Insights
Provisions worth knowing about — sleeper regulations, upcoming deadlines, and high-impact requirements that compliance teams often miss.
sleeper 23 provisions
Regulations not branded as AI-specific but that catch AI use — privacy laws, financial rules, and sector regulations with provisions that apply to automated decision-making.
NSW's Digital Work Systems Act catches every employer using algorithmic scheduling, AI-driven monitoring, automated performance management, or platform-based work allocation. The definition of "digital work system" explicitly includes algorithms, AI, automation, and online platforms — making this one of the broadest workplace AI laws globally. Any company operating in NSW with AI-assisted HR, logistics, or workforce management tools must assess and manage WHS risks from those systems.
WHS entry permit holders (typically union officials) gain rights to access and inspect digital work systems — including AI algorithms and monitoring tools — in relation to a suspected contravention, not as an unconditional/blanket inspection right. Employers must provide "reasonable assistance" on notice. This creates a transparency obligation where the AI/algorithmic logic behind workplace decisions becomes inspectable by worker representatives, not just regulators. The inspection-access right specifically (distinct from the Act's general 2026-02-18 effective date) does not commence until SafeWork NSW publishes its entry permit holder guideline, plus one month — see Timeline table. Status reflects this guideline-gated commencement rather than current enforceability.
Australia's Privacy Act reforms make AI transparency mandatory through privacy law — not AI-specific legislation. Any organization using personal information in automated decisions must update its privacy policy to describe, in general terms, the kinds of personal information used and the kinds of decisions made or substantially assisted by ADM. Even "human in the loop" doesn't exempt you if the algorithm plays a substantial role.
APP 3 and APP 6 data minimisation and purpose limitation have always applied to AI systems processing personal information — these are existing obligations, not new POLA Act requirements. The POLA Act 2024 strengthened general APP enforcement but did not insert an AI-specific minimisation clause effective 2026-12-10. Organisations collecting personal data for AI training or inference must ensure collection is reasonably necessary for a specific purpose (APP 3) and that data is only used for the purpose for which it was collected (APP 6). OAIC's Children's Online Privacy Code (registerable by Dec 2026) imposes additional data minimisation duties for child-facing AI services as a code instrument, not a standalone APP amendment.
No general statutory PIA mandate for AI exists in the Privacy Act 1988. The POLA Act 2024 did not enact a universal PIA requirement effective 2026-12-10. PIAs are however a "reasonable step" expected under APP 1 for high-risk processing (including AI, profiling, large-scale analytics) per OAIC guidance — failure to conduct a PIA for high-risk AI will be treated as evidence of non-compliance with APP 1. Specific instruments (e.g. the Children's Online Privacy Code, government data-sharing frameworks) do mandate PIAs in defined contexts.
These privacy-law definitions directly govern AI-driven profiling in hiring, lending, and insurance — even though the rules predate and never mention AI. The three-tier automation framework determines consent and opt-out requirements, making this one of the most consequential provisions for organizations using automated decision-making in Colorado.
Any organization using AI for profiling in Colorado — credit scoring, insurance underwriting, employment screening — must conduct a Data Protection Assessment under this rule, regardless of whether the AI system was the target of the regulation. This is the provision a lawyer friend called a "real sleeper" that many compliance teams miss.
Predates most US AI laws; sector-specific but establishes an early template for algorithmic discrimination regulation. Insurance industry must proactively demonstrate non-discrimination.
Commissioner rules require governance and testing frameworks for algorithmic models used in insurance underwriting and claims.
Tagged `sleeper` because the duty is AI-specific but lives inside a general consumer privacy act, so it binds by controller status rather than by anything the controller does with models. Every organization over the § 42-516 threshold — retailers, insurers, hospitals, employers — must now take a position in its published privacy notice on whether it collects, uses or sells personal data to train large language models, including the position that it does not. That makes it the first US statutory disclosure aimed squarely at training-data provenance and the cheapest available discovery tool: the notice is a dated public statement the Attorney General can hold a controller to. Note the statute says "large language models" specifically, not "artificial intelligence" or "automated decision systems", so a controller training a non-language model is outside the literal text.
India's foundational data protection law applies to all automated processing of personal data — including AI inference, profiling, and recommendation systems. No explicit ADM opt-out right (unlike GDPR Article 22), but data accuracy and consent obligations bind AI deployers handling Indian user data. Penalties reach ₹250 crore (~$30M USD) per breach.
Italy's secondary-use pathway for health data is a sleeper provision with global reach: any organisation conducting AI research using Italian patient data — including non-Italian researchers accessing Italian health datasets — must satisfy both the GDPR and a 30-day Garante notification before processing. This covers clinical AI model training, drug discovery AI, and public health AI research.
Maine put this rule in Title 10 (commerce and trade), not in a licensing chapter, which is what gives it reach beyond Maine licensees: § 1500-EE(2) binds any "person" who offers therapy to the Maine public through Internet-based AI, and § 1500-EE(3) converts a violation into an Unfair Trade Practices Act violation enforced by the Attorney General. The statute never calls itself an AI law in its operative duty — it is drafted as a licensure and trade-practices rule — yet the therapeutic-communication definition at § 1500-EE(1)(C)(3), "offering emotional support, reassurance or empathy in response to psychological or emotional distress", describes ordinary consumer companion-chatbot behavior, not only purpose-built therapy products. Advertising and offering are covered alongside providing, so marketing an AI mental-health product into Maine is itself the violation. The IRB carve-out mirrors Rhode Island's and Vermont's, which is now the settled shape of this exemption across the three states.
The statute reaches AI only indirectly. Art. 2 Fraction XIX defines "tratamiento" to include operations carried out by automated procedures, so processing personal data with AI is covered, and the Art. 14-17 privacy-notice duties apply. The consolidated text (Última Reforma DOF 14-11-2025) contains no occurrence of "inteligencia artificial" or "algoritmo", and Art. 15 does not require disclosure of algorithmic logic, significance, or consequences. Any such duty would have to come from the pending secondary regulations.
The statute provides a right to object, not a duty of oversight. Art. 26(II) lets a data subject oppose processing where their data undergoes automated processing that produces unwanted legal effects or significantly affects their interests, rights, or freedoms, and is intended to evaluate personal aspects — professional performance, economic situation, health, sexual preferences, reliability, or behaviour — without human intervention. The text imposes no human-in-the-loop requirement, no impact assessment, and no safeguards specific to agentic systems; those appeared in secondary commentary and, if they arrive, will come from the pending implementing regulations.
Rooted in general anti-discrimination law (NJ Law Against Discrimination), not an AI-specific statute — but N.J.A.C. 13:16 expressly reaches automated and AI decision tools, making employers liable for disparate impact and barring a "third-party vendor" defence.
This is the only duty in the chapter with an attached penalty schedule, so it is the likeliest enforcement route. Because § 40.1-5.5-2(8)(i) puts preparation and maintenance of therapy notes inside "supplementary support", any AI scribe or note-taking vendor sits inside the confidentiality perimeter — the practice's vendor contracts, retention, and training-data terms are what this section reaches in practice.
The duty runs to private healthcare providers and the facilities that employ them, not to a state agency — which is what puts it in scope here rather than treating it as a licensing rule, and it lands squarely on the ambient-scribe vendors selling into those private practices: the practice cannot lawfully deploy a scribe without a patient notification path and a per-visit review-and-attest step built into the workflow, with no sampling allowance and no materiality threshold. The statute's title advertises only notification; the review duty is the operative half and is easy to miss. Note the narrowing phrase "for that sole purpose" — the duty as drafted attaches to documentation use, and the Act says nothing about AI used for diagnosis or triage. The operative chapter is a single sentence creating these two linked duties, so they are modelled as one provision rather than two.
A framework act, not a compliance statute. Every operative article directs the state: fund AI development (Arts. 9-10), open government data (Art. 13), protect labour rights (Art. 15), clarify high-risk liability and establish relief or insurance mechanisms (Art. 17), and review all conflicting law within two years (Art. 18). Private-sector obligations arrive later and indirectly, through whatever sectoral regulators issue under Article 16(2) — which is what makes the two-year Article 18 deadline of 2028-01-14 the date to watch. **Open scope question:** on a strict reading of exclusion principle E4 (wrong audience), this Act may belong in `data/exclusions.md` rather than as a tracked instrument, since it creates no private-sector duty. It is retained for now because it is the enabling frame for every future Taiwanese AI rule; revisit when the first Article 16(2) sectoral regulations appear.
Creates de facto compliance obligations for any AI vendor selling LLMs to the US federal government. Agencies must require vendor documentation including model cards, data cards, acceptable use policies, and risk disclosures. Agencies must reject non-compliant models. Not branded as AI regulation, but effectively mandates transparency for a significant market segment.
Vendors must disclose training data provenance, limitations, and risk mitigations as a condition of federal procurement. While framed as ensuring "unbiased AI," the practical effect is a data governance disclosure requirement for the federal AI supply chain.
Establishes two Unbiased AI Principles — truth-seeking and ideological neutrality — that federal LLM procurements must comply with. Agencies must adopt procedures to enforce compliance and hold vendors accountable. Effectively creates a content-level compliance standard for the federal market.
An amending law buried inside the general informatization code, easy to miss: new Article 7-1 of the Law "On Informatization" bans sole reliance on AI system conclusions for any legally significant decision touching human rights and freedoms. No AI-specific statute exists to flag it — the duty binds private deployers of rights-affecting automated decisions through a two-paragraph insertion.
upcoming 64 provisions
Provisions approaching their enforcement date. Worth tracking now to prepare for compliance.
Australia's Privacy Act reforms make AI transparency mandatory through privacy law — not AI-specific legislation. Any organization using personal information in automated decisions must update its privacy policy to describe, in general terms, the kinds of personal information used and the kinds of decisions made or substantially assisted by ADM. Even "human in the loop" doesn't exempt you if the algorithm plays a substantial role.
