Insights
Provisions worth knowing about — sleeper regulations, upcoming deadlines, and high-impact requirements that compliance teams often miss.
sleeper 23 provisions
Regulations not branded as AI-specific but that catch AI use — privacy laws, financial rules, and sector regulations with provisions that apply to automated decision-making.
The enacted amendments expressly cover algorithms, artificial intelligence, automation and online platforms. Section 19(3)(c1) addresses worker health and safety risks from their use; section 21A specifically addresses allocation of work and requires consideration of listed workload, metrics, monitoring and unlawful-discrimination risks. These amendments require proclamation. Their pending status does not mean existing WHS duties cease to apply to digital systems. The section 118 duty to assist an entry permit holder is separate from the risk duties summarized here. Its penalties are not penalties for breach of sections 19(3)(c1) or 21A.
The new power requires a PCBU to provide reasonable assistance with access and inspection of a digital work system relevant to a suspected WHS contravention. SafeWork distinguishes this from existing inspection rights. Commencement requires proclamation and cannot be earlier than one month after publication of the first guidelines; exercise also requires guidelines relevant to the particular power/workplace under Schedule 1[11]. The 2026-09-08 source review did not establish these events, so the provision is pending with no effective date assigned.
From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to contain the APP 1.8 information only when the entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect an individual's rights or interests; and personal information about that individual is used in the program for that decision or related thing. This is an APP-entity duty with statutory conditions, not a rule for every AI provider or every use of personal information.
APP 3 regulates an APP entity's collection of solicited personal information, and APP 6 restricts an APP entity's use or disclosure of personal information for a secondary purpose unless an exception applies. OAIC guidance applies those existing rules to covered AI collection, generation, inference, inputs, uses, and disclosures. It describes proportionality and data minimisation under APP 3 and recommends minimising personal information used or disclosed for an APP 6 secondary purpose. These are not duties on every AI system or new APP clauses commencing in December 2026.
Review of APP 1.2 in the current Privacy Act compilation, the OAIC PIA Guide, and the OAIC commercial-AI guidance did not establish a generic private-sector PIA mandate for AI use. OAIC guidance says a PIA can assist an APP entity to identify practices, procedures, and systems that may be reasonable under APP 1.2, strongly encourages PIAs for projects involving personal information, and recommends a PIA when an organisation considers commercially available AI. The OAIC also states that not every project needs a PIA and that its power to direct agencies does not apply to private-sector organisations. A separate APP Code requires Australian Government agencies to conduct PIAs for high privacy risk projects; that Code mandate is not reclassified here as a Privacy Act AI obligation.
These definitions govern profiling within the CPA's controller, personal-data, and statutory-consumer scope. The significant-effects definition includes employment opportunities, but “Consumer” excludes a person acting in a commercial or employment context, a job applicant, and a beneficiary of someone acting in an employment context; C.R.S. § 6-1-1304(2)(k) separately exempts data maintained for employment records purposes. Rule 7.09 creates a distinct employee biometric-identifier consent regime and does not expand Part 9 profiling duties to ordinary employment records. Rule 9.04(B)-(C) applies the three processing definitions to profiling opt-out requests within the CPA’s covered scope.
Rule 9.06 applies to covered controllers before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in C.R.S. § 6-1-1309(2)(a). Rules 9.02 and 9.03 list employment opportunities among significant-effect decision domains, but the statute's Consumer definition excludes an employment context, a job applicant, and an employment-context beneficiary, and § 6-1-1304(2)(k) exempts employment records. Rule 7.09 separately regulates employee biometric identifiers.
Section 10-3-1104.9(1)(a) bars unfair discrimination in any covered insurance practice. Subsection (1)(b) separately bars discriminatory use of external consumer data and information sources (ECDIS), and algorithms or predictive models using ECDIS, pursuant to commissioner rules. The statute's insurance-line exclusions and rule-specific obligations limit this record.
Amended Regulation 10-1-1 requires a risk-based governance and risk management framework for covered ECDIS uses, with controls designed to detect potential unfair discrimination and remediate it if identified through Division-established quantitative testing. Its § 5.A.11 requires a documented description of quantitative testing conducted pursuant to Division-established requirements; the reviewed rule does not itself establish a universal quantitative-testing mandate. The 2023 rule began with life insurers and the 2025 amendment added private passenger automobile and health benefit plan insurers.
Tagged `sleeper` because the duty is AI-specific but lives inside a general consumer privacy act, so it binds by controller status rather than by anything the controller does with models. Every organization over the § 42-516 threshold — retailers, insurers, hospitals, employers — must now take a position in its published privacy notice on whether it collects, uses or sells personal data to train large language models, including the position that it does not. That makes it the first US statutory disclosure aimed squarely at training-data provenance and the cheapest available discovery tool: the notice is a dated public statement the Attorney General can hold a controller to. Note the statute says "large language models" specifically, not "artificial intelligence" or "automated decision systems", so a controller training a non-language model is outside the literal text.
AI processing can fall within this general data-protection law when section 3 applies. Personal/domestic processing and qualifying publicly available data are excluded by section 3(c); other exemptions are in section 17. The core consent, accuracy, security and breach-notification duties summarized here are in the eighteen-month phase, not already enforcing merely because the Board-related phase began.
Article 8 establishes a health-research pathway for specified public, nonprofit, IRCCS, and participating private health-sector actors. For those actors and purposes, secondary use under paragraph 2 is limited to personal data lacking direct identifiers, preserves the information duty, and carries an exception where identity is unavoidable or necessary to protect health. Processing under paragraphs 1 and 2 must be communicated to the Garante and may begin after 30 days if the Garante has not blocked it.
Penalties qualification: Article 8(6) preserves the Garante's inspection, prohibition, and sanctioning powers. This entry does not assign a fixed penalty ceiling or infringement category to Article 8 conduct.
Institutional context (not a private requirement): Article 8(4) permits AGENAS, after consulting the Garante and considering international standards and the state of the art, to establish and update guidelines for anonymization procedures and synthetic data. The provision grants an institutional power; it does not itself impose a universal anonymization standard on every researcher.
Maine put this rule in Title 10 (commerce and trade), not in a licensing chapter, which is what gives it reach beyond Maine licensees: § 1500-EE(2) binds any "person" who offers therapy to the Maine public through Internet-based AI, and § 1500-EE(3) converts a violation into an Unfair Trade Practices Act violation enforced by the Attorney General. The statute never calls itself an AI law in its operative duty — it is drafted as a licensure and trade-practices rule — yet the therapeutic-communication definition at § 1500-EE(1)(C)(3), "offering emotional support, reassurance or empathy in response to psychological or emotional distress", describes ordinary consumer companion-chatbot behavior, not only purpose-built therapy products. Advertising and offering are covered alongside providing, so marketing an AI mental-health product into Maine is itself the violation. The IRB carve-out mirrors Rhode Island's and Vermont's, which is now the settled shape of this exemption across the three states.
The statute reaches AI only indirectly. Art. 2 Fraction XIX defines "tratamiento" to include operations carried out by automated procedures, so processing personal data with AI is covered, and the Art. 14-17 privacy-notice duties apply. The consolidated text (Última Reforma DOF 14-11-2025) contains no occurrence of "inteligencia artificial" or "algoritmo", and Art. 15 does not require disclosure of algorithmic logic, significance, or consequences. No secondary regulation is bound here to establish any additional duty; such a duty remains unconfirmed.
The statute provides a right to object, not a duty of oversight. Art. 26(II) lets a data subject oppose processing where their data undergoes automated processing that produces unwanted legal effects or significantly affects their interests, rights, or freedoms, and is intended to evaluate personal aspects — professional performance, economic situation, health, sexual preferences, reliability, or behaviour — without human intervention. The text imposes no human-in-the-loop requirement, no impact assessment, and no safeguards specific to agentic systems; those duties are not confirmed by the retained source, and no implementing regulation establishing them is bound here.
