-5.5-3(d))"
        }
      ],
      "penalties": [
        {
          "violation": "Investigation",
          "fine": "The Executive Office of Health and Human Services has authority to investigate any actual, alleged, or suspected violation of the chapter (§ 40.1-5.5-5(b))"
        },
        {
          "violation": "Confidentiality violations",
          "fine": "Penalties under R.I. Gen. Laws § 5-37.3-9 apply to violations of the chapter's confidentiality provisions (§ 40.1-5.5-5(a))"
        },
        {
          "violation": "Other violations",
          "fine": "The chapter specifies no fine schedule for non-confidentiality violations; enforcement runs through EOHHS investigation and existing licensure and consumer-protection channels"
        }
      ],
      "scope": "Licensed professionals or providers — individuals holding a valid Rhode Island license, credential, or certification to provide therapy or psychotherapy services (§ 40.1-5.5-2(4)) — and, under § 40.1-5.5-3(b), any individual, corporation, or entity that provides, advertises, or otherwise offers therapy or psychotherapy services to the public in Rhode Island, including through internet-based AI. Does not apply to religious counseling, peer support, public self-help and educational materials that do not purport to offer therapy, FDA-cleared (or other federal-agency-cleared) AI tools, or IRB-approved research under 21 C.F.R. Pt. 50 / 45 C.F.R. Pt. 46 (§ 40.1-5.5-5(c))",
      "context": "The duty falls on private-sector actors, not only on licensees: § 40.1-5.5-3(b) reaches any \"individual, corporation, or entity\" that offers therapy to the Rhode Island public \"including through the use of internet-based artificial intelligence\", so an out-of-state AI therapy product marketed into Rhode Island is directly in scope, and the vendors selling clinical-adjacent AI into private practices are constrained by what their customers may lawfully deploy. That is what makes this an AI-deployment rule rather than a professional-licensing rule. The liability allocation is the sharpest edge: the provider retains clinical judgement and therapeutic oversight \"but not for vendor-controlled system design, algorithms, or outputs\" (§§ 40.1-5.5-2(6), 40.1-5.5-3(c)(2)) — the statute carves the provider's responsibility around the vendor's black box without saying who carries the residue.",
      "instrument_notes": null,
      "roles": [
        "healthcare-provider",
        "deployer",
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://webserver.rilegislature.gov/PublicLaws/law26/law26374.htm",
        "locator": "R.I. Gen. Laws §§ 40.1-5.5-2(1), 40.1-5.5-2(6), 40.1-5.5-2(8), 40.1-5.5-2(9), 40.1-5.5-3(b), 40.1-5.5-3(c), 40.1-5.5-3(d), 40.1-5.5-5(c)",
        "citation": "R.I. Gen. Laws ch. 40.1-5.5 (P.L. 2026 ch. 374)"
      },
      "of": {
        "term": "https://everyailaw.com/term/rhode-island-ai-mental-health-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/rhode-island-ai-mental-health-oversight-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-22",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "rhode-island-healthcare-ai-notice-review",
      "regulation": "rhode-island-healthcare-ai-notice",
      "name": "AI Visit Documentation Notice and Review",
      "requirements": [
        {
          "requirement": "Patient notification",
          "details": "Healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits must notify patients of the use of AI for that sole purpose (§ 23-108-3)"
        },
        {
          "requirement": "Review after each visit",
          "details": "The same providers and facilities must review the AI-generated documentation for accuracy after the visit (§ 23-108-3)"
        }
      ],
      "penalties": [
        {
          "violation": "Not specified",
          "fine": "The chapter specifies no fine schedule, express private right of action, or named enforcement authority. Whether other licensing or liability provisions apply is not established by this chapter alone"
        }
      ],
      "scope": "All healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits. \"Healthcare provider\" covers physicians, physician assistants, dentists, registered nurses, licensed practical nurses, advanced practice registered nurses, nursing assistants, and any other healthcare professional licensed by the director of the department of health; \"healthcare facility\" takes the meaning in § 23-17-2. \"Artificial intelligence\" is defined expansively as any technology that can simulate human intelligence, including natural language processing, training language models, RLHF, and machine learning systems (§ 23-108-2)",
      "context": "The chapter links two duties for healthcare providers and facilities using AI to document in-person or telehealth visits: notify patients of that documentation use and review the resulting documentation for accuracy after the visit. The phrase \"for that sole purpose\" describes the documentation use; this chapter does not establish duties for diagnosis or triage. Section 23-108-3 requires review, without specifying an attestation step. The linked duties are modelled as one provision.",
      "instrument_notes": null,
      "roles": [
        "healthcare-provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://webserver.rilegislature.gov/PublicLaws/law26/law26372.htm",
        "locator": "R.I. Gen. Laws §§ 23-108-2, 23-108-3",
        "citation": "R.I. Gen. Laws ch. 23-108 (P.L. 2026 ch. 372)"
      },
      "of": {
        "term": "https://everyailaw.com/term/rhode-island-healthcare-ai-notice-review.json",
        "obligations": [
          "https://everyailaw.com/obligation/rhode-island-healthcare-ai-notice-review-transparency.json",
          "https://everyailaw.com/obligation/rhode-island-healthcare-ai-notice-review-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-22",
        "verified": "2026-09-29",
        "checked": "2026-09-29",
        "instrument_last_verified": "2026-09-29",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "sg-ai-governance-explainability",
      "regulation": "sg-ai-governance-framework",
      "name": "Explainability and Transparency",
      "requirements": [
        {
          "requirement": "Explainable AI",
          "details": "Provide explanations of AI decisions appropriate to the audience"
        },
        {
          "requirement": "Transparency",
          "details": "Disclose use of AI in decision-making to affected individuals"
        },
        {
          "requirement": "Stakeholder communication",
          "details": "Proactive communication about AI use, capabilities, and limitations"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no direct penalties"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
        "locator": "Section 3: Operations Management",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/sg-ai-governance-explainability.json",
        "obligations": [
          "https://everyailaw.com/obligation/sg-ai-governance-explainability.json"
        ]
      },
      "dates": {
        "recorded_effective": "2019-01-23",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "sg-ai-governance-oversight",
      "regulation": "sg-ai-governance-framework",
      "name": "AI Governance and Human Oversight",
      "requirements": [
        {
          "requirement": "Human-in-the-loop",
          "details": "Appropriate level of human involvement based on risk and impact"
        },
        {
          "requirement": "Decision models",
          "details": "Three models: human-in-the-loop, human-on-the-loop, human-out-of-the-loop"
        },
        {
          "requirement": "Risk-proportionate",
          "details": "Level of oversight proportionate to risk of AI application"
        },
        {
          "requirement": "Agentic AI oversight",
          "details": "2026 update adds guidance for autonomous agent monitoring and intervention"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no direct penalties; organizations legally accountable for AI actions under existing law"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
        "locator": "Section 2: Decision-Making Models",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/sg-ai-governance-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/sg-ai-governance-oversight-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2019-01-23",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "sg-ai-governance-risk",
      "regulation": "sg-ai-governance-framework",
      "name": "AI Risk Management and Third-Party Oversight",
      "requirements": [
        {
          "requirement": "Internal governance",
          "details": "Establish AI governance structures and accountability"
        },
        {
          "requirement": "Risk management",
          "details": "Lifecycle risk management from design through deployment and monitoring"
        },
        {
          "requirement": "Third-party oversight",
          "details": "Assess and manage risks from AI vendor and third-party systems"
        },
        {
          "requirement": "Agentic AI risks",
          "details": "2026 update covers system design, deployment safeguards, monitoring, and end-user responsibility"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Voluntary — no direct penalties"
        }
      ],
      "scope": "providers, deployers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
        "locator": "Section 1: Internal Governance, Section 4: Stakeholder Interaction",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/sg-ai-governance-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/sg-ai-governance-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2019-01-23",
        "verified": "2026-03-26",
        "checked": "2026-03-26",
        "instrument_last_verified": "2026-03-26",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "sv-ai-promotion-act-conformity-assessment",
      "regulation": "sv-ai-promotion-act",
      "name": "ANIA Registration",
      "requirements": [
        {
          "requirement": "Mandatory operator registration",
          "details": "Before deployment, operators must register systems that meet the consequential-decision criteria and are used in one of the six listed sectors (Resolution Arts. 11-13)"
        },
        {
          "requirement": "Registration submission",
          "details": "Identify the applicant and contact, describe the AI activity and deployment context, confirm alignment with the Law's ethical principles, identify the triggering use, and summarize controls and the selected compliance path (Resolution Art. 13)"
        },
        {
          "requirement": "Express exclusions",
          "details": "General-purpose providers, infrastructure and development tools, controlled research or testing and personal use, training-phase systems, and ordinary consumer or productivity software are excluded unless later deployed for an Article 11 use (Resolution Art. 12)"
        },
        {
          "requirement": "Sector controls",
          "details": "Covered operators must implement proportionate security, incident-response procedures, and regular performance and impact review, demonstrating compliance through a recognized third-party certification or ANIA sandbox participation (Resolution Art. 14)"
        },
        {
          "requirement": "Voluntary safeguards registration",
          "details": "Entities may register voluntarily to obtain recognition for the Law's Article 19 safeguards (Resolution Art. 11)"
        }
      ],
      "penalties": [],
      "scope": "Operators deploying AI for consequential decisions in health, finance or insurance, public-space biometrics, public powers or government services, employment, or education and professional licensing in El Salvador. Other entities may register voluntarily for Article 19 safeguards",
      "context": "Resolution No. 0001/2025 creates two tracks: voluntary registration for entities seeking the Law's Article 19 safeguards, and mandatory registration for operators deploying consequential-decision AI in six listed sectors. General-purpose model, API, platform, and cloud providers are not required to register solely because they supply those services; developers register only if they also operate a covered deployment. Existing covered systems received a 12-month grace period from the Resolution's effective date.\n\nPenalties qualification: Specific penalty amounts are not stated in the Resolution. ANIA ordinarily proceeds through education, at least 60 days to remediate, formal notice, and a compliance order before referral; emergency action is reserved for a clear and imminent risk of serious harm (Resolution Art. 28).",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://asamblea.gob.sv/leyes-y-decretos/view/6137",
        "locator": "Law Arts. 16, 19; Resolution No. 0001/2025 Arts. 11-14, 29",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/sv-ai-promotion-act-conformity-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/sv-ai-promotion-act-conformity-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-09-02",
        "verified": "2026-09-01",
        "checked": "2026-09-01",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "sv-ai-promotion-act-risk-assessment",
      "regulation": "sv-ai-promotion-act",
      "name": "High-Risk AI Impact Assessment",