The provenance chain's other end: the rest of the chapter marks content as synthetic, while this section marks content as camera-captured. It reaches hardware manufacturers rather than AI developers, so it lands on companies that may not otherwise track AI regulation — and default-on embedding (subdivision (a)(2)) is a firmware-level design decision with a long lead time.
Reporting runs to a public-health body rather than a regulator, and the Office must publish the data, so the reports become a public dataset on how often companion chatbots encounter user self-harm. The § 22603(d) requirement to use evidence-based measurement methods means the counting methodology is itself regulated.
Applies across all sectors in all ratifying states — including the US, UK, and EU — creating a transatlantic baseline for AI disclosure. Note the split: Art. 8 transparency and AI-content identification is a firm obligation, while the human-vs-AI notification in Art. 15(2) is drafted as "shall seek to ensure", so implementing states retain discretion.
Article 16 goes further than most voluntary frameworks by requiring States to assess whether specific AI uses should be subject to moratoria or outright bans — a tool available under binding international law that has no equivalent in current national AI regulations.
CETS 225 is the first international treaty to establish a right to contest AI decisions. Articles 14–15 create binding remedies and procedural safeguards — including appeal rights and notification — that States must embed in domestic law, surpassing any existing voluntary framework on human oversight.
HB 26-1263 was signed 2026-05-29 and adds subsections to C.R.S. § 6-1-1701 and adds § 6-1-1708 to part 17 of article 1 of title 6. SB 26-189, signed two weeks earlier on 2026-05-14, repeals and reenacts that same part 17 effective 2027-01-01 (tracked here as colorado-sb26-189). Whether § 6-1-1708 survives that repeal-and-reenactment unchanged is an open harmonization question for the revisor of statutes, and it lands on the same day these operator duties begin. Unresolved as of 2026-08-03 — no answer is asserted here. Separately, Colorado is the only 2026 state chatbot law that affirmatively requires age estimation by commercially reasonable or generally accepted methods and then deems the estimate to be knowledge of the minor's age, so age-blindness is not a defence. Note also that the age-estimation and willful-disregard sentences sit before the "on and after January 1, 2027" clause in the same paragraph; the 2027-01-01 date is recorded here because the clause governs the operator duties the estimate triggers.
The disclosure duty is written as prompt-responsive first — it "must be provided in response to user prompts regarding whether the service is artificially generated and not human" — and then specifies the delivery form by product type: a persistent visible disclaimer on screen products, an intermittent audio disclaimer on screenless products, or beginning-of-interaction plus a three-hour cadence. Colorado gives minors the same three-hour interval as adults, unlike Washington ESHB 2225, which drops the minor cadence to one hour.
Colorado sets two different standards of care inside the same subsection: sexual-content controls must be "technically feasible measures" (§ 6-1-1708(2)(c)) while emotional-dependence controls need only "reasonable measures" (§ 6-1-1708(2)(d)), so the sexual-content duty is the more demanding of the two. The emotional-dependence list reaches model behaviour rather than interface copy — the service must be prevented from explicitly claiming to be human or artificially sentient, from simulating romantic companionship, and from role-playing an adult-minor romantic relationship. The variable-reward ban at § 6-1-1708(2)(b) targets points or similar rewards at unpredictable intervals intended to increase engagement.
This is the provision with no analogue in the other 2026 state chatbot laws. The minor's own privacy tool must let the user turn off cross-session memory personalization — control over whether the service retains information from prior interactions or sessions to personalize future ones — and separately opt out of having their personal data used to train the service. No other state chatbot statute requires either control. Subsection (2)(g) also bolts on compliance with part 13 of article 1 of title 6, Colorado's existing minor-data privacy regime, so the operator inherits that part's duties by reference rather than restating them.
The general disclosure is unconditional — there is no reasonable-person trigger, so a plainly artificial service still discloses. Colorado's daily-reset cadence is distinctive: the disclosure is owed at the beginning of the user's first interaction for each day of interaction, then either every three hours in a continuous interaction or as a persistent visible disclosure. The false-representation bar at § 6-1-1708(5) covers four named professions — licensed health-care professionals, licensed legal professionals, licensed, certified, or registered mental health professionals, and qualified dietitians as described in § 6-1-707(1)(b) — and reaches advertising and interface copy as well as model outputs. Section 6-1-1708(7) preserves constitutional information access, does not require disclosure of trade secrets or confidential information, and does not authorize content moderation inconsistent with the United States Constitution.
Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says "but not including a law enforcement agency." That carve-out is unique among the 2026 state chatbot laws and rules out the wellness-check escalation pattern several operators use today. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.
This is a filing to a regulator, not a website self-disclosure — the contrast with Washington ESHB 2225 and Oregon, which require operators to publish crisis-referral counts themselves. It starts six months after the operator duties, on 2027-07-01, so the first report covers a period already under the § 6-1-1708(4) protocol. The Attorney General may expand the report by determining additional metrics necessary to judge the efficacy and reliability of safeguards, which is an open-ended content hook without a rulemaking procedure attached. Reports must exclude user identifiers and personal information, and measurement must use evidence-based methods.
The duty is an internal whistleblower channel rather than a report to the state — Connecticut regulates the flow of catastrophic-risk information inside the company and to its board, not to a regulator. The quarterly board-sharing requirement, with the carve-out preventing a report from reaching an officer it accuses, is the operative design: it makes suppression at the management layer a statutory violation.
Two dates matter and they are a year apart: the sections take effect 2026-10-01, but the duties attach only to technology deployed on or after 2027-10-01, which is the date recorded here. The developer-to-deployer information duty in § 8 is the structural piece — it makes the vendor responsible for supplying whatever the employer needs to meet its own disclosure duties, closing the "our vendor won't tell us" gap that undercuts comparable laws.
Connecticut's version goes further than California's or New York's in two ways: it requires escalation to clinically appropriate services when a user expresses risk *again after* an initial referral, and it separately requires measures preventing the companion from claiming to be human or generating output that contradicts its own AI disclosure. The second duty closes the gap a disclosure-only rule leaves open — a system that discloses at the top of a session and then insists it is human when asked.
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: a completed GDPR data protection impact assessment can now be cross-referenced rather than duplicated, and the AI Office must ship a questionnaire template.
The three-limb definition in § 39-5-6(a)(1)(A) is conjunctive — memory, unprompted emotional questioning, and sustained personal dialogue must all be present — which is a narrower gate than California SB 243's reasonable-person test, but the recurring-disclosure cadence is stricter: every three hours generally, every hour for known or marketed-to minors. Subsection (h) is the only place the Act addresses licensed professionals: it bars an operator from programming a chatbot to claim mental health, behavioral health, medical, or counseling licensure unless the operator is lawfully authorized to provide those services. That is a proviso, not an exemption — a licensed clinician's companion chatbot is still fully subject to § 39-5-6.
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
Georgia routes the same crisis-referral count that California SB 243 § 22603 sends to the Office of Suicide Prevention straight to the public website instead. There is no regulator to file with and no prescribed form, so the disclosure becomes evidence available to the Attorney General and to plaintiffs without any request. Mapped to incident-reporting for comparability with SB 243's annual crisis reporting, though the channel is public disclosure rather than a filing with an authority.
'Parental controls' is defined at § 39-5-6(a)(7) — usage limits, feature restrictions, transparency tools — but the defined term is not used in the operative duty, which is written in § 39-5-6(i) as 'reasonable tools' to manage screen time and account settings. The duty is triggered only for accounts *known* to belong to minors, so it depends on whatever age signal the operator already holds; § 39-5-6(j) age assurance is not a general gate that would generate that knowledge. The mapping to human-oversight is the closest available fit for a user- and guardian-facing control duty; it is not an oversight-of-automated-decisions obligation in the usual sense.
This is not a general age-verification mandate, despite how the Act is often summarized. The trigger is narrow — access to a feature or mode that may generate sexually explicit synthetic content — and the method is risk-proportionate, so age estimation or account-based assurance can satisfy it where identity verification is not necessary. The binding weight sits in the data rules that follow: minimize collection, no sale, single-purpose use, and a 24-hour retention ceiling for age-assurance data unless a longer period is permitted by law.
Idaho's enterprise carve-outs (§ 48-2102(2)(b)(v), (viii)) are broader than California SB 243's, so the Act lands almost entirely on consumer-facing assistants and companion apps. The § 48-2104(4) duty is the unusual one: it regulates model behaviour rather than interface copy, requiring reasonable measures against simulated emotional dependence, romantic or sexual innuendo, and adult-minor romantic role-play for minor account holders.
Structured as an adoption duty with a reasonable-efforts floor, not California SB 243's engagement gate: Idaho does not bar the service from operating without a protocol, does not require the protocol to be published, and imposes no annual reporting. The practical consequence is that the crisis protocol is only visible to the Attorney General on investigation.
The § 48-2104(2) ban on variable-ratio rewards is the first US AI statute to regulate an engagement mechanic by name rather than its effects, and it is intent-qualified — the reward must be given with intent to encourage increased engagement. Actual-knowledge-or-reasonable-certainty framing means the duties bite only once an operator has age signals, so age assurance is not itself mandated.
The only provision in the chapter that requires a product surface rather than a restraint. The two-tier design — parental tools mandatory under 13, "as appropriate based on relevant risks" for 13 to 17 — leaves the older-minor tier undefined and is the most likely site of enforcement disagreement.
Two disclosure regimes sit side by side. The general one in § 554J.3 fires only on a reasonable-individual mistaken-for-human test, so a service that visibly presents as a bot may owe nothing. The minor-account-holder one in § 554J.2(1) has no such trigger: if the operator knows or is reasonably certain the account holder is under 18, the disclaimer is owed unconditionally. Both routes accept a persistent visible disclaimer, which is the cheap compliance path and is likely what most operators will build.