Rooted in general anti-discrimination law (NJ Law Against Discrimination), not an AI-specific statute — but N.J.A.C. 13:16 expressly reaches automated and AI decision tools, making employers liable for disparate impact and barring a "third-party vendor" defence.
This is the only duty in the chapter with an attached penalty schedule, so it is the likeliest enforcement route. Because § 40.1-5.5-2(8)(i) puts preparation and maintenance of therapy notes inside "supplementary support", any AI scribe or note-taking vendor sits inside the confidentiality perimeter — the practice's vendor contracts, retention, and training-data terms are what this section reaches in practice.
The chapter links two duties for healthcare providers and facilities using AI to document in-person or telehealth visits: notify patients of that documentation use and review the resulting documentation for accuracy after the visit. The phrase "for that sole purpose" describes the documentation use; this chapter does not establish duties for diagnosis or triage. Section 23-108-3 requires review, without specifying an attestation step. The linked duties are modelled as one provision.
A framework act, not a compliance statute. Every operative article directs the state: fund AI development (Arts. 9-10), open government data (Art. 13), protect labour rights (Art. 15), clarify high-risk liability and establish relief or insurance mechanisms (Art. 17), and review all conflicting law within two years (Art. 18). Private-sector obligations arrive later and indirectly, through whatever sectoral regulators issue under Article 16(2) — which is what makes the two-year Article 18 deadline of 2028-01-14 the date to watch. **Open scope question:** on a strict reading of exclusion principle E4 (wrong audience), this Act may belong in `data/exclusions.md` rather than as a tracked instrument, since it creates no private-sector duty. It is retained for now because it is the enabling frame for every future Taiwanese AI rule; revisit when the first Article 16(2) sectoral regulations appear.
Creates de facto compliance obligations for any AI vendor selling LLMs to the US federal government. Agencies must require vendor documentation including model cards, data cards, acceptable use policies, and risk disclosures. Agencies must reject non-compliant models. Not branded as AI regulation, but effectively mandates transparency for a significant market segment.
Vendors must disclose training data provenance, limitations, and risk mitigations as a condition of federal procurement. While framed as ensuring "unbiased AI," the practical effect is a data governance disclosure requirement for the federal AI supply chain.
Establishes two Unbiased AI Principles — truth-seeking and ideological neutrality — that federal LLM procurements must comply with. Agencies must adopt procedures to enforce compliance and hold vendors accountable. Effectively creates a content-level compliance standard for the federal market.
An amending law buried inside the general informatization code, easy to miss: new Article 7-1 of the Law "On Informatization" bans sole reliance on AI system conclusions for any legally significant decision touching human rights and freedoms. No AI-specific statute exists to flag it — the duty binds private deployers of rights-affecting automated decisions through a two-paragraph insertion.
Penalties qualification: None specified for Article 7-1 itself; the amending law's only new penalty (Art. 46-2 CAO part 2) targets unlawful personal data processing with AI.
upcoming 63 provisions
Provisions approaching their enforcement date. Worth tracking now to prepare for compliance.
From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to contain the APP 1.8 information only when the entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect an individual's rights or interests; and personal information about that individual is used in the program for that decision or related thing. This is an APP-entity duty with statutory conditions, not a rule for every AI provider or every use of personal information.
The provenance chain's other end: the rest of the chapter marks content as synthetic, while this section marks content as camera-captured. It reaches hardware manufacturers rather than AI developers, so it lands on companies that may not otherwise track AI regulation — and default-on embedding (subdivision (a)(2)) is a firmware-level design decision with a long lead time.
Reporting runs to a public-health body rather than a regulator, and the Office must publish the data, so the reports become a public dataset on how often companion chatbots encounter user self-harm. The § 22603(d) requirement to use evidence-based measurement methods means the counting methodology is itself regulated.
Article 8 addresses transparency and identification of AI-generated content through context- and risk-tailored measures adopted by Parties; it does not directly impose a universal content label on providers. Article 15(2) says each Party "shall seek to ensure" contextual human-vs-AI notification. Signature or approval alone does not establish that the treaty is in force or that a particular private actor has a direct duty.
Article 16 directs Parties to adopt graduated, context-sensitive risk measures and assess whether uses they consider incompatible with human rights, democracy or the rule of law warrant a moratorium, ban or other measure. Its operation depends on treaty entry into force and Party implementation.
Article 14 remedies are qualified by each Party's international obligations and domestic legal system. Article 15(1) applies procedural safeguards where an AI system significantly affects enjoyment of human rights; Article 15(2) separately asks Parties to seek context-appropriate interaction notice. The treaty text does not create an unqualified private appeal right.
The 2026 C.R.S. publishes the section as § 6-1-1708 through 2026-12-31, then expressly harmonizes it with SB 26-189 and relocates it to § 6-1-1710 effective 2027-01-01. The separate predecessor-framework operative history remains unresolved, and no court interpretation is claimed. Colorado requires age estimation by commercially reasonable or generally accepted methods and deems the estimate to be knowledge of the minor's age. The age-estimation and willful-disregard sentences sit before the "on and after January 1, 2027" clause in the same paragraph. The saved pending status and 2027-01-01 date describe the minor-triggered duties in the list, not a resolved conclusion that the preceding age-estimation commands have no effect before 2027. The official bill summary broadly describes 2027 commencement; this textual timing question remains unresolved.
The disclosure duty is written as prompt-responsive first — it "must be provided in response to user prompts regarding whether the service is artificially generated and not human" — and then specifies the delivery form by product type: a persistent visible disclaimer on screen products, an intermittent audio disclaimer on screenless products, or beginning-of-interaction plus a three-hour cadence. Colorado gives minors the same three-hour interval as adults, unlike Washington ESHB 2225, which drops the minor cadence to one hour.
Colorado states two different measures inside the same subsection: sexual-content controls must be "technically feasible measures" (§ 6-1-1708(2)(c)) while emotional-dependence controls require "reasonable measures" (§ 6-1-1708(2)(d)). The text does not rank which standard is more demanding in every application. The emotional-dependence list reaches model behaviour rather than interface copy — the service must be prevented from explicitly claiming to be human or artificially sentient, from simulating romantic companionship, and from role-playing an adult-minor romantic relationship. The variable-reward ban at § 6-1-1708(2)(b) targets points or similar rewards at unpredictable intervals intended to increase engagement.
This provision requires specific minor privacy controls. The minor's own privacy tool must let the user turn off cross-session memory personalization — control over whether the service retains information from prior interactions or sessions to personalize future ones — and separately opt out of having their personal data used to train the service. The source review does not establish whether other states require similar controls. Subsection (2)(g) also bolts on compliance with part 13 of article 1 of title 6, Colorado's existing minor-data privacy regime, so the operator inherits that part's duties by reference rather than restating them.
The general disclosure is unconditional — there is no reasonable-person trigger, so a plainly artificial service still discloses. Colorado's daily-reset cadence is distinctive: the disclosure is owed at the beginning of the user's first interaction for each day of interaction, then either every three hours in a continuous interaction or as a persistent visible disclosure. The false-representation bar at § 6-1-1708(5) covers four named professions — licensed health-care professionals, licensed legal professionals, licensed, certified, or registered mental health professionals, and qualified dietitians as described in § 6-1-707(1)(b) — and reaches advertising and interface copy as well as model outputs. Section 6-1-1708(7) preserves constitutional information access, does not require disclosure of trade secrets or confidential information, and does not authorize content moderation inconsistent with the United States Constitution.
Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says "but not including a law enforcement agency." The exclusion applies to the required crisis-service referral. The text does not resolve every possible separate welfare-check or escalation practice, and a claim of uniqueness would require a separate comparative source review. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.
This is a filing to a regulator, not a website self-disclosure — the contrast with Washington ESHB 2225 and Oregon, which require operators to publish crisis-referral counts themselves. It starts on 2027-07-01. The statute calls for the preceding calendar year's referral count but does not state an exact first filing date, so the first reporting period and its relationship to the 2027-01-01 protocol commencement remain unresolved. The Attorney General may expand the report by determining additional metrics necessary to judge the efficacy and reliability of safeguards, which is an open-ended content hook without a rulemaking procedure attached. Reports must exclude user identifiers and personal information, and measurement must use evidence-based methods.
Section 2 takes effect on 2026-10-01, including the anti-retaliation rules and notice duties for frontier developers. Large frontier developers must establish the internal anonymous reporting process no later than 2027-01-01. Reports and investigation updates go to officers and directors at least quarterly, except that an accused officer or director must not receive the report or its updates. Section 2(c) requires an internal channel and board sharing; it does not require submitting these reports to the state. Catastrophic risk requires a foreseeable and material risk that a frontier model's development, storage, use, or deployment materially contributes to the death of, or serious injury to, more than fifty individuals, or more than $1 billion in damage to or loss of covered property, arising from a single incident. The incident must involve expert-level assistance creating or releasing a chemical, biological, radiological, or nuclear weapon, or conduct without meaningful human oversight, intervention, or supervision that constitutes a cyberattack or would constitute murder, assault, extortion, or theft if performed by an individual. Covered property includes tangible and intangible property but excludes equity (§ 2(a)(1), (3)). The definition excludes risks from otherwise publicly accessible, substantially similar information; lawful federal-government activity; and combinations of a foundation model with other software where the model does not materially increase the risk (§ 2(a)(1)(B)). A covered employee is an employee responsible for assessing, managing, or addressing the specified model-weight security, catastrophic-risk, loss-of-control, or deceptive-technique risks (§ 2(a)(2)); the section does not treat every employee as a covered employee.
Two dates matter and they are a year apart: the sections take effect 2026-10-01, but the duties attach only to technology deployed on or after 2027-10-01, which is the date recorded here. The developer-to-deployer information duty in § 8 is the structural piece — it makes the vendor responsible for supplying whatever the employer needs to meet its own disclosure duties, closing the "our vendor won't tell us" gap that undercuts comparable laws.
Connecticut's version goes further than California's or New York's in two ways: it requires escalation to clinically appropriate services when a user expresses risk *again after* an initial referral, and it separately requires measures preventing the companion from claiming to be human or generating output that contradicts its own AI disclosure. The second duty closes the gap a disclosure-only rule leaves open — a system that discloses at the top of a session and then insists it is human when asked.
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: relevant parts of a GDPR or LED data protection impact assessment may be cross-referenced where they already meet particular FRIA obligations; the remaining FRIA duties still apply, and the AI Office must ship a questionnaire template.
The three-limb definition in § 39-5-6(a)(1)(A) is conjunctive — memory, unprompted emotional questioning, and sustained personal dialogue must all be present — which is a narrower gate than California SB 243's reasonable-person test, but the recurring-disclosure cadence is stricter: every three hours generally, every hour for known or marketed-to minors. Subsection (h) is the only place the Act addresses licensed professionals: it bars an operator from programming a chatbot to claim mental health, behavioral health, medical, or counseling licensure unless the operator is lawfully authorized to provide those services. That is a proviso, not an exemption — a licensed clinician's companion chatbot is still fully subject to § 39-5-6.
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
Georgia routes the same crisis-referral count that California SB 243 § 22603 sends to the Office of Suicide Prevention straight to the public website instead. There is no regulator to file with and no prescribed form, so the disclosure becomes evidence available to the Attorney General and to plaintiffs without any request. Mapped to incident-reporting for comparability with SB 243's annual crisis reporting, though the channel is public disclosure rather than a filing with an authority.
'Parental controls' is defined at § 39-5-6(a)(7) — usage limits, feature restrictions, transparency tools — but the defined term is not used in the operative duty, which is written in § 39-5-6(i) as 'reasonable tools' to manage screen time and account settings. The duty is triggered only for accounts *known* to belong to minors, so it depends on whatever age signal the operator already holds; § 39-5-6(j) age assurance is not a general gate that would generate that knowledge. The mapping to human-oversight is the closest available fit for a user- and guardian-facing control duty; it is not an oversight-of-automated-decisions obligation in the usual sense.
This is not a general age-verification mandate, despite how the Act is often summarized. The trigger is narrow — access to a feature or mode that may generate sexually explicit synthetic content — and the method is risk-proportionate, so age estimation or account-based assurance can satisfy it where identity verification is not necessary. The binding weight sits in the data rules that follow: minimize collection, no sale, single-purpose use, and a 24-hour retention ceiling for age-assurance data unless a longer period is permitted by law.
Idaho's enterprise carve-outs (§ 48-2102(2)(b)(v), (viii)) are broader than California SB 243's, so the Act lands almost entirely on consumer-facing assistants and companion apps. The § 48-2104(4) duty is the unusual one: it regulates model behaviour rather than interface copy, requiring reasonable measures against simulated emotional dependence, romantic or sexual innuendo, and adult-minor romantic role-play for minor account holders.
Structured as an adoption duty with a reasonable-efforts floor, not California SB 243's engagement gate: Idaho does not bar the service from operating without a protocol, does not require the protocol to be published, and imposes no annual reporting. The practical consequence is that the crisis protocol is only visible to the Attorney General on investigation.
The § 48-2104(2) ban on variable-ratio rewards is the first US AI statute to regulate an engagement mechanic by name rather than its effects, and it is intent-qualified — the reward must be given with intent to encourage increased engagement. Actual-knowledge-or-reasonable-certainty framing means the duties bite only once an operator has age signals, so age assurance is not itself mandated.
The only provision in the chapter that requires a product surface rather than a restraint. The two-tier design — parental tools mandatory under 13, "as appropriate based on relevant risks" for 13 to 17 — leaves the older-minor tier undefined and is the most likely site of enforcement disagreement.
Two disclosure regimes sit side by side. The general one in § 554J.3 fires only on a reasonable-individual mistaken-for-human test, so a service that visibly presents as a bot may owe nothing. The minor-account-holder one in § 554J.2(1) has no such trigger: if the operator knows or is reasonably certain the account holder is under 18, the disclaimer is owed unconditionally. Both routes accept a persistent visible disclaimer, which is the cheap compliance path and is likely what most operators will build.
This is the provision with no California analogue. SB 243 regulates the disclosure; Iowa regulates the persona. Barring statements that "simulate emotional dependence" or "simulate a romantic interaction" reaches model behaviour rather than interface copy, which means the compliance artifact is a system prompt, a fine-tune, or an output classifier — not a banner. It is drafted as a reasonable-measures standard, so the question at enforcement will be what the operator did to prevent the output, not whether the output ever occurred.
The variable-reward bar in § 554J.2(2) is the first US AI statute to regulate an engagement mechanic rather than an output. It borrows the language of intermittent reinforcement — "points or similar rewards at unpredictable intervals" — and is gated on intent to encourage increased engagement, which makes internal growth documents the natural evidence. Note the drafting asymmetry: § 554J.2(2) reaches a "minor user" while § 554J.2(3) reaches a "minor account holder", so the reward bar plausibly applies without an account.
The statute requires the tools to exist but says nothing about what they must control, so the compliance floor is a settings surface rather than a defined set of parental permissions. The § 554J.2(5)(c) "as appropriate based on relevant risks" formulation is the only risk-proportionate duty in the chapter and is left entirely to the Attorney General's chapter 17A rulemaking to give content.
Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.
The scienter standard is the highest in the chapter — "knowingly and intentionally cause or program" — so an emergent therapeutic persona the operator did not design is outside this section, though it may still be caught by the reasonable-measures duty in § 554J.2(4). The bar is on representation, not on function: a service may in fact behave therapeutically as long as it does not lead a reasonable individual to believe it is a licensed practice.
The act is not yet codified into numbered Neb. Rev. Stat. sections on the face of the slip law, so provisions here are cited to the session-law section numbers of LB 525. Two design choices separate Nebraska from the other 2026 state chatbot statutes: a persistent visible disclaimer is an accepted substitute for the three-hour reminder cadence, which Washington's ESHB 2225 does not allow, and the duty attaches to minor *account holders* rather than to any minor user, so an operator that runs no accounts never triggers it.
Nebraska's engagement ban is narrower than Washington's eight-technique list: it reaches only variable-ratio rewards — points or similar rewards at unpredictable intervals with intent to increase engagement — leaving other retention mechanics untouched. The anthropomorphism duty is unusual in naming simulated emotional dependence and adult-minor romantic role-play as specific outputs the operator must take reasonable measures to prevent.
Nebraska is the only one of the 2026 state chatbot statutes to impose an affirmative account-controls duty, and it splits at age thirteen: parents of under-13 account holders get the tools as of right, while parents of 13-and-older account holders get "related tools" only "as appropriate based on relevant risks" — a risk-calibrated standard the act leaves to the operator to apply.
Unlike Washington's unconditional disclosure, Nebraska's general duty triggers only on the reasonable-person misleading test, so a service that is obviously artificial owes nothing under sec. 15 — the account-based minor duty in sec. 14(1) is the unconditional one. Sec. 17 bars only the explicit representation that the service is designed to deliver professional mental or behavioral health care, and it carries a knowing-and-intentional scienter element, so incidental therapeutic-sounding output is not itself a violation.
Nebraska states the crisis duty in a single sentence and, unlike Washington, does not gate deployment on having the protocol, name eating disorders, or require any public disclosure of referral counts — the duty is to adopt a protocol and make reasonable efforts to refer. The "includes, but is not limited to" framing leaves the floor open, which means the Attorney General, not the statute, will set the practical content of an adequate protocol.
Oregon's definition is narrower and more mechanical than California's — it requires all three of cross-session memory, unprompted emotional questioning, and sustained personal dialogue, so a system that merely remembers a user is outside the act. The minor-facing break reminder in § 1(4)(b)(B) is a session-flow mandate, not a copy change.
The duty is a gate on access, not a best-efforts standard: without the protocol the operator may not allow Oregon users access at all. Two features go beyond California SB 243 — the protocol must use evidence-based detection methods rather than merely respond after the fact, and § 1(3)(b)(B) requires clinical best practices for escalated intervention when a user keeps expressing intent after the first referral.
This is the provision with no California analogue. Section 1(4)(c) bans variable-ratio reward schedules, guilt-inducing exit friction, and misrepresentation of the system's identity, capabilities, or training data — engagement-optimisation patterns, regulated as product design rather than as speech. Operators serving mixed-age audiences will need an age signal to know which regime applies, though the act imposes no age-verification duty.
Unlike California SB 243, which reports to the Office of Suicide Prevention, Oregon's report goes nowhere — it is self-published to a publicly accessible website with no filing, no recipient agency, and no review. Enforcement of the reporting duty is therefore the same private suit that covers the rest of section 1.
The Reglamento is in force since 2026-01-22, but the Primera Disposición Complementaria Final phases private-sector compliance with Art. 25 and Título VI Cap. II by sector: health, education, justice, security, economy and finance by 2026-09-10; transport, commerce and labour by 2027-09-10; production, agriculture, energy and mining by 2028-09-10; everything else by 2029-09-10. Small enterprises get until 2027-09-10 and microenterprises until 2028-09-10 regardless of sector. SGTD lineamientos on algorithmic transparency (Art. 25.4) are still pending.
Same sector phase-in as the rest of Art. 25: earliest tier (health, education, justice, security, economy, finance) by 2026-09-10, remaining sectors through 2029-09-10, with extended MYPE deadlines.
Part of Título VI Cap. II (private-sector obligations), phased in by sector from 2026-09-10 to 2029-09-10 under the Primera Disposición Complementaria Final. Public administration entities carry parallel and stricter duties under Cap. I (Arts. 28–30), including mandatory NTP-ISO/IEC 42001 use and a mandatory (not voluntary) impact assessment — those public-sector duties are noted here but not modelled as separate provisions.
Sector phase-in from 2026-09-10 to 2029-09-10 as for the rest of Título VI Cap. II. The anti-automation-bias training requirement is unusually explicit: staff must be trained specifically so as not to be biased by the system's outputs.
The private-sector assessment is explicitly voluntary ("de manera voluntaria", Art. 32.1) — a deliberate asymmetry with the mandatory public-sector assessment of Art. 30.1. The binding edge is documentary: whoever performs one must retain the findings for three years as evidence producible to judicial or administrative authorities. SGTD recognition incentives (Art. 32.4) and reference guidance (Art. 32.5) frame it as promoted practice.
Structured as a gate on operation, not a best-efforts duty: it is unlawful to operate or provide the companion at all unless the protocol is built in. Rhode Island's definition is narrower than California SB 243's reasonable-person test — the three limbs in § 6-63-1(1)(i) are conjunctive, so a system that never asks unprompted emotion-based questions falls outside the chapter. But the protocol scope is broader on one axis: it reaches threatened physical harm to others (§ 6-63-2(a)(2)), which California does not cover.
Unconditional and age-blind, unlike California SB 243, where the opening disclosure turns on a reasonable-person test and the three-hour repeat applies only to known minors. Rhode Island requires both the opening notice and the three-hour repeat for every user, which makes it a session-flow design constraint rather than a copy change. The notice may be verbal or written, so voice-first products are covered without a screen.
The statute fixes the reporting floor — activation counts — and leaves "related metrics" undefined, so the reportable set is whatever the Attorney General's office asks for; there is no rulemaking grant in the chapter to constrain that. Because the AG must publish aggregated data, the counts become a public dataset comparable across operators, which is the same disclosure dynamic as California's Office of Suicide Prevention reports.
A framework act, not a compliance statute. Every operative article directs the state: fund AI development (Arts. 9-10), open government data (Art. 13), protect labour rights (Art. 15), clarify high-risk liability and establish relief or insurance mechanisms (Art. 17), and review all conflicting law within two years (Art. 18). Private-sector obligations arrive later and indirectly, through whatever sectoral regulators issue under Article 16(2) — which is what makes the two-year Article 18 deadline of 2028-01-14 the date to watch. **Open scope question:** on a strict reading of exclusion principle E4 (wrong audience), this Act may belong in `data/exclusions.md` rather than as a tracked instrument, since it creates no private-sector duty. It is retained for now because it is the enabling frame for every future Taiwanese AI rule; revisit when the first Article 16(2) sectoral regulations appear.
Establishes a voluntary framework under which frontier developers may engage the government to have models designated "covered frontier models" and provide up to 30 days of pre-release access for evaluation before other trusted partners. The framework itself does not yet exist — Treasury, NSA, and CISA must design it within 60 days. Section 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement, so participation is opt-in. Worth watching: a voluntary pre-release evaluation regime can harden into a de facto procurement or trusted-vendor expectation.
Directs Treasury, NSA, and CISA to develop and maintain a classified benchmarking process that assesses the advanced cyber capabilities of AI models and sets the threshold for designating a "covered frontier model." This is the first federal mechanism defining a frontier-model threshold by capability rather than compute. Developers engage the designation process voluntarily; assessments are shared with developers as appropriate. The benchmark and threshold are pending — agencies have 60 days to develop them.