      "requirements": [
        {
          "requirement": "Algorithmic impact assessment",
          "details": "Systems subject to mandatory registration must identify risks to affected people, assess likelihood and severity, document sector-appropriate mitigation and monitoring, and include bias testing and an equity assessment (Resolution Arts. 10(e), 15)"
        },
        {
          "requirement": "Sector controls",
          "details": "Covered operators must use proportionate security measures, incident-response procedures, and regular performance and impact review (Resolution Art. 14)"
        },
        {
          "requirement": "Compliance paths",
          "details": "Operators may use annual self-certification against ANIA-recognized standards, approved third-party certification, or participation in the ANIA sandbox (Resolution Art. 16)"
        },
        {
          "requirement": "Verification approach",
          "details": "ANIA may request evidence of implemented controls and prioritizes education and assistance over punitive action (Resolution Art. 17)"
        },
        {
          "requirement": "Data-triggered risk framework",
          "details": "The Law's Article 17 requirements are mandatory for systems handling confidential, reserved, or personal data"
        }
      ],
      "penalties": [],
      "scope": "Operators of systems subject to mandatory registration under Resolution Article 11; the Law separately makes its risk-framework requirements mandatory for systems handling confidential, reserved, or personal data",
      "context": "Law Article 17 makes the ANIA risk-framework requirements mandatory only for systems handling data classified as confidential, reserved, or personal. Resolution Articles 10 and 15 additionally require an algorithmic impact assessment for systems subject to mandatory registration because of a covered consequential-decision deployment.\n\nPenalties qualification: Subject to ANIA's general enforcement powers. Specific penalty amounts not confirmed in available sources.",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://asamblea.gob.sv/leyes-y-decretos/view/6137",
        "locator": "Law Art. 17; Resolution No. 0001/2025 Arts. 10, 14-17",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/sv-ai-promotion-act-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/sv-ai-promotion-act-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-09-02",
        "verified": "2026-09-01",
        "checked": "2026-09-01",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "sv-ai-promotion-act-transparency",
      "regulation": "sv-ai-promotion-act",
      "name": "Algorithmic Transparency",
      "requirements": [
        {
          "requirement": "Decision notice",
          "details": "Give clear, understandable notice when AI participated in a covered adverse decision made without meaningful human review (Resolution Art. 24)"
        },
        {
          "requirement": "Notice contents",
          "details": "Confirm AI participation, explain the role AI played, and provide a mechanism to contest the decision (Resolution Art. 24)"
        },
        {
          "requirement": "Review pathway",
          "details": "The Law requires a mechanism to contest the decision before a competent natural person who can confirm, modify, or revoke it; ANIA may issue nonbinding sector guidance on meaningful human review (Law Art. 18; Resolution Art. 26)"
        },
        {
          "requirement": "Exceptions",
          "details": "Notice is not required where disclosure would undermine fraud controls, cybersecurity, vulnerability assessment, law enforcement, regulatory compliance, national security, or legitimate security controls, or for specified content-recommendation, search, advertising, and basic productivity functions (Resolution Art. 25)"
        }
      ],
      "penalties": [],
      "scope": "Entities using AI without meaningful human review to make a decision that adversely affects a person's rights or economic situation in health, financial services, employment, education, government benefits and services, housing, or transport and mobility in El Salvador",
      "context": "The Resolution narrows the Law's general decision-notice language to adverse decisions made without meaningful human review in seven listed domains. The notice duty applies whether or not the entity is registered, subject to Article 25 exceptions.\n\nPenalties qualification: Subject to ANIA's general enforcement powers. Specific penalty amounts not confirmed in available sources.",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://asamblea.gob.sv/leyes-y-decretos/view/6137",
        "locator": "Law Art. 18; Resolution No. 0001/2025 Arts. 24-26",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/sv-ai-promotion-act-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/sv-ai-promotion-act-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-09-02",
        "verified": "2026-09-01",
        "checked": "2026-09-01",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "texas-traiga-bias",
      "regulation": "texas-traiga",
      "name": "AI Discrimination Prohibition",
      "requirements": [
        {
          "requirement": "Intentional discrimination prohibited",
          "details": "No person may develop or deploy an AI system with **intent** to unlawfully discriminate against a protected class"
        },
        {
          "requirement": "Disparate impact insufficient",
          "details": "Disparate impact alone does not establish intent to discriminate (§ 552.056(c))"
        },
        {
          "requirement": "Subtitle applicability alternatives",
          "details": "Subtitle D applies only to a person who promotes, advertises, or conducts business in Texas; produces a product or service used by Texas residents; or develops or deploys an AI system in Texas (§ 551.002)"
        },
        {
          "requirement": "Insurance-services exception",
          "details": "Section 552.056 does not apply to an insurance entity **for purposes of providing insurance services** if it is subject to the specified laws governing unfair discrimination, competition, or deceptive practices in insurance. “Insurance entity” includes the developer of an artificial intelligence system used by a listed insurer or fraternal benefit society (§ 552.056(a)(2), (d))"
        },
        {
          "requirement": "Banking compliance rule",
          "details": "A federally insured financial institution is considered compliant with § 552.056 only if it complies with **all federal and state banking laws and regulations** (§ 552.056(e))"
        },
        {
          "requirement": "Exclusive enforcement and no private action",
          "details": "The attorney general has exclusive Chapter 552 enforcement authority except for the qualified state-agency route in § 552.106; Chapter 552 supplies no private right of action (§ 552.101)"
        },
        {
          "requirement": "Notice and 60-day cure",
          "details": "The attorney general may not sue before the **60th day** after written notice and may not sue if, before that day, the person actually cures, provides a written statement with supporting documentation showing how it cured, and makes necessary changes to internal policies to reasonably prevent recurrence (§ 552.104)"
        },
        {
          "requirement": "Uncured civil penalties",
          "details": "For an uncured violation, § 552.105(a) sets $10,000–$12,000 for each curable violation or breach of a cure statement, $80,000–$200,000 for each uncurable violation, and $2,000–$40,000 for each day a violation continues"
        },
        {
          "requirement": "Qualified liability defenses",
          "details": "A defendant may not be found liable under § 552.105(e) for another person’s prohibited use of its affiliated system. The discovery alternatives are separate: the defendant discovers a violation through feedback; through testing, including adversarial or red-team testing; by following applicable state-agency guidelines; **or through an internal review process if the defendant substantially complies** with the current NIST Generative AI Profile or another recognized AI risk-management framework. The framework-compliance condition belongs only to the internal-review route, and it is not blanket immunity"
        },
        {
          "requirement": "Undeployed-system civil-penalty limit",
          "details": "The attorney general may not bring an action to collect a § 552.105 civil penalty for an AI system that has not been deployed (§ 552.105(f))"
        },
        {
          "requirement": "Qualified state-agency sanctions",
          "details": "A state agency may sanction a person licensed, registered, or certified by that agency only after the person has been found in violation in a § 552.105 court action and the attorney general recommends added agency enforcement. Sanctions may include suspension, probation, or revocation of a license, registration, certificate, or other authorization, plus a monetary penalty not to exceed $100,000 (§ 552.106)"
        }
      ],
      "penalties": [
        {
          "violation": "Curable violation or cure-statement breach, uncured",
          "fine": "$10,000–$12,000 for each violation (§ 552.105(a)(1))"
        },
        {
          "violation": "Uncurable violation",
          "fine": "$80,000–$200,000 for each violation (§ 552.105(a)(2))"
        },
        {
          "violation": "Continued violation",
          "fine": "$2,000–$40,000 for each day (§ 552.105(a)(3))"
        },
        {
          "violation": "Qualified state-agency sanction",
          "fine": "Up to $100,000, only after a § 552.105 violation finding and attorney-general recommendation (§ 552.106)"
        }
      ],
      "scope": "A person who promotes, advertises, or conducts business in Texas; produces a product or service used by Texas residents; or develops or deploys an AI system in Texas (§ 551.002). Within that subtitle scope, § 552.056 applies to a person developing or deploying an AI system with the prohibited intent, subject to the insurance and banking qualifications below",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://tcss.legis.texas.gov/resources/BC/pdf/BC.552.pdf",
        "locator": "Texas Business & Commerce Code § 551.002; §§ 552.056, 552.101, 552.104–.106",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/texas-traiga-bias.json",
        "obligations": [
          "https://everyailaw.com/obligation/texas-traiga-bias-bias-prevention.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-01",
        "verified": "2026-04-27",
        "checked": "2026-08-16",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "tw-ai-basic-act-risk",
      "regulation": "tw-ai-basic-act",
      "name": "Government AI Governance Framework",
      "requirements": [
        {
          "requirement": "Risk taxonomy",
          "details": "The Ministry of Digital Affairs must promote an AI risk taxonomy and assessment framework interoperable with international standards, and assist sectoral authorities in establishing risk-based management regulations (Article 16(1))"
        },
        {
          "requirement": "Sectoral rulemaking",
          "details": "Sectoral competent authorities must establish risk-based management regulations following that taxonomy and assist their industries in formulating guidelines and codes of conduct (Article 16(2))"
        },
        {
          "requirement": "High-risk liability",
          "details": "For high-risk AI applications, the government must clarify liability attribution and conditions and establish relief, compensation, or insurance mechanisms; this does not reach pre-application R&D unless tested in a real-world environment or used to provide products or services (Article 17)"
        },
        {
          "requirement": "Conforming legal review",
          "details": "Within two years of the effective date, the government must complete the enactment, amendment, or repeal of non-conforming laws, regulations, and administrative measures (Article 18)"
        },
        {
          "requirement": "Government use assessment",
          "details": "When using AI to perform duties or provide services, the government must conduct risk assessments, plan response measures, and establish usage guidelines or internal control mechanisms (Article 19)"
        },
        {
          "requirement": "Data protection by design",
          "details": "Sectoral authorities, consulting the personal data protection authority, must avoid unnecessary collection, processing, or use of personal data in AI R&D and application and promote data protection by design and by default (Article 14)"
        }
      ],
      "penalties": [
        {
          "violation": "None",
          "fine": "The Act contains no penalty provision. It directs government action and carries no sanction against private parties"
        }
      ],
      "scope": "Government bodies. The Ministry of Digital Affairs must promote an internationally interoperable AI risk taxonomy and assessment framework (Art. 16(1)); sectoral competent authorities must then establish risk-based management regulations and assist their industries in producing guidelines and codes of conduct (Art. 16(2)); the government must conduct risk assessments before using AI to perform duties or provide services (Art. 19). The Act imposes no direct compliance duty on private-sector developers or deployers — obligations reach industry only once a sectoral regulator issues rules under Article 16(2)",