This is the provision with no California analogue. SB 243 regulates the disclosure; Iowa regulates the persona. Barring statements that "simulate emotional dependence" or "simulate a romantic interaction" reaches model behaviour rather than interface copy, which means the compliance artifact is a system prompt, a fine-tune, or an output classifier — not a banner. It is drafted as a reasonable-measures standard, so the question at enforcement will be what the operator did to prevent the output, not whether the output ever occurred.
The variable-reward bar in § 554J.2(2) is the first US AI statute to regulate an engagement mechanic rather than an output. It borrows the language of intermittent reinforcement — "points or similar rewards at unpredictable intervals" — and is gated on intent to encourage increased engagement, which makes internal growth documents the natural evidence. Note the drafting asymmetry: § 554J.2(2) reaches a "minor user" while § 554J.2(3) reaches a "minor account holder", so the reward bar plausibly applies without an account.
The statute requires the tools to exist but says nothing about what they must control, so the compliance floor is a settings surface rather than a defined set of parental permissions. The § 554J.2(5)(c) "as appropriate based on relevant risks" formulation is the only risk-proportionate duty in the chapter and is left entirely to the Attorney General's chapter 17A rulemaking to give content.
Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.
The scienter standard is the highest in the chapter — "knowingly and intentionally cause or program" — so an emergent therapeutic persona the operator did not design is outside this section, though it may still be caught by the reasonable-measures duty in § 554J.2(4). The bar is on representation, not on function: a service may in fact behave therapeutically as long as it does not lead a reasonable individual to believe it is a licensed practice.
The act is not yet codified into numbered Neb. Rev. Stat. sections on the face of the slip law, so provisions here are cited to the session-law section numbers of LB 525. Two design choices separate Nebraska from the other 2026 state chatbot statutes: a persistent visible disclaimer is an accepted substitute for the three-hour reminder cadence, which Washington's ESHB 2225 does not allow, and the duty attaches to minor *account holders* rather than to any minor user, so an operator that runs no accounts never triggers it.
Nebraska's engagement ban is narrower than Washington's eight-technique list: it reaches only variable-ratio rewards — points or similar rewards at unpredictable intervals with intent to increase engagement — leaving other retention mechanics untouched. The anthropomorphism duty is unusual in naming simulated emotional dependence and adult-minor romantic role-play as specific outputs the operator must take reasonable measures to prevent.
Nebraska is the only one of the 2026 state chatbot statutes to impose an affirmative account-controls duty, and it splits at age thirteen: parents of under-13 account holders get the tools as of right, while parents of 13-and-older account holders get "related tools" only "as appropriate based on relevant risks" — a risk-calibrated standard the act leaves to the operator to apply.
Unlike Washington's unconditional disclosure, Nebraska's general duty triggers only on the reasonable-person misleading test, so a service that is obviously artificial owes nothing under sec. 15 — the account-based minor duty in sec. 14(1) is the unconditional one. Sec. 17 bars only the explicit representation that the service is designed to deliver professional mental or behavioral health care, and it carries a knowing-and-intentional scienter element, so incidental therapeutic-sounding output is not itself a violation.
Nebraska states the crisis duty in a single sentence and, unlike Washington, does not gate deployment on having the protocol, name eating disorders, or require any public disclosure of referral counts — the duty is to adopt a protocol and make reasonable efforts to refer. The "includes, but is not limited to" framing leaves the floor open, which means the Attorney General, not the statute, will set the practical content of an adequate protocol.
Oregon's definition is narrower and more mechanical than California's — it requires all three of cross-session memory, unprompted emotional questioning, and sustained personal dialogue, so a system that merely remembers a user is outside the act. The minor-facing break reminder in § 1(4)(b)(B) is a session-flow mandate, not a copy change.
The duty is a gate on access, not a best-efforts standard: without the protocol the operator may not allow Oregon users access at all. Two features go beyond California SB 243 — the protocol must use evidence-based detection methods rather than merely respond after the fact, and § 1(3)(b)(B) requires clinical best practices for escalated intervention when a user keeps expressing intent after the first referral.
This is the provision with no California analogue. Section 1(4)(c) bans variable-ratio reward schedules, guilt-inducing exit friction, and misrepresentation of the system's identity, capabilities, or training data — engagement-optimisation patterns, regulated as product design rather than as speech. Operators serving mixed-age audiences will need an age signal to know which regime applies, though the act imposes no age-verification duty.
Unlike California SB 243, which reports to the Office of Suicide Prevention, Oregon's report goes nowhere — it is self-published to a publicly accessible website with no filing, no recipient agency, and no review. Enforcement of the reporting duty is therefore the same private suit that covers the rest of section 1.
The Reglamento is in force since 2026-01-22, but the Primera Disposición Complementaria Final phases private-sector compliance with Art. 25 and Título VI Cap. II by sector: health, education, justice, security, economy and finance by 2026-09-10; transport, commerce and labour by 2027-09-10; production, agriculture, energy and mining by 2028-09-10; everything else by 2029-09-10. Small enterprises get until 2027-09-10 and microenterprises until 2028-09-10 regardless of sector. SGTD lineamientos on algorithmic transparency (Art. 25.4) are still pending.
Same sector phase-in as the rest of Art. 25: earliest tier (health, education, justice, security, economy, finance) by 2026-09-10, remaining sectors through 2029-09-10, with extended MYPE deadlines.
Part of Título VI Cap. II (private-sector obligations), phased in by sector from 2026-09-10 to 2029-09-10 under the Primera Disposición Complementaria Final. Public administration entities carry parallel and stricter duties under Cap. I (Arts. 28–30), including mandatory NTP-ISO/IEC 42001 use and a mandatory (not voluntary) impact assessment — those public-sector duties are noted here but not modelled as separate provisions.
Sector phase-in from 2026-09-10 to 2029-09-10 as for the rest of Título VI Cap. II. The anti-automation-bias training requirement is unusually explicit: staff must be trained specifically so as not to be biased by the system's outputs.
The private-sector assessment is explicitly voluntary ("de manera voluntaria", Art. 32.1) — a deliberate asymmetry with the mandatory public-sector assessment of Art. 30.1. The binding edge is documentary: whoever performs one must retain the findings for three years as evidence producible to judicial or administrative authorities. SGTD recognition incentives (Art. 32.4) and reference guidance (Art. 32.5) frame it as promoted practice.
Structured as a gate on operation, not a best-efforts duty: it is unlawful to operate or provide the companion at all unless the protocol is built in. Rhode Island's definition is narrower than California SB 243's reasonable-person test — the three limbs in § 6-63-1(1)(i) are conjunctive, so a system that never asks unprompted emotion-based questions falls outside the chapter. But the protocol scope is broader on one axis: it reaches threatened physical harm to others (§ 6-63-2(a)(2)), which California does not cover.
Unconditional and age-blind, unlike California SB 243, where the opening disclosure turns on a reasonable-person test and the three-hour repeat applies only to known minors. Rhode Island requires both the opening notice and the three-hour repeat for every user, which makes it a session-flow design constraint rather than a copy change. The notice may be verbal or written, so voice-first products are covered without a screen.
The statute fixes the reporting floor — activation counts — and leaves "related metrics" undefined, so the reportable set is whatever the Attorney General's office asks for; there is no rulemaking grant in the chapter to constrain that. Because the AG must publish aggregated data, the counts become a public dataset comparable across operators, which is the same disclosure dynamic as California's Office of Suicide Prevention reports.
A framework act, not a compliance statute. Every operative article directs the state: fund AI development (Arts. 9-10), open government data (Art. 13), protect labour rights (Art. 15), clarify high-risk liability and establish relief or insurance mechanisms (Art. 17), and review all conflicting law within two years (Art. 18). Private-sector obligations arrive later and indirectly, through whatever sectoral regulators issue under Article 16(2) — which is what makes the two-year Article 18 deadline of 2028-01-14 the date to watch. **Open scope question:** on a strict reading of exclusion principle E4 (wrong audience), this Act may belong in `data/exclusions.md` rather than as a tracked instrument, since it creates no private-sector duty. It is retained for now because it is the enabling frame for every future Taiwanese AI rule; revisit when the first Article 16(2) sectoral regulations appear.
Establishes a voluntary framework under which frontier developers may engage the government to have models designated "covered frontier models" and provide up to 30 days of pre-release access for evaluation before other trusted partners. The framework itself does not yet exist — Treasury, NSA, and CISA must design it within 60 days. Section 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement, so participation is opt-in. Worth watching: a voluntary pre-release evaluation regime can harden into a de facto procurement or trusted-vendor expectation.
Directs Treasury, NSA, and CISA to develop and maintain a classified benchmarking process that assesses the advanced cyber capabilities of AI models and sets the threshold for designating a "covered frontier model." This is the first federal mechanism defining a frontier-model threshold by capability rather than compute. Developers engage the designation process voluntarily; assessments are shared with developers as appropriate. The benchmark and threshold are pending — agencies have 60 days to develop them.
Directs the Secretary of the Treasury to form an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and critical-infrastructure operators, to coordinate vulnerability scanning, validate discovered vulnerabilities, and prioritize remediation and patch distribution. To be formed within 30 days. Participation is voluntary, but for AI providers and critical-infrastructure operators it functions as a coordinated channel for software-vulnerability discovery and remediation.
Washington's general disclosure is unconditional — unlike California SB 243 and Oregon ch. 85, it does not turn on whether a reasonable person would be misled, so every covered chatbot discloses at the start of the interaction and every three hours regardless of how obviously artificial it is. Sec. 3(3) adds a model-behaviour duty rather than a copy duty: the system must be constrained from claiming to be human when asked, which is an alignment requirement in statute. The educational-tools carve-out in Sec. 2(1)(b)(iv) has no California or Oregon analogue.