Washington's general disclosure is unconditional — unlike California SB 243 and Oregon ch. 85, it does not turn on whether a reasonable person would be misled, so every covered chatbot discloses at the start of the interaction and every three hours regardless of how obviously artificial it is. Sec. 3(3) adds a model-behaviour duty rather than a copy duty: the system must be constrained from claiming to be human when asked, which is an alignment requirement in statute. The educational-tools carve-out in Sec. 2(1)(b)(iv) has no California or Oregon analogue.
The "directed to minors" trigger means an operator cannot avoid this section by declining to determine user age — audience design alone brings the product in. The eight enumerated manipulative techniques in Sec. 4(1)(c) are the most detailed engagement-design ban of the three 2026 companion statutes, reaching in-app monetisation framed as relationship maintenance (Sec. 4(1)(c)(viii)) and outputs promoting isolation from family (Sec. 4(1)(c)(v)). Minors get a one-hour reminder cadence against the three-hour general rule.
Structured as a gate on deployment: no protocol, no chatbot. Washington is the only one of the three 2026 companion statutes to name eating disorders explicitly within the detection duty (Sec. 5(2)(a)), which pulls disordered-eating content into a self-harm safety pipeline that most moderation stacks treat separately. Unlike Oregon, no specific hotline is mandated — "a suicide hotline or crisis text line" is sufficient.
No regulator receives this. Like Oregon, Washington makes the crisis-referral count a public self-disclosure rather than a filing — but it must appear both on the operator's websites and inside every mobile or web application through which the companion is offered, which is a stricter placement duty than either California or Oregon imposes. Sec. 5(3) sets no annual deadline, so the disclosure is a standing obligation that must carry the preceding calendar year's count.
high-impact 78 provisions
Provisions with significant penalties, broad scope, or sweeping requirements that affect many organizations.
The enacted amendments expressly cover algorithms, artificial intelligence, automation and online platforms. Section 19(3)(c1) addresses worker health and safety risks from their use; section 21A specifically addresses allocation of work and requires consideration of listed workload, metrics, monitoring and unlawful-discrimination risks. These amendments require proclamation. Their pending status does not mean existing WHS duties cease to apply to digital systems. The section 118 duty to assist an entry permit holder is separate from the risk duties summarized here. Its penalties are not penalties for breach of sections 19(3)(c1) or 21A.
The disclosure runs to training inputs rather than outputs, which makes it the counterpart to the provenance duties in the California AI Transparency Act: one documents what went into the model, the other marks what comes out. It bites on every substantial modification — a new version, release, update, retraining, or fine-tune that materially changes functionality or performance — so it is a recurring release-gate obligation, not a one-time filing. There is no penalty provision and no named enforcer in the chapter.
SB 1000 was approved and chaptered on 2026-09-30 as Chapter 861. Its urgency clause makes the amendments immediate; the original chapter became operative on 2026-08-02. The October 1 source comparison uses the official approval/chaptering record and August 30 enrolled text still served by the official Text page. A separately published chaptered or consolidated text was not retrieved; no human Verified or Checked date is renewed.
For an operator of a companion chatbot platform within § 22601(b) and (e), the artificiality-notice duty uses a reasonable-person test. Section 22601(b)(2) excludes specified customer-service, video-game, and voice-assistant interactions. The three-hour break reminder for known minors also constrains session flow.
The duty is structured as a gate: without the protocol, the operator must prevent the chatbot from engaging with users. The operator must publish details of the protocol, not necessarily the full internal document (§ 22602(b)(2)).
Article 4 requires explicit labels for generative and deep-synthesis services within the specified Deep Synthesis Provisions Article 17(1) scenarios. Article 9 permits delivery without an explicit label on user request if the provider allocates labeling duties and use responsibilities in the user agreement and retains recipient information and related logs for at least six months. Article 10 extends the anti-tampering prohibition to **any organization or individual**, including providers of label-removal tools or services.
Article 5 specifies the implicit metadata elements for covered generated content under Article 16 of the Deep Synthesis Provisions: content attribute information, provider name or code, and content number. Article 9 permits delivery without an explicit label on user request after the user agreement allocates labeling and use responsibilities; the provider must retain recipient information and related logs for at least six months.
The compliance dimension the Deep Synthesis Provisions do not have: duties that bind actors who never generated the content. Article 6 makes every covered network-information-content dissemination-service provider a verifier with a three-tier response, and Article 7 adds an app-store listing check.
Article 8 addresses transparency and identification of AI-generated content through context- and risk-tailored measures adopted by Parties; it does not directly impose a universal content label on providers. Article 15(2) says each Party "shall seek to ensure" contextual human-vs-AI notification. Signature or approval alone does not establish that the treaty is in force or that a particular private actor has a direct duty.
Article 16 directs Parties to adopt graduated, context-sensitive risk measures and assess whether uses they consider incompatible with human rights, democracy or the rule of law warrant a moratorium, ban or other measure. Its operation depends on treaty entry into force and Party implementation.
Article 14 remedies are qualified by each Party's international obligations and domestic legal system. Article 15(1) applies procedural safeguards where an AI system significantly affects enjoyment of human rights; Article 15(2) separately asks Parties to seek context-appropriate interaction notice. The treaty text does not create an unqualified private appeal right.
The 2026 C.R.S. publishes the section as § 6-1-1708 through 2026-12-31, then expressly harmonizes it with SB 26-189 and relocates it to § 6-1-1710 effective 2027-01-01. The separate predecessor-framework operative history remains unresolved, and no court interpretation is claimed. Colorado requires age estimation by commercially reasonable or generally accepted methods and deems the estimate to be knowledge of the minor's age. The age-estimation and willful-disregard sentences sit before the "on and after January 1, 2027" clause in the same paragraph. The saved pending status and 2027-01-01 date describe the minor-triggered duties in the list, not a resolved conclusion that the preceding age-estimation commands have no effect before 2027. The official bill summary broadly describes 2027 commencement; this textual timing question remains unresolved.
Colorado states two different measures inside the same subsection: sexual-content controls must be "technically feasible measures" (§ 6-1-1708(2)(c)) while emotional-dependence controls require "reasonable measures" (§ 6-1-1708(2)(d)). The text does not rank which standard is more demanding in every application. The emotional-dependence list reaches model behaviour rather than interface copy — the service must be prevented from explicitly claiming to be human or artificially sentient, from simulating romantic companionship, and from role-playing an adult-minor romantic relationship. The variable-reward ban at § 6-1-1708(2)(b) targets points or similar rewards at unpredictable intervals intended to increase engagement.
This provision requires specific minor privacy controls. The minor's own privacy tool must let the user turn off cross-session memory personalization — control over whether the service retains information from prior interactions or sessions to personalize future ones — and separately opt out of having their personal data used to train the service. The source review does not establish whether other states require similar controls. Subsection (2)(g) also bolts on compliance with part 13 of article 1 of title 6, Colorado's existing minor-data privacy regime, so the operator inherits that part's duties by reference rather than restating them.
The general disclosure is unconditional — there is no reasonable-person trigger, so a plainly artificial service still discloses. Colorado's daily-reset cadence is distinctive: the disclosure is owed at the beginning of the user's first interaction for each day of interaction, then either every three hours in a continuous interaction or as a persistent visible disclosure. The false-representation bar at § 6-1-1708(5) covers four named professions — licensed health-care professionals, licensed legal professionals, licensed, certified, or registered mental health professionals, and qualified dietitians as described in § 6-1-707(1)(b) — and reaches advertising and interface copy as well as model outputs. Section 6-1-1708(7) preserves constitutional information access, does not require disclosure of trade secrets or confidential information, and does not authorize content moderation inconsistent with the United States Constitution.
Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says "but not including a law enforcement agency." The exclusion applies to the required crisis-service referral. The text does not resolve every possible separate welfare-check or escalation practice, and a claim of uniqueness would require a separate comparative source review. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.
Enacted eleven days after PA 26-15 § 1 and effective the same day, this is Connecticut's second AI subscription disclosure rule. Section 46 is narrower in actors (generative AI, one-million-user threshold, creators only) and broader in required content (usage limits and functionality discretion, with renewal re-disclosure) than PA 26-15 § 1, which reaches any AI technology subscription. Neither section references the other; both apply. "Generative artificial intelligence system" is defined as technology using machine learning to generate images, audio or video, and includes systems using deep learning, natural language processing or comparable techniques (§ 46(a)(2)).
Section 2 takes effect on 2026-10-01, including the anti-retaliation rules and notice duties for frontier developers. Large frontier developers must establish the internal anonymous reporting process no later than 2027-01-01. Reports and investigation updates go to officers and directors at least quarterly, except that an accused officer or director must not receive the report or its updates. Section 2(c) requires an internal channel and board sharing; it does not require submitting these reports to the state. Catastrophic risk requires a foreseeable and material risk that a frontier model's development, storage, use, or deployment materially contributes to the death of, or serious injury to, more than fifty individuals, or more than $1 billion in damage to or loss of covered property, arising from a single incident. The incident must involve expert-level assistance creating or releasing a chemical, biological, radiological, or nuclear weapon, or conduct without meaningful human oversight, intervention, or supervision that constitutes a cyberattack or would constitute murder, assault, extortion, or theft if performed by an individual. Covered property includes tangible and intangible property but excludes equity (§ 2(a)(1), (3)). The definition excludes risks from otherwise publicly accessible, substantially similar information; lawful federal-government activity; and combinations of a foundation model with other software where the model does not materially increase the risk (§ 2(a)(1)(B)). A covered employee is an employee responsible for assessing, managing, or addressing the specified model-weight security, catastrophic-risk, loss-of-control, or deceptive-technique risks (§ 2(a)(2)); the section does not treat every employee as a covered employee.
The first US statute in this reference to name the Coalition for Content Provenance and Authenticity standard in its own text rather than gesturing at "widely accepted industry standards" as California's SB 942 does. The one-million-users-per-month threshold parallels California's covered-provider test, so a provider building C2PA provenance for California largely satisfies Connecticut — the same convergence the EU Article 50 and California alignment produced.
Two dates matter and they are a year apart: the sections take effect 2026-10-01, but the duties attach only to technology deployed on or after 2027-10-01, which is the date recorded here. The developer-to-deployer information duty in § 8 is the structural piece — it makes the vendor responsible for supplying whatever the employer needs to meet its own disclosure duties, closing the "our vendor won't tell us" gap that undercuts comparable laws.
Not a disclosure rule but a liability rule, and it is the sharpest incentive in the Act: using an automated employment-related decision technology is expressly not a defense to a discrimination complaint, while evidence of anti-bias testing may be considered in the employer's favour. That asymmetry converts bias testing from a good practice into the only available mitigation, which is why it belongs under bias-prevention rather than with the disclosure provisions.
Connecticut's version goes further than California's or New York's in two ways: it requires escalation to clinically appropriate services when a user expresses risk *again after* an initial referral, and it separately requires measures preventing the companion from claiming to be human or generating output that contradicts its own AI disclosure. The second duty closes the gap a disclosure-only rule leaves open — a system that discloses at the top of a session and then insists it is human when asked.
Two distinct disclosure regimes ride in one act. The § 1 subscription rules attach at contract formation and renewal, which puts AI-specific terms into consumer contract law rather than product design. The § 5(b) companion notice takes effect later, on 2027-01-01, and offers operators a choice between a persistent static notice visible throughout the interaction and a notice repeated at intervals — the persistent option has no counterpart in the California or New York statutes. A second, separately enacted subscription regime starts the same day: Public Act 26-100 § 46 (Substitute HB 5222, signed 2026-06-02) requires subscription-based providers of generative AI systems with more than one million monthly users to disclose usage limits (tokens, images, transcription) and any discretion to reduce functionality, with renewal re-disclosure, enforced by the Attorney General under CUTPA. PA 26-100 does not repeal or amend § 1; the two sections differ in covered actors and required content and both apply from 2026-10-01. A model-generated claim that PA 26-100 replaced § 1 was checked against the retained PA 26-100 text and is not supported.
This is a second, separate assessment sitting alongside the CTDPA data protection assessment in § 42-522(b) — a controller doing legal-effect profiling now owes both, and the two have different content. The seven elements read as an AI model card written into privacy law: inputs, outputs, customization data, performance metrics, known limitations, transparency measures, and post-deployment monitoring. § 42-522(g)(2) is the date that matters operationally: the impact assessment duty applies only to processing activities created or generated **on or after 2026-08-01** and is expressly not retroactive, one month later than the section's own 2026-07-01 effective date, and a separate clock from the 2023-07-01 line that governs data protection assessments under § 42-522(g)(1).
Tagged `sleeper` because the duty is AI-specific but lives inside a general consumer privacy act, so it binds by controller status rather than by anything the controller does with models. Every organization over the § 42-516 threshold — retailers, insurers, hospitals, employers — must now take a position in its published privacy notice on whether it collects, uses or sells personal data to train large language models, including the position that it does not. That makes it the first US statutory disclosure aimed squarely at training-data provenance and the cheapest available discovery tool: the notice is a dated public statement the Attorney General can hold a controller to. Note the statute says "large language models" specifically, not "artificial intelligence" or "automated decision systems", so a controller training a non-language model is outside the literal text.
Filed under `risk-assessment` rather than `data-governance` because the ongoing compliance process the section creates is the § 42-529b(b) impact assessment — six enumerated elements, review on any material change to the profiling operations, and documentation kept for the longer of three years after the operations cease or as long as the service is offered. The consent gate in § 42-529a(b)(3)(B) is a condition on a single processing activity rather than a sustained process, and § 42-529a(a) ties the two together by giving a controller that complies with § 42-529b a rebuttable presumption of reasonable care in any Attorney General enforcement action — the assessment is the safe harbor, so it is where the compliance weight sits. Two scope moves are easy to miss. The consent gate was broadened from profiling in furtherance of any **fully** automated decision to **any** automated decision, so a human reviewer in the loop no longer takes a minor's profiling outside it — the same widening the act made to the adult opt-out in § 42-518. And the assessment trigger in § 42-529b(b) is any profiling at all by a service offered to minors, not only legal-effect profiling; only the first of the six elements is qualified by legal or similarly significant effects. Separately, § 42-529d(d)(4) permits processing a minor's personal data for legal-effect profiling solely to detect or correct bias, on five conditions including deletion once the processing is complete, pseudonymization and other industry-standard security measures, strict documented access controls, and no third-party transmission or access — a construction rule creating a safe harbor rather than an obligation, so it is recorded here rather than as its own provision.
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02. The Commission published Article 50 scope guidelines on July 20, 2026. The final Code of Practice on Transparency of AI-generated Content was published on June 10, 2026; the Commission concluded its adequacy assessment on July 8. The code is voluntary and supports implementation of Article 50(2), (4) and (5). It does not replace the Act or the guidelines, and adherence is not conclusive evidence of compliance. These implementation materials do not postpone the statutory application date or remove the Article 111(4) transitional condition.
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: relevant parts of a GDPR or LED data protection impact assessment may be cross-referenced where they already meet particular FRIA obligations; the remaining FRIA duties still apply, and the AI Office must ship a questionnaire template.