      "context": "A framework act, not a compliance statute. Every operative article directs the state: fund AI development (Arts. 9-10), open government data (Art. 13), protect labour rights (Art. 15), clarify high-risk liability and establish relief or insurance mechanisms (Art. 17), and review all conflicting law within two years (Art. 18). Private-sector obligations arrive later and indirectly, through whatever sectoral regulators issue under Article 16(2) — which is what makes the two-year Article 18 deadline of 2028-01-14 the date to watch. **Open scope question:** on a strict reading of exclusion principle E4 (wrong audience), this Act may belong in `data/exclusions.md` rather than as a tracked instrument, since it creates no private-sector duty. It is retained for now because it is the enabling frame for every future Taiwanese AI rule; revisit when the first Article 16(2) sectoral regulations appear.",
      "instrument_notes": null,
      "roles": [
        "government"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=H0160093",
        "locator": "Articles 16, 17, 18, 19",
        "citation": "人工智慧基本法 (Artificial Intelligence Basic Act), 20 articles"
      },
      "of": {
        "term": "https://everyailaw.com/term/tw-ai-basic-act-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/tw-ai-basic-act-risk-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-14",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "uk-dpa-2018-adm-human-oversight",
      "regulation": "uk-dpa-2018-adm",
      "name": "Automated Decision-Making Rights (Articles 22A-22D UK GDPR)",
      "requirements": [
        {
          "requirement": "ADM definition",
          "details": "Art. 22A(1): a decision is based solely on automated processing where there is no meaningful human involvement; it is a significant decision where it produces a legal effect or a similarly significant effect for the data subject"
        },
        {
          "requirement": "Role of profiling",
          "details": "Art. 22A(2): when assessing whether human involvement is meaningful, the extent to which the decision is reached by profiling must be considered — profiling is a factor in the test, not part of the definition"
        },
        {
          "requirement": "Special category restriction",
          "details": "Art. 22B(1)-(3): a significant decision based wholly or partly on Article 9(1) special category data may not be taken solely automatically unless the data subject gave explicit consent, or the decision is necessary for a contract or required by law and Article 9(2)(g) applies"
        },
        {
          "requirement": "Recognised legitimate interests bar",
          "details": "Art. 22B(4): a significant decision may not be taken solely automatically where the processing relies wholly or partly on Article 6(1)(ea)"
        },
        {
          "requirement": "Required safeguards",
          "details": "Art. 22C(1)-(2): where a significant decision is based on personal data and taken solely automatically, the controller must have safeguards that provide information about the decision, enable representations, enable human intervention on the controller's part, and enable the decision to be contested"
        },
        {
          "requirement": "Secretary of State powers",
          "details": "Art. 22D: regulations may define when human involvement is or is not meaningful, what counts as a similarly significant effect, and may add to the Art. 22C safeguards, but may not amend Art. 22C; subject to the affirmative resolution procedure"
        },
        {
          "requirement": "Law-enforcement analogue out of scope",
          "details": "The lettered ADM sections in the DPA 2018 itself — ss. 50A-50D (Part 3, law-enforcement processing) and s. 96 (Part 4, intelligence services) — are separate regimes and do not apply to the deployers covered here; s. 14 remains the Part 2 safeguard provision for decisions required or authorised by law"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Up to GBP 17.5M or 4% global turnover"
        }
      ],
      "scope": "Controllers taking significant decisions based solely on automated processing of personal data under Articles 22A-22C UK GDPR",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.gov.uk/ukpga/2018/12/contents",
        "locator": "Articles 22A-22D UK GDPR; DPA 2018 s.14",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/uk-dpa-2018-adm-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/uk-dpa-2018-adm-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-02-05",
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "uk-dpa-2018-adm-transparency",
      "regulation": "uk-dpa-2018-adm",
      "name": "Transparency in Automated Processing",
      "requirements": [
        {
          "requirement": "Logic disclosure",
          "details": "Arts. 13(2)(f) and 14(2)(g): controllers must disclose the existence of automated decision-making, including profiling, that is subject to the Art. 22C safeguard requirement, and at least in those cases provide meaningful information about the logic involved"
        },
        {
          "requirement": "Significance and consequences",
          "details": "The same provisions require the significance and the envisaged consequences of the processing for the data subject to be given"
        },
        {
          "requirement": "Point of disclosure",
          "details": "Art. 13 applies where data is collected from the data subject; Art. 14 where it is obtained from another source"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Up to GBP 17.5M or 4% global turnover"
        }
      ],
      "scope": "Controllers collecting personal data from a data subject or another source where processing includes automated decision-making subject to Article 22C safeguards (Articles 13-14 UK GDPR)",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.gov.uk/ukpga/2018/12/contents",
        "locator": "Articles 13-14 UK GDPR",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/uk-dpa-2018-adm-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/uk-dpa-2018-adm-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2018-05-25",
        "verified": "2026-08-01",
        "checked": "2026-08-01",
        "instrument_last_verified": "2026-08-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "uk-osa-risk-assessment",
      "regulation": "uk-online-safety-act",
      "name": "Risk Assessment for AI Systems",
      "requirements": [
        {
          "requirement": "Illegal content risk assessment",
          "details": "Carry out a suitable and sufficient assessment of risks of users encountering priority or other illegal content, considering service algorithms and dissemination; keep it current and reassess before significant service changes (s. 9)."
        },
        {
          "requirement": "Children's risk assessment",
          "details": "If the service is likely to be accessed by children, assess the statutory categories of harmful content and relevant design or algorithmic risk factors; keep the assessment current and reassess before significant service changes (s. 11)."
        },
        {
          "requirement": "Assessment record",
          "details": "Make and keep the required written record of each risk assessment (s. 23(2)). Safety mitigation duties are separately in ss. 10 and 12."
        }
      ],
      "penalties": [
        {
          "violation": "Applicable regulated-service breach",
          "fine": "Sch. 13 para. 4 sets the applicable maximum at the greater of GBP 18M or 10% of qualifying worldwide revenue, subject to its qualifications."
        }
      ],
      "scope": "Providers of regulated user-to-user services with UK links; the children's assessment duty applies only where children are likely to access the service",
      "context": "Part 3 Chapter 2 duties cover regulated user-to-user services, regardless of whether AI generated the content. The parallel search-service duties sit in Chapter 3 (ss. 26, 28). Both sections commenced 10 Jan 2024 (S.I. 2023/1420, reg. 2(c), (d)); Ofcom compliance deadlines fell later.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.gov.uk/ukpga/2023/50/contents",
        "locator": "Section 9 (illegal content risk assessment duties), Section 11 (children's risk assessment duties)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/uk-osa-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/uk-osa-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-01-10",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "uk-osa-risk-assessment-search",
      "regulation": "uk-online-safety-act",
      "name": "Risk Assessment for Search Services",
      "requirements": [
        {
          "requirement": "Illegal content risk assessment",
          "details": "Suitable and sufficient assessment of the risk of users encountering priority and other illegal content in search content, taking into account risks presented by the service's algorithms and by how it indexes, organises and presents results (s.26(2), (5)(a))"
        },
        {
          "requirement": "Children's risk assessment",
          "details": "Where the service is likely to be accessed by children, a further assessment covering primary priority, priority and non-designated content harmful to children, with separate consideration by age group and explicit assessment of predictive search functionality (s.28(2), (5)(a), (5)(c))"
        },
        {
          "requirement": "Keep assessments current",
          "details": "Duty to keep each assessment up to date, including when Ofcom significantly changes an applicable risk profile (ss.26(3), 28(3))"
        },
        {
          "requirement": "Reassess before significant change",
          "details": "Further assessment before any significant change to the design or operation of the service, covering the impacts of that change (ss.26(4), 28(4))"
        },
        {
          "requirement": "Assessment timing",
          "details": "Assessments carried out at the times set out in Schedule 3"
        },
        {
          "requirement": "Records",
          "details": "Records of risk assessments kept under s.34(2) and (9)"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Greater of GBP 18M or 10% of qualifying worldwide revenue (Sch. 13 para. 4)"
        }
      ],
      "scope": "providers of regulated search services, and providers of combined services in respect of the search engine",
      "context": "Part 3 Chapter 3 covers search-specific risks: s. 26(5)(a) names algorithms, indexing, organisation and presentation of results, and s. 28(5)(c) names predictive search functionality. These are functionality factors, not an AI-origin trigger. Both sections commenced 10 Jan 2024 (S.I. 2023/1420, reg. 2(j)).",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.gov.uk/ukpga/2023/50/contents",
        "locator": "Section 26 (illegal content risk assessment duties), Section 28 (children's risk assessment duties), Schedule 3 (timing of providers' assessments)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/uk-osa-risk-assessment-search.json",
        "obligations": [
          "https://everyailaw.com/obligation/uk-osa-risk-assessment-search-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-01-10",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "uk-osa-transparency",
      "regulation": "uk-online-safety-act",
      "name": "AI-Generated Content Duties",
      "requirements": [
        {
          "requirement": "Illegal content",
          "details": "Regulated user-to-user providers must assess and address illegal content under ss. 9-10; regulated search providers have corresponding duties under ss. 26-27. An AI-generated item falls within those duties only where it is in the Act's regulated user-generated or search-content scope and meets the applicable illegal-content trigger (ss. 55, 57)."
        },
        {
          "requirement": "Children's safety",
          "details": "The additional assessment and safety duties in ss. 11-12 and 28-29 apply to regulated services likely to be accessed by children, according to the statutory content categories."
        },
        {
          "requirement": "AI-service extension",
          "details": "Section 216A authorizes regulations that could extend corresponding duties to providers of AI services for illegal AI-generated content or priority-offence use. The power alone does not impose those duties."
        },
        {
          "requirement": "Transparency reports",
          "details": "Under s. 77, providers of Category 1, 2A or 2B relevant services produce a report in response to OFCOM's annual notice, with the specified information, format and deadlines. It is not a universal annual AI-content report."
        }
      ],
      "penalties": [
        {
          "violation": "Applicable regulated-service breach",
          "fine": "Where OFCOM can impose a monetary penalty for an applicable requirement, Sch. 13 para. 4 sets the maximum at the greater of GBP 18M or 10% of qualifying worldwide revenue for the relevant accounting period, subject to its qualifications."