The "directed to minors" trigger means an operator cannot avoid this section by declining to determine user age — audience design alone brings the product in. The eight enumerated manipulative techniques in Sec. 4(1)(c) are the most detailed engagement-design ban of the three 2026 companion statutes, reaching in-app monetisation framed as relationship maintenance (Sec. 4(1)(c)(viii)) and outputs promoting isolation from family (Sec. 4(1)(c)(v)). Minors get a one-hour reminder cadence against the three-hour general rule.
Structured as a gate on deployment: no protocol, no chatbot. Washington is the only one of the three 2026 companion statutes to name eating disorders explicitly within the detection duty (Sec. 5(2)(a)), which pulls disordered-eating content into a self-harm safety pipeline that most moderation stacks treat separately. Unlike Oregon, no specific hotline is mandated — "a suicide hotline or crisis text line" is sufficient.
No regulator receives this. Like Oregon, Washington makes the crisis-referral count a public self-disclosure rather than a filing — but it must appear both on the operator's websites and inside every mobile or web application through which the companion is offered, which is a stricter placement duty than either California or Oregon imposes. Sec. 5(3) sets no annual deadline, so the disclosure is a standing obligation that must carry the preceding calendar year's count.
high-impact 74 provisions
Provisions with significant penalties, broad scope, or sweeping requirements that affect many organizations.
NSW's Digital Work Systems Act catches every employer using algorithmic scheduling, AI-driven monitoring, automated performance management, or platform-based work allocation. The definition of "digital work system" explicitly includes algorithms, AI, automation, and online platforms — making this one of the broadest workplace AI laws globally. Any company operating in NSW with AI-assisted HR, logistics, or workforce management tools must assess and manage WHS risks from those systems.
The disclosure runs to training inputs rather than outputs, which makes it the counterpart to the provenance duties in the California AI Transparency Act: one documents what went into the model, the other marks what comes out. It bites on every substantial modification — a new version, release, update, retraining, or fine-tune that materially changes functionality or performance — so it is a recurring release-gate obligation, not a one-time filing. There is no penalty provision and no named enforcer in the chapter.
Operative since 2026-08-02, the same day EU AI Act Article 50 reached general application — AB 853 moved this chapter's date from 2026-01-01 to match. Providers building C2PA-style provenance for one regime largely satisfy the other. Two caveats on this entry: the threshold attaches to the GenAI system, not the parent company, so a large firm's smaller system may fall outside it; and SB 1000, an urgency bill on the Assembly Third Reading File as of 2026-08-03, would delete that threshold and the manifest-disclosure duty with immediate effect on signature (see data/watch-list.md).
The disclosure trigger is a reasonable-person test rather than a product category, so it reaches any conversational system built to sustain a relationship — the exclusions in § 22601(b)(2) do the scoping work, and they are narrow. The three-hour break reminder for known minors is an unusual design mandate: it constrains session flow, not just copy.
The duty is structured as a gate, not a best-efforts standard: without the protocol, the operator must prevent the chatbot from engaging with users at all. Publication of the protocol turns an internal safety process into a public document that plaintiffs can read before suing under § 22605.
Applies across all sectors in all ratifying states — including the US, UK, and EU — creating a transatlantic baseline for AI disclosure. Note the split: Art. 8 transparency and AI-content identification is a firm obligation, while the human-vs-AI notification in Art. 15(2) is drafted as "shall seek to ensure", so implementing states retain discretion.
Article 16 goes further than most voluntary frameworks by requiring States to assess whether specific AI uses should be subject to moratoria or outright bans — a tool available under binding international law that has no equivalent in current national AI regulations.
CETS 225 is the first international treaty to establish a right to contest AI decisions. Articles 14–15 create binding remedies and procedural safeguards — including appeal rights and notification — that States must embed in domestic law, surpassing any existing voluntary framework on human oversight.
HB 26-1263 was signed 2026-05-29 and adds subsections to C.R.S. § 6-1-1701 and adds § 6-1-1708 to part 17 of article 1 of title 6. SB 26-189, signed two weeks earlier on 2026-05-14, repeals and reenacts that same part 17 effective 2027-01-01 (tracked here as colorado-sb26-189). Whether § 6-1-1708 survives that repeal-and-reenactment unchanged is an open harmonization question for the revisor of statutes, and it lands on the same day these operator duties begin. Unresolved as of 2026-08-03 — no answer is asserted here. Separately, Colorado is the only 2026 state chatbot law that affirmatively requires age estimation by commercially reasonable or generally accepted methods and then deems the estimate to be knowledge of the minor's age, so age-blindness is not a defence. Note also that the age-estimation and willful-disregard sentences sit before the "on and after January 1, 2027" clause in the same paragraph; the 2027-01-01 date is recorded here because the clause governs the operator duties the estimate triggers.
Colorado sets two different standards of care inside the same subsection: sexual-content controls must be "technically feasible measures" (§ 6-1-1708(2)(c)) while emotional-dependence controls need only "reasonable measures" (§ 6-1-1708(2)(d)), so the sexual-content duty is the more demanding of the two. The emotional-dependence list reaches model behaviour rather than interface copy — the service must be prevented from explicitly claiming to be human or artificially sentient, from simulating romantic companionship, and from role-playing an adult-minor romantic relationship. The variable-reward ban at § 6-1-1708(2)(b) targets points or similar rewards at unpredictable intervals intended to increase engagement.
This is the provision with no analogue in the other 2026 state chatbot laws. The minor's own privacy tool must let the user turn off cross-session memory personalization — control over whether the service retains information from prior interactions or sessions to personalize future ones — and separately opt out of having their personal data used to train the service. No other state chatbot statute requires either control. Subsection (2)(g) also bolts on compliance with part 13 of article 1 of title 6, Colorado's existing minor-data privacy regime, so the operator inherits that part's duties by reference rather than restating them.
The general disclosure is unconditional — there is no reasonable-person trigger, so a plainly artificial service still discloses. Colorado's daily-reset cadence is distinctive: the disclosure is owed at the beginning of the user's first interaction for each day of interaction, then either every three hours in a continuous interaction or as a persistent visible disclosure. The false-representation bar at § 6-1-1708(5) covers four named professions — licensed health-care professionals, licensed legal professionals, licensed, certified, or registered mental health professionals, and qualified dietitians as described in § 6-1-707(1)(b) — and reaches advertising and interface copy as well as model outputs. Section 6-1-1708(7) preserves constitutional information access, does not require disclosure of trade secrets or confidential information, and does not authorize content moderation inconsistent with the United States Constitution.
Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says "but not including a law enforcement agency." That carve-out is unique among the 2026 state chatbot laws and rules out the wellness-check escalation pattern several operators use today. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.
The duty is an internal whistleblower channel rather than a report to the state — Connecticut regulates the flow of catastrophic-risk information inside the company and to its board, not to a regulator. The quarterly board-sharing requirement, with the carve-out preventing a report from reaching an officer it accuses, is the operative design: it makes suppression at the management layer a statutory violation.
The first US statute in this reference to name the Coalition for Content Provenance and Authenticity standard in its own text rather than gesturing at "widely accepted industry standards" as California's SB 942 does. The one-million-users-per-month threshold parallels California's covered-provider test, so a provider building C2PA provenance for California largely satisfies Connecticut — the same convergence the EU Article 50 and California alignment produced.
Two dates matter and they are a year apart: the sections take effect 2026-10-01, but the duties attach only to technology deployed on or after 2027-10-01, which is the date recorded here. The developer-to-deployer information duty in § 8 is the structural piece — it makes the vendor responsible for supplying whatever the employer needs to meet its own disclosure duties, closing the "our vendor won't tell us" gap that undercuts comparable laws.
Not a disclosure rule but a liability rule, and it is the sharpest incentive in the Act: using an automated employment-related decision technology is expressly not a defense to a discrimination complaint, while evidence of anti-bias testing may be considered in the employer's favour. That asymmetry converts bias testing from a good practice into the only available mitigation, which is why it belongs under bias-prevention rather than with the disclosure provisions.
Connecticut's version goes further than California's or New York's in two ways: it requires escalation to clinically appropriate services when a user expresses risk *again after* an initial referral, and it separately requires measures preventing the companion from claiming to be human or generating output that contradicts its own AI disclosure. The second duty closes the gap a disclosure-only rule leaves open — a system that discloses at the top of a session and then insists it is human when asked.
Two distinct disclosure regimes ride in one act. The § 1 subscription rules attach at contract formation and renewal, which puts AI-specific terms into consumer contract law rather than product design. The § 5(b) companion notice takes effect later, on 2027-01-01, and offers operators a choice between a persistent static notice visible throughout the interaction and a notice repeated at intervals — the persistent option has no counterpart in the California or New York statutes.
This is a second, separate assessment sitting alongside the CTDPA data protection assessment in § 42-522(b) — a controller doing legal-effect profiling now owes both, and the two have different content. The seven elements read as an AI model card written into privacy law: inputs, outputs, customization data, performance metrics, known limitations, transparency measures, and post-deployment monitoring. § 42-522(g)(2) is the date that matters operationally: the impact assessment duty applies only to processing activities created or generated **on or after 2026-08-01** and is expressly not retroactive, one month later than the section's own 2026-07-01 effective date, and a separate clock from the 2023-07-01 line that governs data protection assessments under § 42-522(g)(1).
Tagged `sleeper` because the duty is AI-specific but lives inside a general consumer privacy act, so it binds by controller status rather than by anything the controller does with models. Every organization over the § 42-516 threshold — retailers, insurers, hospitals, employers — must now take a position in its published privacy notice on whether it collects, uses or sells personal data to train large language models, including the position that it does not. That makes it the first US statutory disclosure aimed squarely at training-data provenance and the cheapest available discovery tool: the notice is a dated public statement the Attorney General can hold a controller to. Note the statute says "large language models" specifically, not "artificial intelligence" or "automated decision systems", so a controller training a non-language model is outside the literal text.