The three-limb definition in § 39-5-6(a)(1)(A) is conjunctive — memory, unprompted emotional questioning, and sustained personal dialogue must all be present — which is a narrower gate than California SB 243's reasonable-person test, but the recurring-disclosure cadence is stricter: every three hours generally, every hour for known or marketed-to minors. Subsection (h) is the only place the Act addresses licensed professionals: it bars an operator from programming a chatbot to claim mental health, behavioral health, medical, or counseling licensure unless the operator is lawfully authorized to provide those services. That is a proviso, not an exemption — a licensed clinician's companion chatbot is still fully subject to § 39-5-6.
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
The codified section number is not on the face of the act — Sec. 3 adds "a new section to part I" of ch. 481B "to be appropriately designated", so provisions are cited by the subsection letters (a) to (i) that do appear in the enacted text until the revisor publishes the number. Hawaii is the only 2026 state companion-AI statute already in force; Washington, California, Oregon and Nebraska all run from 2027. The minor cadence is the strictest in the cohort: at least once per hour, and the reminder must also tell the user to take a break from the chat, where Washington and Nebraska stop at a three-hour general interval. A persistent visible disclaimer under § (b)(1) is an accepted alternative to the whole session-start-plus-hourly cadence, which no other state in the cohort allows. The general disclosure in § (a) keeps a reasonable-person trigger, unlike Washington's unconditional duty.
Two duties here have almost no analogue in the cohort. § (c)(2) requires evidence-based methods for measuring suicidal ideation and the risk of self-harm — a methodological standard rather than a "reasonable measures" standard, which only Oregon and Colorado otherwise impose. § (c)(5) reaches outward: reasonable measures must prevent outputs encouraging the user to cause serious bodily injury to another person, and no other state statute in this cohort covers harm to third parties at all. § (c)(3) also bars the companion from representing that it is designed to provide professional mental or behavioral health care, which pulls the section into scope-of-practice territory alongside consumer protection.
The trigger is actual knowledge or reasonable certainty, not an age-estimation duty — the legislature's findings in Sec. 2 expressly say regulation should "proactively avoid the mandatory collection of data by technology companies such as identity documentation for age verification purposes", so Hawaii deliberately declines the Colorado-style duty to estimate age. § (d)(1) targets variable-ratio reward schedules by name (points or similar rewards at unpredictable intervals intended to encourage increased engagement), which is a narrower and more mechanism-specific engagement ban than Washington's eight-technique list. § (d)(4) is the cohort's parental-tools duty: screen-time and account-settings controls must be available to the user and to parents and guardians alike.
Idaho's enterprise carve-outs (§ 48-2102(2)(b)(v), (viii)) are broader than California SB 243's, so the Act lands almost entirely on consumer-facing assistants and companion apps. The § 48-2104(4) duty is the unusual one: it regulates model behaviour rather than interface copy, requiring reasonable measures against simulated emotional dependence, romantic or sexual innuendo, and adult-minor romantic role-play for minor account holders.
The § 48-2104(2) ban on variable-ratio rewards is the first US AI statute to regulate an engagement mechanic by name rather than its effects, and it is intent-qualified — the reward must be given with intent to encourage increased engagement. Actual-knowledge-or-reasonable-certainty framing means the duties bite only once an operator has age signals, so age assurance is not itself mandated.
India's first binding synthetic media obligations: intermediaries enabling AI-generated content (deepfakes, audio/video synthesis) must embed permanent provenance metadata and prominent labels — and prevent their removal. Non-compliance forfeits safe harbor under the IT Act 2000.
Two disclosure regimes sit side by side. The general one in § 554J.3 fires only on a reasonable-individual mistaken-for-human test, so a service that visibly presents as a bot may owe nothing. The minor-account-holder one in § 554J.2(1) has no such trigger: if the operator knows or is reasonably certain the account holder is under 18, the disclaimer is owed unconditionally. Both routes accept a persistent visible disclaimer, which is the cheap compliance path and is likely what most operators will build.
This is the provision with no California analogue. SB 243 regulates the disclosure; Iowa regulates the persona. Barring statements that "simulate emotional dependence" or "simulate a romantic interaction" reaches model behaviour rather than interface copy, which means the compliance artifact is a system prompt, a fine-tune, or an output classifier — not a banner. It is drafted as a reasonable-measures standard, so the question at enforcement will be what the operator did to prevent the output, not whether the output ever occurred.
The variable-reward bar in § 554J.2(2) is the first US AI statute to regulate an engagement mechanic rather than an output. It borrows the language of intermittent reinforcement — "points or similar rewards at unpredictable intervals" — and is gated on intent to encourage increased engagement, which makes internal growth documents the natural evidence. Note the drafting asymmetry: § 554J.2(2) reaches a "minor user" while § 554J.2(3) reaches a "minor account holder", so the reward bar plausibly applies without an account.
Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.
Article 7 treats healthcare AI as support in prevention, diagnosis, care, and therapeutic choice while reserving the clinical decision to medical professionals. It separately gives the interested person a right to be informed of AI use and requires healthcare AI systems and their data to be reliable, periodically verified, and updated.
Penalties qualification: This entry does not assign a provision-specific penalty to the Article 7 requirements. Applicable oversight and sanctions depend on the competent authority and the relevant national and EU framework.
Institutional context (not a private requirement): Article 10 inserts Article 12-bis into Decree-Law 179/2012. It assigns AGENAS the design, implementation, operation, and ownership of a national healthcare AI platform. The platform supplies non-binding suggestions to healthcare professionals and doctors and access support to users. These are statutory functions of AGENAS and the platform, not requirements imposed on the private deployers described in the Article 7 provision above.
Article 11 requires employers and principals to inform workers of workplace AI use in the cases and modalities of Article 1-bis of Legislative Decree 152/1997. That incorporated provision covers fully automated decision or monitoring systems producing indications relevant to specified employment decisions and conditions. Article 4(4) separately ties under-14 access to AI technologies and consequent personal-data processing to parental-responsibility consent.
Penalties qualification: This entry does not assign a provision-specific penalty to Article 11. Applicable consequences depend on the incorporated employment-law duties and the competent national and EU enforcement frameworks.
Owners and holders classify AI systems as minimum, medium, or high risk and perform lifecycle risk management. Article 19(2) requires an audit when an owner or holder seeks inclusion in an industry authority's trusted high-risk list; Article 20 specifies the audit framework and added assessment topics. Article 25 describes the National AI Platform as a controlled environment for platform software products and models, but does not require every high-risk system to be developed or tested there.
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a 15–200 MCI fine range.
Article 21 requires users to be informed when goods, works, or services are produced or provided using AI. Distribution of a synthetic result is allowed only with a machine-readable mark and a perceptible visual or other warning. Article 1(4) limits a synthetic result to AI-created or AI-altered image, video, audio, text, or a combination that imitates a natural person's appearance, voice, or behaviour, or events that did not occur; it does not cover every generated output.
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a labeling-specific MCI fine.
Article 17(3) prohibits creating or operating AI systems in Kazakhstan when they possess one of seven listed functionalities. The clauses are conditional: manipulative methods must distort behaviour and constrain informed choice or force a decision capable of causing harm; vulnerability exploitation requires a harmful purpose or threat; social evaluation has statutory exceptions; biometric classification must be for discrimination; and emotion detection has consent and statutory exceptions.
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set an Article 17-specific MCI fine or suspension rule.
Maine put this rule in Title 10 (commerce and trade), not in a licensing chapter, which is what gives it reach beyond Maine licensees: § 1500-EE(2) binds any "person" who offers therapy to the Maine public through Internet-based AI, and § 1500-EE(3) converts a violation into an Unfair Trade Practices Act violation enforced by the Attorney General. The statute never calls itself an AI law in its operative duty — it is drafted as a licensure and trade-practices rule — yet the therapeutic-communication definition at § 1500-EE(1)(C)(3), "offering emotional support, reassurance or empathy in response to psychological or emotional distress", describes ordinary consumer companion-chatbot behavior, not only purpose-built therapy products. Advertising and offering are covered alongside providing, so marketing an AI mental-health product into Maine is itself the violation. The IRB carve-out mirrors Rhode Island's and Vermont's, which is now the settled shape of this exemption across the three states.