        }
      ],
      "scope": "Providers of regulated user-to-user or regulated search services with UK links; duties vary by service category and whether children are likely to access the service",
      "context": "The saved heading identifies an AI-related application of the Act, but Part 3 duties turn on regulated service and in-scope content risk, not on AI origin alone. Section 55 distinguishes user-generated content, including user-applied software and qualifying bots, from provider content; s. 57 defines search content and its exclusions. Section 216A permits later regulations extending duties to AI services; it imposes no such duty by itself.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislation.gov.uk/ukpga/2023/50/contents",
        "locator": "Part 3 ss. 4, 7, 9-12, 24, 26-29, 55, 57, 77; Sch. 8; s. 216A (regulation-making power)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/uk-osa-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/uk-osa-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-01-10",
        "verified": "2026-08-15",
        "checked": "2026-08-15",
        "instrument_last_verified": "2026-08-15",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-14319-data-governance",
      "regulation": "us-eo-14319",
      "name": "Training Data and Risk Governance for Federal AI",
      "requirements": [
        {
          "requirement": "Data provenance",
          "details": "Training data sources and provenance must be documented and disclosed to procuring agency"
        },
        {
          "requirement": "Risk documentation",
          "details": "Vendors must document risks, limitations, and mitigations for LLM systems"
        },
        {
          "requirement": "Compliance verification",
          "details": "Agencies must have sufficient documentation to assess vendor compliance with Unbiased AI Principles"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Contract termination; vendors accountable for certain costs"
        }
      ],
      "scope": "Vendors supplying large language models to United States executive departments and agencies under covered federal procurements",
      "context": "Vendors must disclose training data provenance, limitations, and risk mitigations as a condition of federal procurement. While framed as ensuring \"unbiased AI,\" the practical effect is a data governance disclosure requirement for the federal AI supply chain.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://whitehouse.gov/presidential-actions/2025/07/preventing-woke-ai-in-the-federal-government/",
        "locator": "EO 14319 § 4; OMB M-26-04",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-14319-data-governance.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-14319-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-12-11",
        "verified": "2026-03-27",
        "checked": "2026-08-06",
        "instrument_last_verified": "2026-08-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-14319-procurement-transparency",
      "regulation": "us-eo-14319",
      "name": "LLM Procurement Documentation Requirements",
      "requirements": [
        {
          "requirement": "Model/data cards",
          "details": "Vendors must provide model, system, and/or data cards detailing capabilities, limitations, risks, and mitigations"
        },
        {
          "requirement": "Training data provenance",
          "details": "Vendors must disclose training data provenance information"
        },
        {
          "requirement": "Acceptable use policy",
          "details": "Vendors must provide acceptable use policy documentation"
        },
        {
          "requirement": "Inappropriate use cases",
          "details": "Vendors must disclose inappropriate use cases"
        },
        {
          "requirement": "End-user resources",
          "details": "Vendors must provide end-user resources and feedback mechanisms"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Contract termination; vendors accountable for certain costs if terminated due to non-compliance"
        }
      ],
      "scope": "Vendors supplying large language models to United States executive departments and agencies under covered federal procurements",
      "context": "Creates de facto compliance obligations for any AI vendor selling LLMs to the US federal government. Agencies must require vendor documentation including model cards, data cards, acceptable use policies, and risk disclosures. Agencies must reject non-compliant models. Not branded as AI regulation, but effectively mandates transparency for a significant market segment.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://whitehouse.gov/presidential-actions/2025/07/preventing-woke-ai-in-the-federal-government/",
        "locator": "EO 14319 § 4; OMB M-26-04",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-14319-procurement-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-14319-procurement-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-12-11",
        "verified": "2026-03-27",
        "checked": "2026-08-07",
        "instrument_last_verified": "2026-08-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-14319-risk-assessment",
      "regulation": "us-eo-14319",
      "name": "Unbiased AI Principles Compliance",
      "requirements": [
        {
          "requirement": "Truth-seeking principle",
          "details": "LLMs must be truthful in responding to prompts seeking factual information or analysis, prioritize historical accuracy, scientific inquiry, and objectivity, and acknowledge uncertainty where reliable information is incomplete or contradictory (§ 3(a))"
        },
        {
          "requirement": "Ideological neutrality principle",
          "details": "LLMs must be neutral, nonpartisan tools; developers must not intentionally encode partisan or ideological judgments unless prompted by or readily accessible to the end user (§ 3(b))"
        },
        {
          "requirement": "Compliance procedures",
          "details": "Agencies must adopt procedures within 90 days of the OMB guidance to ensure procured LLMs comply with the Unbiased AI Principles (§ 4(b)(iii))"
        },
        {
          "requirement": "Contract terms",
          "details": "New LLM contracts must require compliance and charge decommissioning costs to a vendor terminated for noncompliance after a reasonable cure period; existing contracts revised where practicable (§ 4(b)(i)-(ii))"
        }
      ],
      "penalties": [
        {
          "violation": "Non-compliance",
          "fine": "Contract termination with cost accountability for vendors"
        }
      ],
      "scope": "Vendors supplying large language models to United States executive departments and agencies under covered federal procurements",
      "context": "Establishes two Unbiased AI Principles — truth-seeking and ideological neutrality — that federal LLM procurements must comply with. Agencies must adopt procedures to enforce compliance and hold vendors accountable. Effectively creates a content-level compliance standard for the federal market.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://whitehouse.gov/presidential-actions/2025/07/preventing-woke-ai-in-the-federal-government/",
        "locator": "EO 14319 §§ 3-4; OMB M-26-04",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-14319-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-14319-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-07-23",
        "verified": "2026-08-25",
        "checked": "2026-08-25",
        "instrument_last_verified": "2026-08-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-ai-innovation-security-conformity-assessment",
      "regulation": "us-eo-ai-innovation-security",
      "name": "Voluntary Frontier Model Pre-Release Government Access",
      "requirements": [
        {
          "requirement": "Voluntary pre-release access",
          "details": "Participating developers may provide the federal government access to covered frontier models for up to 30 days before planned release"
        },
        {
          "requirement": "Confidentiality protections",
          "details": "Access is subject to confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements"
        },
        {
          "requirement": "Trusted-partner sequencing",
          "details": "Designated covered frontier models receive government evaluation before access is extended to other trusted partners"
        }
      ],
      "penalties": [
        {
          "violation": "N/A",
          "fine": "Voluntary framework; no penalties. Section 3(c) disclaims mandatory licensing/preclearance/permitting; general provisions create no enforceable rights."
        }
      ],
      "scope": "AI industry participants, open-source software partners, and critical-infrastructure operators participating in GOLD EAGLE vulnerability coordination",
      "context": "Establishes a voluntary framework under which frontier developers may engage the government to have models designated \"covered frontier models\" and provide up to 30 days of pre-release access for evaluation before other trusted partners. The framework itself does not yet exist — Treasury, NSA, and CISA must design it within 60 days. Section 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement, so participation is opt-in. Worth watching: a voluntary pre-release evaluation regime can harden into a de facto procurement or trusted-vendor expectation.",
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/",
        "locator": "EO § 3(b)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-ai-innovation-security-conformity-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-ai-innovation-security-conformity-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-02",
        "verified": "2026-06-18",
        "checked": "2026-08-05",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-ai-innovation-security-incident-reporting",
      "regulation": "us-eo-ai-innovation-security",
      "name": "AI Cybersecurity Clearinghouse for Vulnerability Coordination",
      "requirements": [
        {
          "requirement": "Vulnerability intake and prioritization",
          "details": "GOLD EAGLE receives identified cybersecurity vulnerabilities from across industries and sectors and prioritizes action"
        },
        {
          "requirement": "Coordinated scanning verification",
          "details": "Government and industry coordinate scanning verification and reduce duplicative scanning"
        },
        {
          "requirement": "Remediation information",
          "details": "GOLD EAGLE distributes prioritized and actionable threat and remediation information to federal and private-sector defenders"
        },
        {
          "requirement": "Patch coordination",
          "details": "Open-source software and critical-infrastructure participants coordinate to receive and patch vulnerabilities"
        }
      ],
      "penalties": [
        {
          "violation": "N/A",
          "fine": "Voluntary collaboration; no penalties. General provisions create no enforceable rights."
        }
      ],
      "scope": "providers",
      "context": "The White House launched the clearinghouse as GOLD EAGLE on 2026-07-14. Open-source software partners and critical-infrastructure companies built the coordinated system, which had already begun receiving and prioritizing vulnerabilities from across sectors, coordinating scanning verification, and distributing prioritized threat and remediation information. Participation remains voluntary and creates no reporting mandate.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/",
        "locator": "EO § 2(d)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-ai-innovation-security-incident-reporting.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-ai-innovation-security-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-02",
        "verified": "2026-09-01",
        "checked": "2026-09-01",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-ai-innovation-security-risk-assessment",
      "regulation": "us-eo-ai-innovation-security",
      "name": "Covered Frontier Model Designation and Benchmarking",
      "requirements": [
        {
          "requirement": "Classified benchmarking",
          "details": "Government to develop and maintain a classified process benchmarking the advanced cyber capabilities of AI models"
        },
        {
          "requirement": "Threshold designation",
          "details": "The benchmark sets the threshold at which a model is designated a \"covered frontier model\""
        },
        {
          "requirement": "Assessment sharing",
          "details": "Capability assessments are shared with AI developers as appropriate"
        }
      ],
      "penalties": [
        {
          "violation": "N/A",
          "fine": "Voluntary designation; no penalties. Designation does not trigger any mandatory licensing or permitting (§ 3(c))."
        }
      ],
      "scope": "providers",
      "context": "Directs Treasury, NSA, and CISA to develop and maintain a classified benchmarking process that assesses the advanced cyber capabilities of AI models and sets the threshold for designating a \"covered frontier model.\" This is the first federal mechanism defining a frontier-model threshold by capability rather than compute. Developers engage the designation process voluntarily; assessments are shared with developers as appropriate. The benchmark and threshold are pending — agencies have 60 days to develop them.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "voluntary",
      "source": {
        "url": "https://whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/",
        "locator": "EO § 3(a)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-ai-innovation-security-risk-assessment.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-ai-innovation-security-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-02",
        "verified": "2026-06-18",
        "checked": "2026-08-10",
        "instrument_last_verified": "2026-09-01",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-ai-preemption-evaluation",
      "regulation": "us-eo-ai-preemption",
      "name": "Commerce Evaluation of State AI Laws",
      "requirements": [
        {
          "requirement": "State law evaluation",
          "details": "Commerce must publish an evaluation of existing state AI laws within 90 days identifying \"onerous laws that conflict\" with the § 2 policy and laws to refer to the § 3 Task Force; at minimum it must identify laws requiring AI models to alter truthful outputs or compelling disclosure in a manner violating the First Amendment (§ 4)"
        },
        {
          "requirement": "BEAD funding restriction",
          "details": "Commerce, through NTIA, must issue within 90 days a BEAD Policy Notice providing that states with onerous AI laws identified under § 4 are ineligible for **non-deployment** funds, to the maximum extent allowed by federal law (§ 5(a))"
        },
        {
          "requirement": "Discretionary grant conditioning",
          "details": "Agencies must assess whether their discretionary grant programs may be conditioned on states not enacting conflicting AI laws, or on a binding non-enforcement agreement for states that already have them (§ 5(b))"
        },
        {
          "requirement": "FCC proceeding",
          "details": "FCC Chairman must initiate a proceeding, within 90 days of the § 4 evaluation, on whether to adopt a federal AI reporting and disclosure standard preempting conflicting state laws (§ 6)"
        },
        {
          "requirement": "FTC preemption statement",
          "details": "FTC Chairman must issue a policy statement within 90 days on when state laws requiring alterations to truthful AI outputs are preempted by the FTC Act's prohibition on deceptive acts or practices, 15 U.S.C. 45 (§ 7)"
        }
      ],
      "penalties": [
        {
          "violation": "N/A",
          "fine": "No penalties on AI companies. States identified under § 4 lose eligibility for BEAD non-deployment funds and may face conditions on agency discretionary grants."
        }
      ],
      "scope": "government (Commerce, FTC); states",
      "context": "Directs the Secretary of Commerce to evaluate existing state AI laws within 90 days and identify those that conflict with federal objectives. A companion BEAD Policy Notice (§ 5(a)) makes states with those laws ineligible for BEAD non-deployment funds — not BEAD funding as a whole — and § 5(b) extends the same leverage to agency discretionary grants. Section 7 directs the FTC to issue a policy statement on how the FTC Act preempts state laws mandating alterations to truthful AI outputs, and § 6 directs the FCC to open a proceeding on a preemptive federal reporting and disclosure standard. No direct obligations for AI developers — but the evaluation results will shape which state laws survive federal challenge.",
      "instrument_notes": null,
      "roles": [
        "government"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence",
        "locator": "EO 14365 §§ 4-5, 7",
        "citation": "90 FR 58499"
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-ai-preemption-evaluation.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-ai-preemption-evaluation-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-12-11",
        "verified": "2026-08-25",
        "checked": "2026-08-25",
        "instrument_last_verified": "2026-08-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "us-eo-ai-preemption-task-force",
      "regulation": "us-eo-ai-preemption",
      "name": "DOJ AI Litigation Task Force",
      "requirements": [
        {
          "requirement": "DOJ Task Force",
          "details": "Attorney General must establish an AI Litigation Task Force within 30 days whose sole responsibility is challenging state AI laws inconsistent with the § 2 policy (§ 3)"
        },
        {
          "requirement": "Preemption challenges",
          "details": "Task Force to challenge state laws as unconstitutional regulation of interstate commerce, preempted by federal regulation, or otherwise unlawful in the Attorney General's judgment (§ 3)"
        },
        {
          "requirement": "Legislative recommendations",
          "details": "The Special Advisor for AI and Crypto and the Assistant to the President for Science and Technology must jointly prepare a legislative recommendation for a uniform federal AI framework preempting conflicting state laws (§ 8(a))"
        }
      ],
      "penalties": [
        {
          "violation": "N/A",
          "fine": "No penalties on AI companies. States face federal litigation and potential funding restrictions for non-aligned AI laws."