Filed under `risk-assessment` rather than `data-governance` because the ongoing compliance process the section creates is the § 42-529b(b) impact assessment — six enumerated elements, review on any material change to the profiling operations, and documentation kept for the longer of three years after the operations cease or as long as the service is offered. The consent gate in § 42-529a(b)(3)(B) is a condition on a single processing activity rather than a sustained process, and § 42-529a(a) ties the two together by giving a controller that complies with § 42-529b a rebuttable presumption of reasonable care in any Attorney General enforcement action — the assessment is the safe harbor, so it is where the compliance weight sits. Two scope moves are easy to miss. The consent gate was broadened from profiling in furtherance of any **fully** automated decision to **any** automated decision, so a human reviewer in the loop no longer takes a minor's profiling outside it — the same widening the act made to the adult opt-out in § 42-518. And the assessment trigger in § 42-529b(b) is any profiling at all by a service offered to minors, not only legal-effect profiling; only the first of the six elements is qualified by legal or similarly significant effects. Separately, § 42-529d(d)(4) permits processing a minor's personal data for legal-effect profiling solely to detect or correct bias, on five conditions including deletion once the processing is complete, pseudonymization and other industry-standard security measures, strict documented access controls, and no third-party transmission or access — a construction rule creating a safe harbor rather than an obligation, so it is recorded here rather than as its own provision.
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02.
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: a completed GDPR data protection impact assessment can now be cross-referenced rather than duplicated, and the AI Office must ship a questionnaire template.
The three-limb definition in § 39-5-6(a)(1)(A) is conjunctive — memory, unprompted emotional questioning, and sustained personal dialogue must all be present — which is a narrower gate than California SB 243's reasonable-person test, but the recurring-disclosure cadence is stricter: every three hours generally, every hour for known or marketed-to minors. Subsection (h) is the only place the Act addresses licensed professionals: it bars an operator from programming a chatbot to claim mental health, behavioral health, medical, or counseling licensure unless the operator is lawfully authorized to provide those services. That is a proviso, not an exemption — a licensed clinician's companion chatbot is still fully subject to § 39-5-6.
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
The codified section number is not on the face of the act — Sec. 3 adds "a new section to part I" of ch. 481B "to be appropriately designated", so provisions are cited by the subsection letters (a) to (i) that do appear in the enacted text until the revisor publishes the number. Hawaii is the only 2026 state companion-AI statute already in force; Washington, California, Oregon and Nebraska all run from 2027. The minor cadence is the strictest in the cohort: at least once per hour, and the reminder must also tell the user to take a break from the chat, where Washington and Nebraska stop at a three-hour general interval. A persistent visible disclaimer under § (b)(1) is an accepted alternative to the whole session-start-plus-hourly cadence, which no other state in the cohort allows. The general disclosure in § (a) keeps a reasonable-person trigger, unlike Washington's unconditional duty.
Two duties here have almost no analogue in the cohort. § (c)(2) requires evidence-based methods for measuring suicidal ideation and the risk of self-harm — a methodological standard rather than a "reasonable measures" standard, which only Oregon and Colorado otherwise impose. § (c)(5) reaches outward: reasonable measures must prevent outputs encouraging the user to cause serious bodily injury to another person, and no other state statute in this cohort covers harm to third parties at all. § (c)(3) also bars the companion from representing that it is designed to provide professional mental or behavioral health care, which pulls the section into scope-of-practice territory alongside consumer protection.
The trigger is actual knowledge or reasonable certainty, not an age-estimation duty — the legislature's findings in Sec. 2 expressly say regulation should "proactively avoid the mandatory collection of data by technology companies such as identity documentation for age verification purposes", so Hawaii deliberately declines the Colorado-style duty to estimate age. § (d)(1) targets variable-ratio reward schedules by name (points or similar rewards at unpredictable intervals intended to encourage increased engagement), which is a narrower and more mechanism-specific engagement ban than Washington's eight-technique list. § (d)(4) is the cohort's parental-tools duty: screen-time and account-settings controls must be available to the user and to parents and guardians alike.
Idaho's enterprise carve-outs (§ 48-2102(2)(b)(v), (viii)) are broader than California SB 243's, so the Act lands almost entirely on consumer-facing assistants and companion apps. The § 48-2104(4) duty is the unusual one: it regulates model behaviour rather than interface copy, requiring reasonable measures against simulated emotional dependence, romantic or sexual innuendo, and adult-minor romantic role-play for minor account holders.
The § 48-2104(2) ban on variable-ratio rewards is the first US AI statute to regulate an engagement mechanic by name rather than its effects, and it is intent-qualified — the reward must be given with intent to encourage increased engagement. Actual-knowledge-or-reasonable-certainty framing means the duties bite only once an operator has age signals, so age assurance is not itself mandated.
India's first binding synthetic media obligations: intermediaries enabling AI-generated content (deepfakes, audio/video synthesis) must embed permanent provenance metadata and prominent labels — and prevent their removal. Non-compliance forfeits safe harbor under the IT Act 2000.
Two disclosure regimes sit side by side. The general one in § 554J.3 fires only on a reasonable-individual mistaken-for-human test, so a service that visibly presents as a bot may owe nothing. The minor-account-holder one in § 554J.2(1) has no such trigger: if the operator knows or is reasonably certain the account holder is under 18, the disclaimer is owed unconditionally. Both routes accept a persistent visible disclaimer, which is the cheap compliance path and is likely what most operators will build.
This is the provision with no California analogue. SB 243 regulates the disclosure; Iowa regulates the persona. Barring statements that "simulate emotional dependence" or "simulate a romantic interaction" reaches model behaviour rather than interface copy, which means the compliance artifact is a system prompt, a fine-tune, or an output classifier — not a banner. It is drafted as a reasonable-measures standard, so the question at enforcement will be what the operator did to prevent the output, not whether the output ever occurred.
The variable-reward bar in § 554J.2(2) is the first US AI statute to regulate an engagement mechanic rather than an output. It borrows the language of intermittent reinforcement — "points or similar rewards at unpredictable intervals" — and is gated on intent to encourage increased engagement, which makes internal growth documents the natural evidence. Note the drafting asymmetry: § 554J.2(2) reaches a "minor user" while § 554J.2(3) reaches a "minor account holder", so the reward bar plausibly applies without an account.
Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.
Italy is the first EU member state to legislate sector-specific AI rules beyond the EU AI Act. For healthcare AI, the law establishes a hard prohibition on AI making autonomous clinical decisions — physicians retain ultimate authority regardless of AI recommendation quality. Any healthcare organisation deploying diagnostic or treatment AI in Italy must build physician-override workflows into every clinical AI deployment.
Italy extends AI transparency duties into employment and child contexts that sit beyond the EU AI Act's direct scope. Employers using AI in recruitment or performance evaluation must disclose AI involvement to workers — creating a specific notification duty for HR technology deployments. The parental consent requirement for under-14s applies to any AI-powered product or service used by children, including education platforms, apps, and consumer AI.
Kazakhstan's AI law is the first in Central Asia, establishing a three-tier risk framework (minimum/medium/high) that directly mirrors the EU AI Act's approach. High-risk AI systems must use the state National AI Platform for development and testing — a unique state-platform requirement not seen in Western AI laws.
Kazakhstan mandates machine-readable markings on all distributed synthetic AI outputs (images, text, video) — a technically specific requirement that affects any AI system generating content for Kazakh users. Combined with advance user notification of AI involvement, this creates dual transparency obligations covering both the content itself and the service interaction.
Kazakhstan's prohibition list covers social scoring and biometric discrimination — two categories that directly constrain AI systems used in hiring, lending, and public services. The ban on subconscious manipulation techniques is broadly worded and could catch persuasion AI, recommender systems, and targeted advertising tools.
Maine put this rule in Title 10 (commerce and trade), not in a licensing chapter, which is what gives it reach beyond Maine licensees: § 1500-EE(2) binds any "person" who offers therapy to the Maine public through Internet-based AI, and § 1500-EE(3) converts a violation into an Unfair Trade Practices Act violation enforced by the Attorney General. The statute never calls itself an AI law in its operative duty — it is drafted as a licensure and trade-practices rule — yet the therapeutic-communication definition at § 1500-EE(1)(C)(3), "offering emotional support, reassurance or empathy in response to psychological or emotional distress", describes ordinary consumer companion-chatbot behavior, not only purpose-built therapy products. Advertising and offering are covered alongside providing, so marketing an AI mental-health product into Maine is itself the violation. The IRB carve-out mirrors Rhode Island's and Vermont's, which is now the settled shape of this exemption across the three states.
The allocation of liability is unqualified: § 2113(2)(A) makes the licensee responsible for "all interactions, outputs and data use" associated with the AI, with no carve-out for vendor-controlled design or algorithms — the opposite of Rhode Island's § 40.1-5.5-3(c)(2), which expressly excludes vendor-controlled system design from provider responsibility. A Maine licensee therefore cannot contract that residue away, which is what pushes the duty onto vendor selection and configuration. The prohibitions at § 2113(4) fix the human-in-the-loop boundary — no independent therapeutic decisions, no direct therapeutic interaction with clients, and no recommendation or treatment plan that has not been reviewed and approved by the licensee. P.L. 2026 ch. 687 replicates § 2113 verbatim across six further licensing chapters (32 M.R.S. §§ 2600-G, 3300-J, 3820-A, 6207-D, 7009, and 13870), so the same duty attaches to every board that licenses a mental-health profession in Maine; the rules implementing it are major substantive rules under 5 M.R.S. ch. 375, subch. 2-A, meaning they must go back to the Legislature for review before final adoption.