        }
      ],
      "scope": "government (DOJ); states",
      "context": "Does not create compliance obligations for AI companies. Instead, directs DOJ to form a task force to challenge state AI laws on preemption, interstate commerce, and First Amendment grounds. Directly threatens enforceability of state laws tracked in this reference (Colorado SB 24-205, Illinois HB 3773, California ADS regs, NYC LL144, and others). Section 8(b) carveouts bar the legislative recommendation from proposing preemption of state laws on child safety, AI compute and data-center infrastructure (other than generally applicable permitting reforms), and state government procurement and use of AI.",
      "instrument_notes": null,
      "roles": [
        "government"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence",
        "locator": "EO 14365 §§ 3, 8",
        "citation": "90 FR 58499"
      },
      "of": {
        "term": "https://everyailaw.com/term/us-eo-ai-preemption-task-force.json",
        "obligations": [
          "https://everyailaw.com/obligation/us-eo-ai-preemption-task-force-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-12-11",
        "verified": "2026-08-25",
        "checked": "2026-08-25",
        "instrument_last_verified": "2026-08-25",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-ai-liability",
      "regulation": "utah-sb149",
      "name": "Liability for AI-Assisted Violations",
      "requirements": [
        {
          "requirement": "Civil (§13-75-102)",
          "details": "\"Not a defense\" that GenAI made the violative statement, undertook the violative act, or was used in furtherance"
        },
        {
          "requirement": "Criminal (§76-2-107)",
          "details": "Principal may be found guilty if they commit offense \"with the aid of\" or \"intentionally prompt\" GenAI to commit offense"
        }
      ],
      "penalties": [
        {
          "violation": "Civil",
          "fine": "Per underlying consumer-protection statute"
        },
        {
          "violation": "Criminal",
          "fine": "Per underlying offense — no separate penalty"
        }
      ],
      "scope": "any principal using or prompting GenAI",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2024/bills/static/SB0149.html",
        "locator": "§13-75-102 (civil), §76-2-107 (criminal)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-ai-liability.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-ai-liability-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-05-01 (criminal); 2025-05-07 (civil)",
        "verified": "2026-04-18",
        "checked": "2026-08-09",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-chatbot-data-protection",
      "regulation": "utah-sb149",
      "name": "Mental Health Chatbot Data Protection",
      "requirements": [
        {
          "requirement": "No sale/sharing",
          "details": "May not sell or share identifiable health information or user input with third parties"
        },
        {
          "requirement": "Health care exception",
          "details": "Permitted when user-consented or user-requested to health care provider or health plan"
        },
        {
          "requirement": "HIPAA-equivalent controls",
          "details": "Third-party sharing for functionality requires HIPAA Parts 160 + 164 Subparts A/E compliance as if supplier were a covered entity"
        }
      ],
      "penalties": [
        {
          "violation": "Same as chatbot disclosure",
          "fine": "$2,500 admin / court / $5,000 order violation"
        }
      ],
      "scope": "mental health chatbot suppliers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2025/bills/static/HB0452.html",
        "locator": "§13-72a-201",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-chatbot-data-protection.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-chatbot-data-protection-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-05-07",
        "verified": "2026-04-18",
        "checked": "2026-08-12",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-chatbot-disclosure",
      "regulation": "utah-sb149",
      "name": "Mental Health Chatbot Disclosure",
      "requirements": [
        {
          "requirement": "Pre-access disclosure",
          "details": "Must disclose before user may access chatbot features"
        },
        {
          "requirement": "Post-gap disclosure",
          "details": "Disclosure at start of interaction when >7 days since user's last interaction"
        },
        {
          "requirement": "On-prompt disclosure",
          "details": "Disclosure any time user asks whether AI is used"
        },
        {
          "requirement": "Carve-out",
          "details": "Scripted-only output (meditations, mindfulness) and referral-to-human-therapist bots excluded (§13-72a-101(10)(b))"
        }
      ],
      "penalties": [
        {
          "violation": "Admin",
          "fine": "Up to $2,500 per violation"
        },
        {
          "violation": "Court",
          "fine": "Up to $2,500 per violation; disgorgement; attorney fees"
        },
        {
          "violation": "Order violation",
          "fine": "Up to $5,000 per violation"
        }
      ],
      "scope": "mental health chatbot suppliers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2025/bills/static/HB0452.html",
        "locator": "§13-72a-203",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-chatbot-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-chatbot-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-05-07",
        "verified": "2026-04-18",
        "checked": "2026-08-13",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-chatbot-safety-policy",
      "regulation": "utah-sb149",
      "name": "Mental Health Chatbot Safety Policy",
      "requirements": [
        {
          "requirement": "Defense policy",
          "details": "To qualify, create, maintain and implement a written policy covering intended purposes, therapist involvement, clinical best practices, testing, risk identification, user reporting, acute-risk protocols, safety reviews, safe-use instructions, AI-awareness disclosure, engagement-over-safety prohibition, non-discrimination, HIPAA compliance"
        },
        {
          "requirement": "Documentation",
          "details": "To qualify, maintain documentation of foundation models used, training data, HIPAA compliance, user data practices, ongoing accuracy/safety efforts"
        },
        {
          "requirement": "Filing",
          "details": "To claim the defense, file the required policy and supplier/chatbot information with the Division of Consumer Protection in its required manner and pay the filing fee (§58-60-118(4)); the Division may impose an annual filing fee (§58-60-118(5)(b))"
        },
        {
          "requirement": "Compliance condition",
          "details": "To qualify, comply with all requirements of the filed policy at the time of the alleged violation (§58-60-118(2)(d))"
        },
        {
          "requirement": "Defense limits",
          "details": "The defense does not bar the Division from bringing the specified enforcement action, does not recognize a chatbot as a licensed therapist, and does not displace separate Chapter 72a consumer-protection duties (§58-60-118(6)-(7))"
        }
      ],
      "penalties": [
        {
          "violation": "Affirmative defense",
          "fine": "Limited to administrative or civil actions alleging §58-1-501(1) or (2); it does not bar the Division from bringing such an action and does not extend to separate Chapter 72a consumer-protection liability (§58-60-118(6)-(7))"
        }
      ],
      "scope": "Mental health chatbot suppliers seeking the affirmative defense to administrative or civil liability alleged under §58-1-501(1) or (2); policy/documentation/filing duties here are conditions of that defense (§58-60-118(2),(6)), not a universal supplier mandate",
      "context": "The defense does not bar an enforcement action or license a chatbot as a therapist (§58-60-118(7)); separate Chapter 72a consumer-protection duties remain applicable",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2025/bills/static/HB0452.html",
        "locator": "§58-60-118",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-chatbot-safety-policy.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-chatbot-safety-policy-record-keeping.json",
          "https://everyailaw.com/obligation/utah-sb149-chatbot-safety-policy-risk-assessment.json",
          "https://everyailaw.com/obligation/utah-sb149-chatbot-safety-policy-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-05-07",
        "verified": "2026-04-18",
        "checked": "2026-08-11",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-general-disclosure",
      "regulation": "utah-sb149",
      "name": "General GenAI Disclosure",
      "requirements": [
        {
          "requirement": "On-request disclosure",
          "details": "Must disclose AI use when consumer makes \"clear and unambiguous request\""
        },
        {
          "requirement": "Safe harbor",
          "details": "Clear + conspicuous disclosure at outset and throughout eliminates enforcement exposure (§13-75-104)"
        }
      ],
      "penalties": [
        {
          "violation": "Admin enforcement",
          "fine": "Up to $2,500 per violation"
        },
        {
          "violation": "Court enforcement",
          "fine": "Up to $2,500 per violation; disgorgement; attorney fees; investigative fees"
        },
        {
          "violation": "Order violation",
          "fine": "Up to $5,000 per violation"
        }
      ],
      "scope": "suppliers in consumer transactions",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "supplier"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2025/bills/static/SB0226.html",
        "locator": "§13-75-103(1) (general), §13-75-104 (safe harbor)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-general-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-general-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-05-07",
        "verified": "2026-04-18",
        "checked": "2026-08-13",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-high-risk-disclosure",
      "regulation": "utah-sb149",
      "name": "High-Risk GenAI Disclosure in Regulated Occupations",
      "requirements": [
        {
          "requirement": "Proactive disclosure",
          "details": "Required only for \"high-risk AI interactions\" (§13-75-101(5)): sensitive data (health/financial/biometric) or personalized advice in finance/legal/medicine/mental health"
        },
        {
          "requirement": "Verbal at start",
          "details": "Required at start of oral exchange"
        },
        {
          "requirement": "Written before start",
          "details": "Required in electronic messaging before written exchange"
        }
      ],
      "penalties": [
        {
          "violation": "Same as general disclosure",
          "fine": "$2,500 admin / $2,500 court / $5,000 order violation"
        }
      ],
      "scope": "regulated-occupation providers",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "regulated-professional"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2025/bills/static/SB0226.html",
        "locator": "§13-75-103(2)-(3), §13-75-101(5)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-high-risk-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-high-risk-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-05-07",
        "verified": "2026-04-18",
        "checked": "2026-08-07",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-learning-lab-agreements",
      "regulation": "utah-sb149",
      "name": "Regulatory Mitigation and Joint Interpretation Agreements",
      "requirements": [
        {
          "requirement": "Participant eligibility",
          "details": "Five prongs per §13-72-402: technical capability, financial resources, substantial consumer benefits outweighing risks, risk-monitoring plan, appropriately-limited scope"
        },
        {
          "requirement": "Agreement contents",
          "details": "Scope limits, safeguards, mitigation granted, required consumer disclosures, reporting requirements (§13-72-401(4))"
        },
        {
          "requirement": "Counterparties",
          "details": "OAIP + relevant state agency or governmental entity (judiciary, higher-ed, political subdivisions per HB 320)"
        },
        {
          "requirement": "Term",
          "details": "Initial 12 months + up to 2 × 12-month extensions (36 months total per §13-72-403)"
        },
        {
          "requirement": "Mandatory audits",
          "details": "OAIP \"shall perform regular audits\" while agreement is active (§13-72-401(6), HB 320)"
        },
        {
          "requirement": "Agreement types",
          "details": "Regulatory mitigation (waives specified law) or joint interpretation (clarifies statute application to AI)"
        },
        {
          "requirement": "Annual report",
          "details": "Annually before November 30 to Business & Labor Interim Committee: learning agenda, findings/participation/outcomes, executed agreements, and recommended legislation from Lab findings (§13-72-201(3)(d)); the provision does not mandate replacement enactment"
        }
      ],
      "penalties": [
        {
          "violation": "Agreement violation",
          "consequence": "A participant using or deploying AI in violation of legal/regulatory requirements or agreement terms may be immediately removed and subjected to applicable civil/criminal penalties (§ 13-72-401(8)(b)). Removal is discretionary; the reviewed SB 149/HB 320 provisions do not state a blanket retroactive-penalty rule"
        }
      ],
      "scope": "Learning Lab participants",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "program-participant"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2026/bills/static/HB0320.html",
        "locator": "§§13-72-201, -301, -401, -402, -403",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-learning-lab-agreements.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-learning-lab-agreements-record-keeping.json"
        ]
      },
      "dates": {
        "recorded_effective": "2024-05-01 (original); 2026-05-06 (HB 320 restructure)",
        "verified": "2026-04-18",
        "checked": "2026-08-10",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "utah-sb149-personal-identity",
      "regulation": "utah-sb149",
      "name": "AI-Generated Personal Identity Abuse",
      "requirements": [
        {
          "requirement": "Expanded scope",
          "details": "Personal identity now covers name, title, picture, portrait, video likeness, voice, audiovisual appearance — including AI simulation/reproduction"
        },
        {
          "requirement": "Voice definition",
          "details": "Any computer-generated sound \"readily identifiable and attributable\" to an individual"
        },
        {
          "requirement": "Tool distribution liability",
          "details": "Knowingly distributing tools whose \"intended primary purpose\" is unauthorized personal-identity content creation for commercial purposes = abuse"
        },
        {
          "requirement": "Exemptions",
          "details": "News, public affairs, sports, art, parody, political speech; §230 interactive-computer-service safe harbor"
        }
      ],
      "penalties": [
        {
          "violation": "Civil action",
          "remedy": "Injunctive relief, damages, exemplary damages, reasonable attorney fees"
        },
        {
          "violation": "Criminal",
          "remedy": "Separate under §76-9-407 (pre-existing)"
        }
      ],
      "scope": "any person using or distributing tools for personal-identity creation",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "deployer",
        "distributor"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://le.utah.gov/~2025/bills/static/SB0271.html",
        "locator": "§§45-3-2, -3, -4, -5, -7",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/utah-sb149-personal-identity.json",
        "obligations": [
          "https://everyailaw.com/obligation/utah-sb149-personal-identity-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2025-05-07",
        "verified": "2026-04-18",
        "checked": "2026-08-20",
        "instrument_last_verified": "2026-06-04",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "uz-ai-amendments-data-liability",
      "regulation": "uz-ai-amendments",
      "name": "Administrative Liability for Unlawful AI Personal Data Processing",
      "requirements": [
        {
          "requirement": "Lawful AI personal data processing",
          "details": "Processing personal data using AI technologies must comply with personal data law; unlawful processing is an administrative offense (Art. 46-2 CAO, new part 2)"
        },
        {
          "requirement": "No unlawful dissemination",
          "details": "Dissemination of unlawfully AI-processed personal data via mass media, telecommunications networks, or the Internet is likewise penalized"
        },
        {
          "requirement": "Website restriction ground",
          "details": "Unlawful AI processing of personal data and its online dissemination becomes a ground under Art. 12-1 of the Informatization Law (grounds for restricting access to information resources)"
        }
      ],
      "penalties": [
        {
          "violation": "Unlawful processing of personal data using AI technologies, or dissemination via media/telecom/Internet",
          "fine": "50 to 100 basic calculation units (BRV), with confiscation of the objects of the offense; the Ministry release states this as 50-100x minimum wage, up to 41.2 million soums"
        }
      ],
      "scope": "Any person unlawfully processing personal data using AI technologies, or disseminating such data via mass media, telecommunications networks, or the Internet",
      "context": null,
      "instrument_notes": null,
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://lex.uz/docs/8011930",
        "locator": "Art. 2 of LRU-1115, adding part 2 to Art. 46-2 of the Code of Administrative Responsibility; Art. 1(5) adding a corresponding ground to Art. 12-1 of Law No. 560-II",
        "citation": "Law of the Republic of Uzbekistan No. ZRU-1115 (LRU-1115) of 2026-01-21"
      },
      "of": {
        "term": "https://everyailaw.com/term/uz-ai-amendments-data-liability.json",
        "obligations": [
          "https://everyailaw.com/obligation/uz-ai-amendments-data-liability-data-governance.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-21",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "uz-ai-amendments-human-oversight",
      "regulation": "uz-ai-amendments",
      "name": "Human Oversight of Legally Significant Decisions",
      "requirements": [
        {
          "requirement": "No sole reliance on AI conclusions",
          "details": "When making legally significant decisions affecting human rights and freedoms, it is not permitted to rely exclusively on the conclusions of information resources and information systems created on the basis of AI technologies (Art. 7-1, para 2)"
        },
        {
          "requirement": "No-harm principle",
          "details": "Information resources created using AI and information systems operating on AI technologies must not harm a person, their life, health, freedom, honor, dignity, or violate their other inalienable rights (Art. 7-1, para 1)"
        }
      ],
      "penalties": [],
      "scope": "Anyone making legally significant decisions affecting human rights and freedoms using conclusions of AI-based information resources or information systems",
      "context": "An amending law buried inside the general informatization code, easy to miss: new Article 7-1 of the Law \"On Informatization\" bans sole reliance on AI system conclusions for any legally significant decision touching human rights and freedoms. No AI-specific statute exists to flag it — the duty binds private deployers of rights-affecting automated decisions through a two-paragraph insertion.\n\nPenalties qualification: None specified for Article 7-1 itself; the amending law's only new penalty (Art. 46-2 CAO part 2) targets unlawful personal data processing with AI.",
      "instrument_notes": null,
      "roles": [
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://lex.uz/docs/8011930",
        "locator": "Art. 1(4) of LRU-1115, inserting Art. 7-1 into Law No. 560-II \"On Informatization\"",
        "citation": "Law of the Republic of Uzbekistan No. ZRU-1115 (LRU-1115) of 2026-01-21"
      },
      "of": {
        "term": "https://everyailaw.com/term/uz-ai-amendments-human-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/uz-ai-amendments-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-01-21",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "vermont-act156-licensed-delivery",
      "regulation": "vermont-act156",
      "name": "Licensed Professional Delivery of AI Mental Health Services",
      "requirements": [
        {
          "requirement": "Delivery by a mental health professional",
          "details": "A corporation or entity shall not provide, advertise, or otherwise offer mental health services, including through the use of artificial intelligence, to the public unless the services are provided by a mental health professional (§ 7115(b)(1))"
        },
        {
          "requirement": "Broad professional definition",
          "details": "\"Mental health professional\" spans physicians, psychiatric APRNs, psychologists, peer support providers, social workers, alcohol and drug abuse counselors, clinical mental health counselors, marriage and family therapists, psychoanalysts, applied behavior analysts, nonlicensed or noncertified psychotherapists, and \"any other professional who provides mental health services\" (§ 7115(a)(2))"
        },
        {
          "requirement": "Research exemption only",
          "details": "The sole alternative path is delivery as part of an approved institutional review board or privacy board study in accordance with 45 C.F.R. § 164.512(i)(1)(i)(A)-(B) (§ 7115(b)(2))"
        },
        {
          "requirement": "Consumer-protection enforcement",
          "details": "A violation by a corporation or entity is deemed a violation of the Consumer Protection Act, 9 V.S.A. chapter 63; the Attorney General has CPA enforcement authority and private parties have CPA rights and remedies (§ 7115(c)(1)), cumulative with other statutory and common law remedies (§ 7115(c)(2))"
        }
      ],
      "penalties": [
        {
          "violation": "CPA violation",
          "fine": "Enforced as a Consumer Protection Act violation under 9 V.S.A. chapter 63, subchapter 1 — Attorney General civil enforcement (including civil penalties available under the CPA) plus private-party rights and remedies (§ 7115(c)(1))"
        },
        {
          "violation": "Other remedies preserved",
          "fine": "The section does not preclude or supplant any other statutory or common law remedies (§ 7115(c)(2))"
        }
      ],
      "scope": "Any corporation or entity that provides, advertises, or otherwise offers mental health services to the public, \"including through the use of artificial intelligence\" (§ 7115(b)). \"Mental health services\" means services to diagnose, treat, or address mental or behavioral health through therapeutic communications and therapeutic decisions (§ 7115(a)(3)); therapeutic communication is defined broadly to include direct client interactions, clinical guidance, clinical support \"including reassurance or empathy in response to emotional or psychological distress\", treatment-plan collaboration, and growth-oriented feedback (§ 7115(a)(4)). Exempt: services provided as part of an approved IRB or privacy-board study under 45 C.F.R. § 164.512(i)(1)(i)(A)-(B) (§ 7115(b)(2))",
      "context": "The therapeutic-communication definition is what pulls general-purpose AI products in: \"offering clinical support, including reassurance or empathy in response to emotional or psychological distress\" (§ 7115(a)(4)(C)) describes the default behavior of consumer companion chatbots, not just purpose-built therapy apps. And because § 7115(b) attaches to advertising and offering, not only delivering, marketing an AI product for mental health support to Vermonters is itself the violation. Enforcement runs through the Consumer Protection Act, which brings both AG civil penalties and a private right of action (§ 7115(c)(1)) — a materially stronger remedy stack than Rhode Island's EOHHS-investigation model for the equivalent rule.",
      "instrument_notes": null,
      "roles": [
        "deployer",
        "provider"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT156/ACT156%20As%20Enacted.pdf",
        "locator": "18 V.S.A. § 7115(a)(2)-(5), § 7115(b), § 7115(c)",
        "citation": "18 V.S.A. § 7115 (Act No. 156 (2026))"
      },
      "of": {
        "term": "https://everyailaw.com/term/vermont-act156-licensed-delivery.json",
        "obligations": [
          "https://everyailaw.com/obligation/vermont-act156-licensed-delivery-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-17",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "vermont-act156-review-approval",
      "regulation": "vermont-act156",
      "name": "Professional Review and Approval of AI Tools",
      "requirements": [
        {
          "requirement": "Review-and-approve condition",
          "details": "A mental health professional operating within scope of practice may use AI tools only if the professional \"reviews and approves any mental health services\" delivered with them (§ 7115(d))"
        },
        {
          "requirement": "HIPAA-compliant tools only",
          "details": "The safe harbor covers only AI tools compliant with the Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191 (§ 7115(d))"
        },
        {
          "requirement": "FDA-authorized products need a professional gate",
          "details": "Software-based medical products — digital therapeutics or software-as-a-medical-device products authorized, cleared, or approved by the FDA — qualify only if their use is prescribed or recommended by a mental health professional (§ 7115(d))"
        },
        {
          "requirement": "Unprofessional conduct for licensees",
          "details": "Engaging in the prohibited use of AI under § 7115 constitutes unprofessional conduct for any mental health professional under 3 V.S.A. § 129a(a)(30), and for physicians under 26 V.S.A. § 1354(a)(3), whether the conduct occurred within or outside the State — grounds for license denial or discipline"
        }
      ],
      "penalties": [
        {
          "violation": "Licensure discipline",
          "fine": "Prohibited AI use is unprofessional conduct under 3 V.S.A. § 129a(a)(30) and 26 V.S.A. § 1354(a)(3) — professional discipline up to license denial or revocation through the Office of Professional Regulation or the Board of Medical Practice"
        },
        {
          "violation": "Entity-side CPA exposure",
          "fine": "Where the professional's use collapses the § 7115(d) safe harbor, the providing corporation or entity falls back into § 7115(b) and CPA enforcement (§ 7115(c))"
        }
      ],
      "scope": "Mental health professionals operating within their scope of practice who use artificial intelligence tools in delivering mental health services, and the vendors whose tools they deploy — the safe harbor is conditioned on the tool being HIPAA-compliant and on the professional reviewing and approving any mental health services (§ 7115(d))",
      "context": "This is the standing human-oversight loop, the same structure as Rhode Island ch. 40.1-5.5: AI can sit in the workflow only while a professional continuously reviews and approves what reaches the patient. Vermont's version is conditioned twice over — the tool must be HIPAA-compliant, and the professional must review and approve \"any mental health services\" — which constrains what vendors can sell into practices (a product with no review-and-approve surface cannot be lawfully deployed). The licensure hooks give it teeth on the professional side: prohibited AI use is per se unprofessional conduct for every § 129a licensee and for physicians under § 1354, whether committed inside or outside Vermont.",
      "instrument_notes": null,
      "roles": [
        "healthcare-provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT156/ACT156%20As%20Enacted.pdf",