This is the requirement neither Vermont nor Rhode Island has: Maine permits AI supplementary support "only when the client's therapeutic session is recorded or transcribed" (§ 2113(3)). That is an affirmative surveillance precondition, not a restriction on surveillance — a practice that wants an AI scribe or progress-tracking tool must first put the session on the record. Paired with it is a consent definition (§ 2113(1)(C)) that is unusually strict even against Rhode Island's: consent must be a clear, explicit, affirmative act communicating express, informed, voluntary, specific, unambiguous written agreement, revocable by the client, and it expressly is not acceptance of a general or broad terms-of-use agreement, not hovering over, muting, pausing, or closing electronic content, and not anything obtained through deceptive actions. The disclosure at § 2113(3)(A)(3) reaches further than either sibling statute: the client must be told in writing how session data will be stored, retained, **used for training**, and deleted on termination of services — a written commitment about training-data use, made per client. And § 2113(5) bars the licensee from denying or refusing treatment because the client withheld consent, so declining AI is genuinely costless for the client and fully blocking for the licensee. Any client waiver of the section is void as contrary to public policy (§ 2113(11)), which forecloses the intake-paperwork workaround.
Malta's dual-authority model (MDIA for market surveillance, IDPC for fundamental rights) creates a practical enforcement structure that other small EU member states may follow. The early classification requirement means deployers must proactively assess whether their AI systems fall under Annex III high-risk categories before placing them on the Maltese market — not wait for a regulator to classify them.
The act is not yet codified into numbered Neb. Rev. Stat. sections on the face of the slip law, so provisions here are cited to the session-law section numbers of LB 525. Two design choices separate Nebraska from the other 2026 state chatbot statutes: a persistent visible disclaimer is an accepted substitute for the three-hour reminder cadence, which Washington's ESHB 2225 does not allow, and the duty attaches to minor *account holders* rather than to any minor user, so an operator that runs no accounts never triggers it.
Nebraska's engagement ban is narrower than Washington's eight-technique list: it reaches only variable-ratio rewards — points or similar rewards at unpredictable intervals with intent to increase engagement — leaving other retention mechanics untouched. The anthropomorphism duty is unusual in naming simulated emotional dependence and adult-minor romantic role-play as specific outputs the operator must take reasonable measures to prevent.
Unlike Washington's unconditional disclosure, Nebraska's general duty triggers only on the reasonable-person misleading test, so a service that is obviously artificial owes nothing under sec. 15 — the account-based minor duty in sec. 14(1) is the unconditional one. Sec. 17 bars only the explicit representation that the service is designed to deliver professional mental or behavioral health care, and it carries a knowing-and-intentional scienter element, so incidental therapeutic-sounding output is not itself a violation.
Nebraska states the crisis duty in a single sentence and, unlike Washington, does not gate deployment on having the protocol, name eating disorders, or require any public disclosure of referral counts — the duty is to adopt a protocol and make reasonable efforts to refer. The "includes, but is not limited to" framing leaves the floor open, which means the Attorney General, not the statute, will set the practical content of an adequate protocol.
Structured as a prohibition on operating without the protocol, so the compliance question is binary rather than a standard of care. The three-part definition of an AI companion in § 1700(4)(a) is conjunctive — memory across sessions, unprompted emotion-based questions, and sustained personal dialogue — which is narrower than California's SB 243 test and turns on product design rather than on marketing category.
The cadence rule cuts both ways: the notice need not appear more than once per day, but must appear at least every three hours within a continuing interaction. New York and California both settled on a three-hour interval, though New York applies it to all users while California's applies only to users known to be minors.
Oregon's definition is narrower and more mechanical than California's — it requires all three of cross-session memory, unprompted emotional questioning, and sustained personal dialogue, so a system that merely remembers a user is outside the act. The minor-facing break reminder in § 1(4)(b)(B) is a session-flow mandate, not a copy change.
The duty is a gate on access, not a best-efforts standard: without the protocol the operator may not allow Oregon users access at all. Two features go beyond California SB 243 — the protocol must use evidence-based detection methods rather than merely respond after the fact, and § 1(3)(b)(B) requires clinical best practices for escalated intervention when a user keeps expressing intent after the first referral.
This is the provision with no California analogue. Section 1(4)(c) bans variable-ratio reward schedules, guilt-inducing exit friction, and misrepresentation of the system's identity, capabilities, or training data — engagement-optimisation patterns, regulated as product design rather than as speech. Operators serving mixed-age audiences will need an age signal to know which regime applies, though the act imposes no age-verification duty.
First binding AI-specific regulation in the GCC. All QCB-licensed financial entities must establish AI governance frameworks, risk management systems, and obtain QCB pre-approval before deploying any AI system. High-risk AI systems face additional scrutiny and may require sandbox testing.
Structured as a gate on operation, not a best-efforts duty: it is unlawful to operate or provide the companion at all unless the protocol is built in. Rhode Island's definition is narrower than California SB 243's reasonable-person test — the three limbs in § 6-63-1(1)(i) are conjunctive, so a system that never asks unprompted emotion-based questions falls outside the chapter. But the protocol scope is broader on one axis: it reaches threatened physical harm to others (§ 6-63-2(a)(2)), which California does not cover.
The duty falls on private-sector actors, not only on licensees: § 40.1-5.5-3(b) reaches any "individual, corporation, or entity" that offers therapy to the Rhode Island public "including through the use of internet-based artificial intelligence", so an out-of-state AI therapy product marketed into Rhode Island is directly in scope, and the vendors selling clinical-adjacent AI into private practices are constrained by what their customers may lawfully deploy. That is what makes this an AI-deployment rule rather than a professional-licensing rule. The liability allocation is the sharpest edge: the provider retains clinical judgement and therapeutic oversight "but not for vendor-controlled system design, algorithms, or outputs" (§§ 40.1-5.5-2(6), 40.1-5.5-3(c)(2)) — the statute carves the provider's responsibility around the vendor's black box without saying who carries the residue.
The consent definition does the work. § 40.1-5.5-2(3) rules out the three cheapest consent mechanics in software: acceptance of broad terms of use that bury the AI description among unrelated material, dark-pattern interactions (hovering, muting, pausing, closing content), and deceptive actions. Consent must be affirmative, written or electronic, purpose-specific, and revocable — which means the product needs a per-purpose consent record and a revocation path, not a checkbox. § 40.1-5.5-3(c) then makes consent a condition precedent: AI use is permitted "only to the extent that such use meets the requirements of subsection (a)".
The duty runs to private healthcare providers and the facilities that employ them, not to a state agency — which is what puts it in scope here rather than treating it as a licensing rule, and it lands squarely on the ambient-scribe vendors selling into those private practices: the practice cannot lawfully deploy a scribe without a patient notification path and a per-visit review-and-attest step built into the workflow, with no sampling allowance and no materiality threshold. The statute's title advertises only notification; the review duty is the operative half and is easy to miss. Note the narrowing phrase "for that sole purpose" — the duty as drafted attaches to documentation use, and the Act says nothing about AI used for diagnosis or triage. The operative chapter is a single sentence creating these two linked duties, so they are modelled as one provision rather than two.
El Salvador's AI law is the first in Latin America to require registration with a national AI authority. Registration with ANIA unlocks liability protections (immunity for third-party misuse if reasonable safety measures were taken) and access to tax incentives — creating a meaningful incentive structure for compliance. All natural and legal persons engaged in AI research, development, or deployment must register.
Mandatory impact assessments apply to AI systems handling confidential, personal, or restricted data, or deployed in critical sectors (healthcare, finance, public administration). ANIA establishes the risk-assessment framework. This is a risk-based approach analogous to the EU AI Act but with a pro-innovation tilt: lighter obligations for lower-risk systems.
Creates de facto compliance obligations for any AI vendor selling LLMs to the US federal government. Agencies must require vendor documentation including model cards, data cards, acceptable use policies, and risk disclosures. Agencies must reject non-compliant models. Not branded as AI regulation, but effectively mandates transparency for a significant market segment.
Establishes two Unbiased AI Principles — truth-seeking and ideological neutrality — that federal LLM procurements must comply with. Agencies must adopt procedures to enforce compliance and hold vendors accountable. Effectively creates a content-level compliance standard for the federal market.
Establishes a voluntary framework under which frontier developers may engage the government to have models designated "covered frontier models" and provide up to 30 days of pre-release access for evaluation before other trusted partners. The framework itself does not yet exist — Treasury, NSA, and CISA must design it within 60 days. Section 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement, so participation is opt-in. Worth watching: a voluntary pre-release evaluation regime can harden into a de facto procurement or trusted-vendor expectation.
Does not create compliance obligations for AI companies. Instead, directs DOJ to form a task force to challenge state AI laws on preemption, interstate commerce, and First Amendment grounds. Directly threatens enforceability of state laws tracked in this reference (Colorado SB 24-205, Illinois HB 3773, California ADS regs, NYC LL144, and others). Carveouts preserve state authority on child safety, AI infrastructure, and government procurement.
Directs the Secretary of Commerce to evaluate existing state AI laws within 90 days and identify those that conflict with federal objectives. The evaluation includes a BEAD Program policy notice making states with conflicting AI laws ineligible for broadband funding. Also directs FTC to issue a policy statement on how the FTC Act preempts state laws mandating alterations to truthful AI outputs. No direct obligations for AI developers — but the evaluation results will shape which state laws survive federal challenge.
The therapeutic-communication definition is what pulls general-purpose AI products in: "offering clinical support, including reassurance or empathy in response to emotional or psychological distress" (§ 7115(a)(4)(C)) describes the default behavior of consumer companion chatbots, not just purpose-built therapy apps. And because § 7115(b) attaches to advertising and offering, not only delivering, marketing an AI product for mental health support to Vermonters is itself the violation. Enforcement runs through the Consumer Protection Act, which brings both AG civil penalties and a private right of action (§ 7115(c)(1)) — a materially stronger remedy stack than Rhode Island's EOHHS-investigation model for the equivalent rule.