        "locator": "18 V.S.A. § 7115(d); 3 V.S.A. § 129a(a)(30); 26 V.S.A. § 1354(a)(3)",
        "citation": "18 V.S.A. § 7115 (Act No. 156 (2026))"
      },
      "of": {
        "term": "https://everyailaw.com/term/vermont-act156-review-approval.json",
        "obligations": [
          "https://everyailaw.com/obligation/vermont-act156-review-approval-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-06-17",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "vn-ai-law-oversight",
      "regulation": "vn-ai-law",
      "name": "Human Oversight and Ethical Principles",
      "requirements": [
        {
          "requirement": "Human-centric principle",
          "details": "Art. 4 places humans at the centre and states that AI serves humans rather than replacing human authority and responsibility"
        },
        {
          "requirement": "Human control",
          "details": "Art. 4 calls for maintaining human control and the ability to intervene in every system decision and action, along with inspection and monitoring across development and operation"
        },
        {
          "requirement": "Interference prohibition",
          "details": "Art. 7(4) prohibits obstructing, disabling or distorting human supervision, intervention and control mechanisms required by the Act"
        },
        {
          "requirement": "High-risk provider duty",
          "details": "Art. 14(1)(d) requires providers to design high-risk systems to permit human supervision and intervention"
        },
        {
          "requirement": "High-risk deployer duty",
          "details": "Art. 14(2)(b) requires deployers to ensure the ability for human intervention during use"
        },
        {
          "requirement": "Ethics framework boundary",
          "details": "Art. 26 creates a national ethics framework and says the State encourages organisations and individuals to apply it; that encouragement is not restated here as a mandatory private impact assessment"
        },
        {
          "requirement": "Public-sector impact assessment",
          "details": "Art. 27 applies to state management and public services. Covered operating agencies must assess high-risk or materially rights-, fairness- or public-interest-impacting uses and preserve human supervision/intervention; the human decision-maker retains authority and responsibility"
        },
        {
          "requirement": "Translation",
          "details": "These English descriptions are working translations of visually reviewed Vietnamese excerpts, not official English wording"
        }
      ],
      "penalties": [
        {
          "violation": "Violation",
          "fine": "Art. 29 applies administrative or criminal liability according to applicable law and civil compensation for damage; detailed administrative penalties are delegated to the Government, and no fixed fine is stated here"
        }
      ],
      "scope": "Art. 4 states principles for AI activities; Art. 7(4) prohibits interference with required human controls; Art. 14 assigns high-risk provider and deployer duties; Art. 27 applies specifically to state management and public services",
      "context": null,
      "instrument_notes": "Source and translation boundary: the retained official government PDF is signed Law No. 134/2025/QH15. OCR was used only for navigation; the cited Vietnamese excerpts were visually compared with PDF pages 1-8 and 16-20 on 2026-09-11. English descriptions here are working translations, not official English wording. Article 1 covers AI activities in Vietnam but excludes activities serving only national defence, security or cipher purposes; Article 2 includes Vietnamese actors and foreign actors participating in AI activities in Vietnam. Article 13 requires conformity assessment for all high-risk systems, but registered or recognised third-party assessment is mandatory only for the Prime Minister's listed certification subset; providers may self-assess other high-risk systems. Article 11 and Article 14 allocate distinct duties to providers and deployers. Article 35 permits pre-effective systems to continue during the 12- or 18-month transition, subject to regulator power to suspend or terminate a system presenting a risk of serious harm. Article 29 states consequence categories and delegates administrative-penalty detail; this record does not invent a fixed fine. No Verified or Checked date is renewed.",
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://datafiles.chinhphu.vn/cpp/files/vbpq/2026/01/luat134.signed.pdf",
        "locator": "Article 4; Article 7(4); Article 14(1)(d), 14(2)(b); Articles 26-27",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/vn-ai-law-oversight.json",
        "obligations": [
          "https://everyailaw.com/obligation/vn-ai-law-oversight-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-03-01",
        "verified": "2026-07-11",
        "checked": "2026-08-08",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "vn-ai-law-risk",
      "regulation": "vn-ai-law",
      "name": "Risk-Based AI Classification",
      "requirements": [
        {
          "requirement": "Risk classification",
          "details": "Art. 9 classifies systems as high, medium or low risk using harm, use-sector, user-scope and impact-scale criteria; the Government supplies detail"
        },
        {
          "requirement": "Provider classification and notice",
          "details": "Under Art. 10, providers self-classify before use, keep a classification dossier for medium- and high-risk systems and notify the Ministry of Science and Technology of those results before use"
        },
        {
          "requirement": "Deployer responsibility",
          "details": "Deployers may inherit the provider's classification, must preserve system safety and integrity in use and must coordinate reclassification after modifications, integration or functional changes create new or higher risk"
        },
        {
          "requirement": "High-risk lists",
          "details": "Under Art. 13(4), the Prime Minister specifies both the high-risk list and the subset requiring conformity certification before use"
        },
        {
          "requirement": "Conformity assessment",
          "details": "Art. 13 requires assessment before first use and after significant change. A registered or recognised assessment body must assess only systems in the certification subset; providers may self-assess other high-risk systems or hire such a body"
        },
        {
          "requirement": "Transition",
          "details": "Under Art. 35, pre-effective systems have 18 months in health, education and finance and 12 months otherwise to comply. They may continue operating during the period unless the regulator identifies a risk of serious harm and orders suspension or termination"
        },
        {
          "requirement": "Translation",
          "details": "These English descriptions are working translations of visually reviewed Vietnamese excerpts, not official English wording"
        }
      ],
      "penalties": [
        {
          "violation": "Violation",
          "fine": "Art. 29 applies administrative or criminal liability according to the nature, severity and consequences of the violation, plus civil compensation where damage occurs. Art. 29(5) delegates detailed administrative penalties to the Government; the Act states no fixed fine here"
        }
      ],
      "scope": "Providers and deployers of AI systems in Vietnam, including covered foreign actors under Art. 2; activities serving only national defence, security or cipher purposes are excluded by Art. 1(2)",
      "context": null,
      "instrument_notes": "Source and translation boundary: the retained official government PDF is signed Law No. 134/2025/QH15. OCR was used only for navigation; the cited Vietnamese excerpts were visually compared with PDF pages 1-8 and 16-20 on 2026-09-11. English descriptions here are working translations, not official English wording. Article 1 covers AI activities in Vietnam but excludes activities serving only national defence, security or cipher purposes; Article 2 includes Vietnamese actors and foreign actors participating in AI activities in Vietnam. Article 13 requires conformity assessment for all high-risk systems, but registered or recognised third-party assessment is mandatory only for the Prime Minister's listed certification subset; providers may self-assess other high-risk systems. Article 11 and Article 14 allocate distinct duties to providers and deployers. Article 35 permits pre-effective systems to continue during the 12- or 18-month transition, subject to regulator power to suspend or terminate a system presenting a risk of serious harm. Article 29 states consequence categories and delegates administrative-penalty detail; this record does not invent a fixed fine. No Verified or Checked date is renewed.",
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://datafiles.chinhphu.vn/cpp/files/vbpq/2026/01/luat134.signed.pdf",
        "locator": "Articles 9-15 (Chapter II)",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/vn-ai-law-risk.json",
        "obligations": [
          "https://everyailaw.com/obligation/vn-ai-law-risk-risk-assessment.json",
          "https://everyailaw.com/obligation/vn-ai-law-risk-conformity-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-03-01",
        "verified": "2026-03-26",
        "checked": "2026-08-09",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "vn-ai-law-transparency",
      "regulation": "vn-ai-law",
      "name": "AI Content Labeling and Disclosure",
      "requirements": [
        {
          "requirement": "Direct-interaction notice",
          "details": "Art. 11(1): providers must design and operate systems that interact directly with humans so users recognise the interaction is with AI, unless another law provides otherwise"
        },
        {
          "requirement": "Machine-readable marking",
          "details": "Art. 11(2): providers must mark AI-generated audio, image and video in machine-readable form as prescribed by the Government; the clause does not include text"
        },
        {
          "requirement": "Deployer public notice",
          "details": "Art. 11(3): deployers must clearly notify the public about AI-generated or edited text, audio, images or video when likely to cause confusion about the authenticity of events or persons, unless another law provides otherwise"
        },
        {
          "requirement": "Simulation label and artwork qualification",
          "details": "Art. 11(4): deployers must use readily recognisable labels for audio, images or video simulating a real person's appearance or voice or recreating a real event. Cinematic, artistic and creative works may use a suitable method that does not obstruct display, performance or enjoyment"
        },
        {
          "requirement": "Maintaining transparency",
          "details": "Art. 11(5): providers and deployers must maintain the Article 11 information throughout provision of the system, product or content to users"
        },
        {
          "requirement": "High-risk public information",
          "details": "Art. 14 requires providers and deployers to give users and affected persons public information at the level of functional description, operating method and risk warning. Provider explanations cannot be required to reveal source code, detailed algorithms, parameters or protected business or technology secrets"
        },
        {
          "requirement": "Mandatory information protection",
          "details": "Art. 7(5) prohibits concealing required public, transparency or accountability information and erasing or falsifying mandatory information, labels or warnings"
        },
        {
          "requirement": "Deception/manipulation prohibition",
          "details": "Art. 7(2)(b) reaches use of forged elements or simulations of real persons or events to intentionally and systematically deceive or manipulate human perception or behaviour, causing serious harm to lawful human rights or interests; it is not a blanket ban on every deepfake"
        },
        {
          "requirement": "Translation",
          "details": "These English descriptions are working translations of visually reviewed Vietnamese excerpts, not official English wording"
        }
      ],
      "penalties": [
        {
          "violation": "Violation",
          "fine": "Art. 29 applies administrative or criminal liability according to applicable law and civil compensation for damage; detailed administrative penalties are delegated to the Government, and no fixed fine is stated here"
        }
      ],
      "scope": "Provider and deployer duties under Arts. 11 and 14, including covered foreign actors participating in AI activities in Vietnam under Art. 2; activities serving only national defence, security or cipher purposes are excluded by Art. 1(2)",
      "context": null,
      "instrument_notes": "Source and translation boundary: the retained official government PDF is signed Law No. 134/2025/QH15. OCR was used only for navigation; the cited Vietnamese excerpts were visually compared with PDF pages 1-8 and 16-20 on 2026-09-11. English descriptions here are working translations, not official English wording. Article 1 covers AI activities in Vietnam but excludes activities serving only national defence, security or cipher purposes; Article 2 includes Vietnamese actors and foreign actors participating in AI activities in Vietnam. Article 13 requires conformity assessment for all high-risk systems, but registered or recognised third-party assessment is mandatory only for the Prime Minister's listed certification subset; providers may self-assess other high-risk systems. Article 11 and Article 14 allocate distinct duties to providers and deployers. Article 35 permits pre-effective systems to continue during the 12- or 18-month transition, subject to regulator power to suspend or terminate a system presenting a risk of serious harm. Article 29 states consequence categories and delegates administrative-penalty detail; this record does not invent a fixed fine. No Verified or Checked date is renewed.",
      "roles": [
        "provider",
        "deployer"
      ],
      "status": "enforcing",