This is the standing human-oversight loop, the same structure as Rhode Island ch. 40.1-5.5: AI can sit in the workflow only while a professional continuously reviews and approves what reaches the patient. Vermont's version is conditioned twice over — the tool must be HIPAA-compliant, and the professional must review and approve "any mental health services" — which constrains what vendors can sell into practices (a product with no review-and-approve surface cannot be lawfully deployed). The licensure hooks give it teeth on the professional side: prohibited AI use is per se unprofessional conduct for every § 129a licensee and for physicians under § 1354, whether committed inside or outside Vermont.
Washington's general disclosure is unconditional — unlike California SB 243 and Oregon ch. 85, it does not turn on whether a reasonable person would be misled, so every covered chatbot discloses at the start of the interaction and every three hours regardless of how obviously artificial it is. Sec. 3(3) adds a model-behaviour duty rather than a copy duty: the system must be constrained from claiming to be human when asked, which is an alignment requirement in statute. The educational-tools carve-out in Sec. 2(1)(b)(iv) has no California or Oregon analogue.
The "directed to minors" trigger means an operator cannot avoid this section by declining to determine user age — audience design alone brings the product in. The eight enumerated manipulative techniques in Sec. 4(1)(c) are the most detailed engagement-design ban of the three 2026 companion statutes, reaching in-app monetisation framed as relationship maintenance (Sec. 4(1)(c)(viii)) and outputs promoting isolation from family (Sec. 4(1)(c)(v)). Minors get a one-hour reminder cadence against the three-hour general rule.
Structured as a gate on deployment: no protocol, no chatbot. Washington is the only one of the three 2026 companion statutes to name eating disorders explicitly within the detection duty (Sec. 5(2)(a)), which pulls disordered-eating content into a self-harm safety pipeline that most moderation stacks treat separately. Unlike Oregon, no specific hotline is mandated — "a suicide hotline or crisis text line" is sufficient.
cross-domain 45 provisions
Provisions that span multiple industries. A privacy rule that affects AI in hiring, lending, and insurance simultaneously.
NSW's Digital Work Systems Act catches every employer using algorithmic scheduling, AI-driven monitoring, automated performance management, or platform-based work allocation. The definition of "digital work system" explicitly includes algorithms, AI, automation, and online platforms — making this one of the broadest workplace AI laws globally. Any company operating in NSW with AI-assisted HR, logistics, or workforce management tools must assess and manage WHS risks from those systems.
WHS entry permit holders (typically union officials) gain rights to access and inspect digital work systems — including AI algorithms and monitoring tools — in relation to a suspected contravention, not as an unconditional/blanket inspection right. Employers must provide "reasonable assistance" on notice. This creates a transparency obligation where the AI/algorithmic logic behind workplace decisions becomes inspectable by worker representatives, not just regulators. The inspection-access right specifically (distinct from the Act's general 2026-02-18 effective date) does not commence until SafeWork NSW publishes its entry permit holder guideline, plus one month — see Timeline table. Status reflects this guideline-gated commencement rather than current enforceability.
Australia's Privacy Act reforms make AI transparency mandatory through privacy law — not AI-specific legislation. Any organization using personal information in automated decisions must update its privacy policy to describe, in general terms, the kinds of personal information used and the kinds of decisions made or substantially assisted by ADM. Even "human in the loop" doesn't exempt you if the algorithm plays a substantial role.
APP 3 and APP 6 data minimisation and purpose limitation have always applied to AI systems processing personal information — these are existing obligations, not new POLA Act requirements. The POLA Act 2024 strengthened general APP enforcement but did not insert an AI-specific minimisation clause effective 2026-12-10. Organisations collecting personal data for AI training or inference must ensure collection is reasonably necessary for a specific purpose (APP 3) and that data is only used for the purpose for which it was collected (APP 6). OAIC's Children's Online Privacy Code (registerable by Dec 2026) imposes additional data minimisation duties for child-facing AI services as a code instrument, not a standalone APP amendment.
The disclosure runs to training inputs rather than outputs, which makes it the counterpart to the provenance duties in the California AI Transparency Act: one documents what went into the model, the other marks what comes out. It bites on every substantial modification — a new version, release, update, retraining, or fine-tune that materially changes functionality or performance — so it is a recurring release-gate obligation, not a one-time filing. There is no penalty provision and no named enforcer in the chapter.
The provenance chain's other end: the rest of the chapter marks content as synthetic, while this section marks content as camera-captured. It reaches hardware manufacturers rather than AI developers, so it lands on companies that may not otherwise track AI regulation — and default-on embedding (subdivision (a)(2)) is a firmware-level design decision with a long lead time.
The duty is structured as a gate, not a best-efforts standard: without the protocol, the operator must prevent the chatbot from engaging with users at all. Publication of the protocol turns an internal safety process into a public document that plaintiffs can read before suing under § 22605.
Applies across all sectors in all ratifying states — including the US, UK, and EU — creating a transatlantic baseline for AI disclosure. Note the split: Art. 8 transparency and AI-content identification is a firm obligation, while the human-vs-AI notification in Art. 15(2) is drafted as "shall seek to ensure", so implementing states retain discretion.
Article 16 goes further than most voluntary frameworks by requiring States to assess whether specific AI uses should be subject to moratoria or outright bans — a tool available under binding international law that has no equivalent in current national AI regulations.
CETS 225 is the first international treaty to establish a right to contest AI decisions. Articles 14–15 create binding remedies and procedural safeguards — including appeal rights and notification — that States must embed in domestic law, surpassing any existing voluntary framework on human oversight.
Article 10 (Equality and non-discrimination) is the operative provision: Parties must ensure AI lifecycle activities respect equality, including gender equality, and must adopt measures aimed at overcoming inequalities. Article 16's risk management mandate covers impacts on equality rights, and Article 17 requires the Convention itself to be implemented without discrimination. As a treaty built on the European Convention on Human Rights, it binds AI use to existing ECtHR jurisprudence.
These privacy-law definitions directly govern AI-driven profiling in hiring, lending, and insurance — even though the rules predate and never mention AI. The three-tier automation framework determines consent and opt-out requirements, making this one of the most consequential provisions for organizations using automated decision-making in Colorado.
Any organization using AI for profiling in Colorado — credit scoring, insurance underwriting, employment screening — must conduct a Data Protection Assessment under this rule, regardless of whether the AI system was the target of the regulation. This is the provision a lawyer friend called a "real sleeper" that many compliance teams miss.
Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says "but not including a law enforcement agency." That carve-out is unique among the 2026 state chatbot laws and rules out the wellness-check escalation pattern several operators use today. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.
Not a disclosure rule but a liability rule, and it is the sharpest incentive in the Act: using an automated employment-related decision technology is expressly not a defense to a discrimination complaint, while evidence of anti-bias testing may be considered in the employer's favour. That asymmetry converts bias testing from a good practice into the only available mitigation, which is why it belongs under bias-prevention rather than with the disclosure provisions.
This is the provision that converts the § 42-522(c) impact assessment from a paperwork exercise into a retained, producible record. Three design choices matter together: the Attorney General may compel any assessment relevant to an investigation and evaluate it for compliance across §§ 42-515 to 42-525; the assessments are confidential and exempt from the Freedom of Information Act, so a competitor cannot obtain them by request; and disclosure to the Attorney General waives neither attorney-client privilege nor work product protection. The privilege carve-out is the load-bearing piece — without it, counsel would advise against writing anything candid in an assessment, which is precisely how comparable assessment regimes hollow out.
Filed under `risk-assessment` rather than `data-governance` because the ongoing compliance process the section creates is the § 42-529b(b) impact assessment — six enumerated elements, review on any material change to the profiling operations, and documentation kept for the longer of three years after the operations cease or as long as the service is offered. The consent gate in § 42-529a(b)(3)(B) is a condition on a single processing activity rather than a sustained process, and § 42-529a(a) ties the two together by giving a controller that complies with § 42-529b a rebuttable presumption of reasonable care in any Attorney General enforcement action — the assessment is the safe harbor, so it is where the compliance weight sits. Two scope moves are easy to miss. The consent gate was broadened from profiling in furtherance of any **fully** automated decision to **any** automated decision, so a human reviewer in the loop no longer takes a minor's profiling outside it — the same widening the act made to the adult opt-out in § 42-518. And the assessment trigger in § 42-529b(b) is any profiling at all by a service offered to minors, not only legal-effect profiling; only the first of the six elements is qualified by legal or similarly significant effects. Separately, § 42-529d(d)(4) permits processing a minor's personal data for legal-effect profiling solely to detect or correct bias, on five conditions including deletion once the processing is complete, pseudonymization and other industry-standard security measures, strict documented access controls, and no third-party transmission or access — a construction rule creating a safe harbor rather than an obligation, so it is recorded here rather than as its own provision.
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02.
A permission, not a mandate — Article 4a(2) states expressly that it creates no obligation to conduct bias detection. It matters because it is the only lawful route to processing special-category personal data for bias work, and the six cumulative safeguards are themselves an ongoing compliance burden for anyone who uses it. Replaces the former Article 10(5), which was limited to high-risk training data.
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
Two duties here have almost no analogue in the cohort. § (c)(2) requires evidence-based methods for measuring suicidal ideation and the risk of self-harm — a methodological standard rather than a "reasonable measures" standard, which only Oregon and Colorado otherwise impose. § (c)(5) reaches outward: reasonable measures must prevent outputs encouraging the user to cause serious bodily injury to another person, and no other state statute in this cohort covers harm to third parties at all. § (c)(3) also bars the companion from representing that it is designed to provide professional mental or behavioral health care, which pulls the section into scope-of-practice territory alongside consumer protection.
The trigger is actual knowledge or reasonable certainty, not an age-estimation duty — the legislature's findings in Sec. 2 expressly say regulation should "proactively avoid the mandatory collection of data by technology companies such as identity documentation for age verification purposes", so Hawaii deliberately declines the Colorado-style duty to estimate age. § (d)(1) targets variable-ratio reward schedules by name (points or similar rewards at unpredictable intervals intended to encourage increased engagement), which is a narrower and more mechanism-specific engagement ban than Washington's eight-technique list. § (d)(4) is the cohort's parental-tools duty: screen-time and account-settings controls must be available to the user and to parents and guardians alike.
This is a filing to a health regulator, not a consumer-protection disclosure — Washington and Oregon make the crisis-referral count a public self-disclosure with no recipient agency, while Hawaii routes it to the behavioral health administration of the Department of Health, which is where the state's own suicide-prevention programming sits. The data-minimisation proviso is a hard cap rather than a floor: the report "shall include only the information listed in this subsection" and no user identifiers or personal information, so an operator cannot pad the filing with supporting detail. The duty is the one part of the act not in force on approval; it begins with the first report on 2028-01-01, covering the preceding calendar year.
Structured as an adoption duty with a reasonable-efforts floor, not California SB 243's engagement gate: Idaho does not bar the service from operating without a protocol, does not require the protocol to be published, and imposes no annual reporting. The practical consequence is that the crisis protocol is only visible to the Attorney General on investigation.
India's foundational data protection law applies to all automated processing of personal data — including AI inference, profiling, and recommendation systems. No explicit ADM opt-out right (unlike GDPR Article 22), but data accuracy and consent obligations bind AI deployers handling Indian user data. Penalties reach ₹250 crore (~$30M USD) per breach.
Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.
The scienter standard is the highest in the chapter — "knowingly and intentionally cause or program" — so an emergent therapeutic persona the operator did not design is outside this section, though it may still be caught by the reasonable-measures duty in § 554J.2(4). The bar is on representation, not on function: a service may in fact behave therapeutically as long as it does not lead a reasonable individual to believe it is a licensed practice.
Italy is the first EU member state to legislate sector-specific AI rules beyond the EU AI Act. For healthcare AI, the law establishes a hard prohibition on AI making autonomous clinical decisions — physicians retain ultimate authority regardless of AI recommendation quality. Any healthcare organisation deploying diagnostic or treatment AI in Italy must build physician-override workflows into every clinical AI deployment.
Italy extends AI transparency duties into employment and child contexts that sit beyond the EU AI Act's direct scope. Employers using AI in recruitment or performance evaluation must disclose AI involvement to workers — creating a specific notification duty for HR technology deployments. The parental consent requirement for under-14s applies to any AI-powered product or service used by children, including education platforms, apps, and consumer AI.
Italy's secondary-use pathway for health data is a sleeper provision with global reach: any organisation conducting AI research using Italian patient data — including non-Italian researchers accessing Italian health datasets — must satisfy both the GDPR and a 30-day Garante notification before processing. This covers clinical AI model training, drug discovery AI, and public health AI research.
Maine put this rule in Title 10 (commerce and trade), not in a licensing chapter, which is what gives it reach beyond Maine licensees: § 1500-EE(2) binds any "person" who offers therapy to the Maine public through Internet-based AI, and § 1500-EE(3) converts a violation into an Unfair Trade Practices Act violation enforced by the Attorney General. The statute never calls itself an AI law in its operative duty — it is drafted as a licensure and trade-practices rule — yet the therapeutic-communication definition at § 1500-EE(1)(C)(3), "offering emotional support, reassurance or empathy in response to psychological or emotional distress", describes ordinary consumer companion-chatbot behavior, not only purpose-built therapy products. Advertising and offering are covered alongside providing, so marketing an AI mental-health product into Maine is itself the violation. The IRB carve-out mirrors Rhode Island's and Vermont's, which is now the settled shape of this exemption across the three states.
This is the requirement neither Vermont nor Rhode Island has: Maine permits AI supplementary support "only when the client's therapeutic session is recorded or transcribed" (§ 2113(3)). That is an affirmative surveillance precondition, not a restriction on surveillance — a practice that wants an AI scribe or progress-tracking tool must first put the session on the record. Paired with it is a consent definition (§ 2113(1)(C)) that is unusually strict even against Rhode Island's: consent must be a clear, explicit, affirmative act communicating express, informed, voluntary, specific, unambiguous written agreement, revocable by the client, and it expressly is not acceptance of a general or broad terms-of-use agreement, not hovering over, muting, pausing, or closing electronic content, and not anything obtained through deceptive actions. The disclosure at § 2113(3)(A)(3) reaches further than either sibling statute: the client must be told in writing how session data will be stored, retained, **used for training**, and deleted on termination of services — a written commitment about training-data use, made per client. And § 2113(5) bars the licensee from denying or refusing treatment because the client withheld consent, so declining AI is genuinely costless for the client and fully blocking for the licensee. Any client waiver of the section is void as contrary to public policy (§ 2113(11)), which forecloses the intake-paperwork workaround.
The statute reaches AI only indirectly. Art. 2 Fraction XIX defines "tratamiento" to include operations carried out by automated procedures, so processing personal data with AI is covered, and the Art. 14-17 privacy-notice duties apply. The consolidated text (Última Reforma DOF 14-11-2025) contains no occurrence of "inteligencia artificial" or "algoritmo", and Art. 15 does not require disclosure of algorithmic logic, significance, or consequences. Any such duty would have to come from the pending secondary regulations.
The statute provides a right to object, not a duty of oversight. Art. 26(II) lets a data subject oppose processing where their data undergoes automated processing that produces unwanted legal effects or significantly affects their interests, rights, or freedoms, and is intended to evaluate personal aspects — professional performance, economic situation, health, sexual preferences, reliability, or behaviour — without human intervention. The text imposes no human-in-the-loop requirement, no impact assessment, and no safeguards specific to agentic systems; those appeared in secondary commentary and, if they arrive, will come from the pending implementing regulations.
Nebraska states the crisis duty in a single sentence and, unlike Washington, does not gate deployment on having the protocol, name eating disorders, or require any public disclosure of referral counts — the duty is to adopt a protocol and make reasonable efforts to refer. The "includes, but is not limited to" framing leaves the floor open, which means the Attorney General, not the statute, will set the practical content of an adequate protocol.
The duty is a gate on access, not a best-efforts standard: without the protocol the operator may not allow Oregon users access at all. Two features go beyond California SB 243 — the protocol must use evidence-based detection methods rather than merely respond after the fact, and § 1(3)(b)(B) requires clinical best practices for escalated intervention when a user keeps expressing intent after the first referral.
The duty falls on private-sector actors, not only on licensees: § 40.1-5.5-3(b) reaches any "individual, corporation, or entity" that offers therapy to the Rhode Island public "including through the use of internet-based artificial intelligence", so an out-of-state AI therapy product marketed into Rhode Island is directly in scope, and the vendors selling clinical-adjacent AI into private practices are constrained by what their customers may lawfully deploy. That is what makes this an AI-deployment rule rather than a professional-licensing rule. The liability allocation is the sharpest edge: the provider retains clinical judgement and therapeutic oversight "but not for vendor-controlled system design, algorithms, or outputs" (§§ 40.1-5.5-2(6), 40.1-5.5-3(c)(2)) — the statute carves the provider's responsibility around the vendor's black box without saying who carries the residue.
Creates de facto compliance obligations for any AI vendor selling LLMs to the US federal government. Agencies must require vendor documentation including model cards, data cards, acceptable use policies, and risk disclosures. Agencies must reject non-compliant models. Not branded as AI regulation, but effectively mandates transparency for a significant market segment.
Vendors must disclose training data provenance, limitations, and risk mitigations as a condition of federal procurement. While framed as ensuring "unbiased AI," the practical effect is a data governance disclosure requirement for the federal AI supply chain.
Establishes two Unbiased AI Principles — truth-seeking and ideological neutrality — that federal LLM procurements must comply with. Agencies must adopt procedures to enforce compliance and hold vendors accountable. Effectively creates a content-level compliance standard for the federal market.
Directs the Secretary of the Treasury to form an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and critical-infrastructure operators, to coordinate vulnerability scanning, validate discovered vulnerabilities, and prioritize remediation and patch distribution. To be formed within 30 days. Participation is voluntary, but for AI providers and critical-infrastructure operators it functions as a coordinated channel for software-vulnerability discovery and remediation.
Does not create compliance obligations for AI companies. Instead, directs DOJ to form a task force to challenge state AI laws on preemption, interstate commerce, and First Amendment grounds. Directly threatens enforceability of state laws tracked in this reference (Colorado SB 24-205, Illinois HB 3773, California ADS regs, NYC LL144, and others). Carveouts preserve state authority on child safety, AI infrastructure, and government procurement.
Directs the Secretary of Commerce to evaluate existing state AI laws within 90 days and identify those that conflict with federal objectives. The evaluation includes a BEAD Program policy notice making states with conflicting AI laws ineligible for broadband funding. Also directs FTC to issue a policy statement on how the FTC Act preempts state laws mandating alterations to truthful AI outputs. No direct obligations for AI developers — but the evaluation results will shape which state laws survive federal challenge.
The therapeutic-communication definition is what pulls general-purpose AI products in: "offering clinical support, including reassurance or empathy in response to emotional or psychological distress" (§ 7115(a)(4)(C)) describes the default behavior of consumer companion chatbots, not just purpose-built therapy apps. And because § 7115(b) attaches to advertising and offering, not only delivering, marketing an AI product for mental health support to Vermonters is itself the violation. Enforcement runs through the Consumer Protection Act, which brings both AG civil penalties and a private right of action (§ 7115(c)(1)) — a materially stronger remedy stack than Rhode Island's EOHHS-investigation model for the equivalent rule.
Structured as a gate on deployment: no protocol, no chatbot. Washington is the only one of the three 2026 companion statutes to name eating disorders explicitly within the detection duty (Sec. 5(2)(a)), which pulls disordered-eating content into a self-harm safety pipeline that most moderation stacks treat separately. Unlike Oregon, no specific hotline is mandated — "a suicide hotline or crisis text line" is sufficient.