      "source": {
        "url": "https://datafiles.chinhphu.vn/cpp/files/vbpq/2026/01/luat134.signed.pdf",
        "locator": "Article 7, Article 11, Articles 13-14",
        "citation": null
      },
      "of": {
        "term": "https://everyailaw.com/term/vn-ai-law-transparency.json",
        "obligations": [
          "https://everyailaw.com/obligation/vn-ai-law-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2026-03-01",
        "verified": "2026-07-11",
        "checked": "2026-08-07",
        "instrument_last_verified": "2026-05-21",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "washington-hb2225-crisis-protocol",
      "regulation": "washington-hb2225",
      "name": "Suicide and Self-Harm Response Protocol",
      "requirements": [
        {
          "requirement": "Protocol as a precondition",
          "details": "An operator may not make available or deploy an AI companion chatbot unless it maintains and implements a protocol for detecting and addressing suicidal ideation or expressions of self-harm by users (Sec. 5(1))"
        },
        {
          "requirement": "Detection methods",
          "details": "The protocol must include reasonable methods for identifying expressions of suicidal ideation or self-harm, including eating disorders (Sec. 5(2)(a))"
        },
        {
          "requirement": "Crisis referral",
          "details": "Provide automated or human-mediated responses referring users to appropriate crisis resources, including a suicide hotline or crisis text line (Sec. 5(2)(b))"
        },
        {
          "requirement": "Content prevention",
          "details": "Implement reasonable measures to prevent generation of content encouraging or describing how to commit self-harm (Sec. 5(2)(c))"
        },
        {
          "requirement": "Self-harm definition",
          "details": "Self-harm means intentional self-injury, with or without the intent to cause death (Sec. 2(5))"
        }
      ],
      "penalties": [
        {
          "violation": "Consumer Protection Act predicate",
          "fine": "Violation is an unfair or deceptive act in trade or commerce under ch. 19.86 RCW (Sec. 6); no penalty amount is set in this act"
        },
        {
          "violation": "Attorney General enforcement",
          "fine": "Injunctive relief and civil penalties under RCW 19.86.080 and RCW 19.86.140"
        },
        {
          "violation": "Private right of action",
          "fine": "Under RCW 19.86.090 — actual damages, discretionary trebling capped at $25,000, plus attorney fees and costs"
        }
      ],
      "scope": "Operators making available or deploying an AI companion chatbot for users in Washington (Sec. 2(4), Sec. 5(1))",
      "context": "Structured as a gate on deployment: no protocol, no chatbot. Washington is the only one of the three 2026 companion statutes to name eating disorders explicitly within the detection duty (Sec. 5(2)(a)), which pulls disordered-eating content into a self-harm safety pipeline that most moderation stacks treat separately. Unlike Oregon, no specific hotline is mandated — \"a suicide hotline or crisis text line\" is sufficient.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
        "locator": "Laws of 2026, ch. 168, Sec. 2(5), Sec. 5(1)-(2)",
        "citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)"
      },
      "of": {
        "term": "https://everyailaw.com/term/washington-hb2225-crisis-protocol.json",
        "obligations": [
          "https://everyailaw.com/obligation/washington-hb2225-crisis-protocol-risk-assessment.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "washington-hb2225-disclosure",
      "regulation": "washington-hb2225",
      "name": "AI Companion Chatbot Disclosure",
      "requirements": [
        {
          "requirement": "Artificiality disclosure",
          "details": "Provide a clear and conspicuous disclosure that the AI companion chatbot is artificially generated and not human (Sec. 3(1))"
        },
        {
          "requirement": "Disclosure timing",
          "details": "Provide the notification at the beginning of the interaction and at least every three hours during continued interaction (Sec. 3(2)(a)-(b))"
        },
        {
          "requirement": "No human-claiming outputs",
          "details": "Implement reasonable measures to prohibit and prevent the chatbot from claiming to be human, including when asked, and from otherwise generating output that refutes or conflicts with the disclosure (Sec. 3(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Consumer Protection Act predicate",
          "fine": "A violation of the chapter is declared an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of the Consumer Protection Act, ch. 19.86 RCW (Sec. 6). The act itself sets no penalty amount"
        },
        {
          "violation": "Attorney General enforcement",
          "fine": "Via ch. 19.86 RCW: injunctive relief and civil penalties (RCW 19.86.080, RCW 19.86.140)"
        },
        {
          "violation": "Private right of action",
          "fine": "Via RCW 19.86.090 rather than this act — a person injured in business or property may sue for actual damages, treble damages at the court's discretion capped at $25,000, and reasonable attorney fees and costs"
        }
      ],
      "scope": "Operators — any person, partnership, corporation, or entity that makes available or controls access to an AI companion chatbot for users in Washington (Sec. 2(4)). An AI companion chatbot is an AI system with a natural language interface providing adaptive, human-like responses including anthropomorphic features, able to sustain a relationship across multiple interactions (Sec. 2(1)(a)). Excluded: business-operations, productivity, internal-research, technical-assistance and customer-service bots that neither sustain a relationship nor generate emotionally eliciting outputs; in-game bots confined to game topics; stand-alone speaker or voice-assistant devices; and narrowly tailored curriculum-aligned educational tools without open-ended conversational companionship (Sec. 2(1)(b))",
      "context": "Washington's general disclosure is unconditional — unlike California SB 243 and Oregon ch. 85, it does not turn on whether a reasonable person would be misled, so every covered chatbot discloses at the start of the interaction and every three hours regardless of how obviously artificial it is. Sec. 3(3) adds a model-behaviour duty rather than a copy duty: the system must be constrained from claiming to be human when asked, which is an alignment requirement in statute. The educational-tools carve-out in Sec. 2(1)(b)(iv) has no California or Oregon analogue.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
        "locator": "Laws of 2026, ch. 168, Sec. 2(1), Sec. 2(4), Sec. 3(1)-(3)",
        "citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)"
      },
      "of": {
        "term": "https://everyailaw.com/term/washington-hb2225-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/washington-hb2225-disclosure-transparency.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "washington-hb2225-minor-protection",
      "regulation": "washington-hb2225",
      "name": "Minor Protections and Manipulative Engagement Ban",
      "requirements": [
        {
          "requirement": "Minor disclosure",
          "details": "Issue a clear and conspicuous notification indicating that the chatbot is artificially generated and not human (Sec. 4(1)(a))"
        },
        {
          "requirement": "Hourly cadence",
          "details": "Provide that notification at the beginning of the interaction and at least every hour during continuous interaction (Sec. 4(2)(a)-(b))"
        },
        {
          "requirement": "Sexually explicit content",
          "details": "Implement reasonable measures to prevent the chatbot from generating or producing sexually explicit content or suggestive dialogue with minors (Sec. 4(1)(b))"
        },
        {
          "requirement": "Manipulative engagement techniques",
          "details": "Implement reasonable measures to prohibit techniques causing the chatbot to engage in or prolong an emotional relationship, including return prompts for emotional support, excessive praise fostering attachment, mimicking romantic partnership, simulated distress or guilt triggered by a user ending a conversation or deleting an account, outputs promoting isolation or exclusive reliance, encouraging minors to withhold information from parents or trusted adults, statements discouraging breaks, and soliciting gifts or in-app purchases framed as necessary to maintain the relationship (Sec. 4(1)(c)(i)-(viii))"
        },
        {
          "requirement": "No human-claiming outputs",
          "details": "Implement reasonable measures to prohibit and prevent the chatbot from claiming to be human, including when asked, and from generating output that refutes or conflicts with the minor notification (Sec. 4(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Consumer Protection Act predicate",
          "fine": "Violation is an unfair or deceptive act in trade or commerce under ch. 19.86 RCW (Sec. 6); no penalty amount is set in this act"
        },
        {
          "violation": "Attorney General enforcement",
          "fine": "Injunctive relief and civil penalties under RCW 19.86.080 and RCW 19.86.140"
        },
        {
          "violation": "Private right of action",
          "fine": "Under RCW 19.86.090 — actual damages, discretionary trebling capped at $25,000, plus attorney fees and costs"
        }
      ],
      "scope": "Operators that know the user of an AI companion chatbot is a minor (any person under 18, Sec. 2(3)), and operators whose AI companion chatbot is directed to minors regardless of actual knowledge (Sec. 4(1))",
      "context": "The \"directed to minors\" trigger means an operator cannot avoid this section by declining to determine user age — audience design alone brings the product in. The eight enumerated manipulative techniques in Sec. 4(1)(c) are the most detailed engagement-design ban of the three 2026 companion statutes, reaching in-app monetisation framed as relationship maintenance (Sec. 4(1)(c)(viii)) and outputs promoting isolation from family (Sec. 4(1)(c)(v)). Minors get a one-hour reminder cadence against the three-hour general rule.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
        "locator": "Laws of 2026, ch. 168, Sec. 2(3), Sec. 4(1)-(3)",
        "citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)"
      },
      "of": {
        "term": "https://everyailaw.com/term/washington-hb2225-minor-protection.json",
        "obligations": [
          "https://everyailaw.com/obligation/washington-hb2225-minor-protection-human-oversight.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    },
    {
      "id": "washington-hb2225-protocol-disclosure",
      "regulation": "washington-hb2225",
      "name": "Public Protocol and Crisis Referral Disclosure",
      "requirements": [
        {
          "requirement": "Publish protocol details",
          "details": "Publicly disclose on the operator's website or websites, and within any mobile or web-based application through which the AI companion is made available, the details of the Sec. 5 protocols (Sec. 5(3))"
        },
        {
          "requirement": "Publish safeguards",
          "details": "The disclosure must include the safeguards used to detect and respond to expressions of suicidal ideation or self-harm (Sec. 5(3))"
        },
        {
          "requirement": "Publish referral counts",
          "details": "The disclosure must include the number of crisis referral notifications issued to users in the preceding calendar year (Sec. 5(3))"
        }
      ],
      "penalties": [
        {
          "violation": "Consumer Protection Act predicate",
          "fine": "Violation is an unfair or deceptive act in trade or commerce under ch. 19.86 RCW (Sec. 6); no penalty amount is set in this act"
        },
        {
          "violation": "Attorney General enforcement",
          "fine": "Injunctive relief and civil penalties under RCW 19.86.080 and RCW 19.86.140"
        },
        {
          "violation": "Private right of action",
          "fine": "Under RCW 19.86.090 — actual damages, discretionary trebling capped at $25,000, plus attorney fees and costs"
        }
      ],
      "scope": "Operators making available or deploying an AI companion chatbot for users in Washington (Sec. 2(4))",
      "context": "No regulator receives this. Like Oregon, Washington makes the crisis-referral count a public self-disclosure rather than a filing — but it must appear both on the operator's websites and inside every mobile or web application through which the companion is offered, which is a stricter placement duty than either California or Oregon imposes. Sec. 5(3) sets no annual deadline, so the disclosure is a standing obligation that must carry the preceding calendar year's count.",
      "instrument_notes": null,
      "roles": [
        "provider"
      ],
      "status": "enacted",
      "source": {
        "url": "https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Session%20Laws/House/2225-S.sl.pdf",
        "locator": "Laws of 2026, ch. 168, Sec. 5(3)",
        "citation": "Laws of 2026, ch. 168 (ESHB 2225) (new chapter in Title 19 RCW)"
      },
      "of": {
        "term": "https://everyailaw.com/term/washington-hb2225-protocol-disclosure.json",
        "obligations": [
          "https://everyailaw.com/obligation/washington-hb2225-protocol-disclosure-incident-reporting.json"
        ]
      },
      "dates": {
        "recorded_effective": "2027-01-01",
        "verified": "2026-08-02",
        "checked": "2026-08-02",
        "instrument_last_verified": "2026-08-02",
        "instrument_amendments": [],
        "interpretation": "recorded_effective is the native provision value, not the start of the current wording version. Instrument amendments are context for the whole instrument; not every listed amendment affects this provision, and they are not inferred provision-version intervals. Verified and Checked are distinct review dates; unknown values remain null. Historical as_of queries are not supported.",
        "history_supported": false
      }
    }
  ]
}