The allocation of liability is unqualified: § 2113(2)(A) makes the licensee responsible for "all interactions, outputs and data use" associated with the AI, with no carve-out for vendor-controlled design or algorithms — the opposite of Rhode Island's § 40.1-5.5-3(c)(2), which expressly excludes vendor-controlled system design from provider responsibility. A Maine licensee therefore cannot contract that residue away, which is what pushes the duty onto vendor selection and configuration. The prohibitions at § 2113(4) fix the human-in-the-loop boundary — no independent therapeutic decisions, no direct therapeutic interaction with clients, and no recommendation or treatment plan that has not been reviewed and approved by the licensee. P.L. 2026 ch. 687 replicates § 2113 verbatim across six further licensing chapters (32 M.R.S. §§ 2600-G, 3300-J, 3820-A, 6207-D, 7009, and 13870), so the same duty attaches to every board that licenses a mental-health profession in Maine; the rules implementing it are major substantive rules under 5 M.R.S. ch. 375, subch. 2-A, meaning they must go back to the Legislature for review before final adoption.
This is the requirement neither Vermont nor Rhode Island has: Maine permits AI supplementary support "only when the client's therapeutic session is recorded or transcribed" (§ 2113(3)). That is an affirmative surveillance precondition, not a restriction on surveillance — a practice that wants an AI scribe or progress-tracking tool must first put the session on the record. Paired with it is a consent definition (§ 2113(1)(C)) that is unusually strict even against Rhode Island's: consent must be a clear, explicit, affirmative act communicating express, informed, voluntary, specific, unambiguous written agreement, revocable by the client, and it expressly is not acceptance of a general or broad terms-of-use agreement, not hovering over, muting, pausing, or closing electronic content, and not anything obtained through deceptive actions. The disclosure at § 2113(3)(A)(3) reaches further than either sibling statute: the client must be told in writing how session data will be stored, retained, **used for training**, and deleted on termination of services — a written commitment about training-data use, made per client. And § 2113(5) bars the licensee from denying or refusing treatment because the client withheld consent, so declining AI is genuinely costless for the client and fully blocking for the licensee. Any client waiver of the section is void as contrary to public policy (§ 2113(11)), which forecloses the intake-paperwork workaround.
LN 226/2025 adds no Maltese classification or general risk-assessment duty: classification follows Article 6 and Annex III of Regulation (EU) 2024/1689. The two operator requirements below retain their own named actors; this grouped section has no common role or asserted obligation-category mapping. Institutional context: MDIA is market-surveillance authority and single point of contact (reg. 3), coordinates with the specified sectoral authorities, and is Notifying Authority; the National Accreditation Board performs the Article 28(1) assessment and monitoring (reg. 7). MDIA establishes and runs the national regulatory sandbox (reg. 9); participation is a facility, not an operator duty. Registration, importer-information and sandbox provisions commence on 2026-08-02; the earlier institutional designations and penalty provisions are not deferred by the grouped Effective date.
Penalties qualification: Imposed by MDIA and without prejudice to the Chapter XII penalties of Regulation (EU) 2024/1689. Appeals lie under Part IX of the MDIA Act.
The act is not yet codified into numbered Neb. Rev. Stat. sections on the face of the slip law, so provisions here are cited to the session-law section numbers of LB 525. Two design choices separate Nebraska from the other 2026 state chatbot statutes: a persistent visible disclaimer is an accepted substitute for the three-hour reminder cadence, which Washington's ESHB 2225 does not allow, and the duty attaches to minor *account holders* rather than to any minor user, so an operator that runs no accounts never triggers it.
Nebraska's engagement ban is narrower than Washington's eight-technique list: it reaches only variable-ratio rewards — points or similar rewards at unpredictable intervals with intent to increase engagement — leaving other retention mechanics untouched. The anthropomorphism duty is unusual in naming simulated emotional dependence and adult-minor romantic role-play as specific outputs the operator must take reasonable measures to prevent.
Unlike Washington's unconditional disclosure, Nebraska's general duty triggers only on the reasonable-person misleading test, so a service that is obviously artificial owes nothing under sec. 15 — the account-based minor duty in sec. 14(1) is the unconditional one. Sec. 17 bars only the explicit representation that the service is designed to deliver professional mental or behavioral health care, and it carries a knowing-and-intentional scienter element, so incidental therapeutic-sounding output is not itself a violation.
Nebraska states the crisis duty in a single sentence and, unlike Washington, does not gate deployment on having the protocol, name eating disorders, or require any public disclosure of referral counts — the duty is to adopt a protocol and make reasonable efforts to refer. The "includes, but is not limited to" framing leaves the floor open, which means the Attorney General, not the statute, will set the practical content of an adequate protocol.
Structured as a prohibition on operating without the protocol, so the compliance question is binary rather than a standard of care. The three-part definition of an AI companion in § 1700(4)(a) is conjunctive — memory across sessions, unprompted emotion-based questions, and sustained personal dialogue — which is narrower than California's SB 243 test and turns on product design rather than on marketing category.
The cadence rule cuts both ways: the notice need not appear more than once per day, but must appear at least every three hours within a continuing interaction. New York and California both settled on a three-hour interval, though New York applies it to all users while California's applies only to users known to be minors.
Oregon's definition is narrower and more mechanical than California's — it requires all three of cross-session memory, unprompted emotional questioning, and sustained personal dialogue, so a system that merely remembers a user is outside the act. The minor-facing break reminder in § 1(4)(b)(B) is a session-flow mandate, not a copy change.
The duty is a gate on access, not a best-efforts standard: without the protocol the operator may not allow Oregon users access at all. Two features go beyond California SB 243 — the protocol must use evidence-based detection methods rather than merely respond after the fact, and § 1(3)(b)(B) requires clinical best practices for escalated intervention when a user keeps expressing intent after the first referral.
This is the provision with no California analogue. Section 1(4)(c) bans variable-ratio reward schedules, guilt-inducing exit friction, and misrepresentation of the system's identity, capabilities, or training data — engagement-optimisation patterns, regulated as product design rather than as speech. Operators serving mixed-age audiences will need an age signal to know which regime applies, though the act imposes no age-verification duty.
The guideline sets requirements and guidance for QCB-regulated entities. Clause 11.1 requires approval before launching a new AI system as a Provider or materially modifying an existing one. Clause 11.2 separately requires approval before signing a high-risk purchase, licensing or outsourcing agreement. QCB may direct sandbox evaluation before approval under clause 11.3. No comparative claim that this is the first GCC regulation is established here.
Penalties qualification: Penalties not specified in the guideline. Non-compliance is subject to QCB's general supervisory and enforcement powers over licensed entities.
Structured as a gate on operation, not a best-efforts duty: it is unlawful to operate or provide the companion at all unless the protocol is built in. Rhode Island's definition is narrower than California SB 243's reasonable-person test — the three limbs in § 6-63-1(1)(i) are conjunctive, so a system that never asks unprompted emotion-based questions falls outside the chapter. But the protocol scope is broader on one axis: it reaches threatened physical harm to others (§ 6-63-2(a)(2)), which California does not cover.
The duty falls on private-sector actors, not only on licensees: § 40.1-5.5-3(b) reaches any "individual, corporation, or entity" that offers therapy to the Rhode Island public "including through the use of internet-based artificial intelligence", so an out-of-state AI therapy product marketed into Rhode Island is directly in scope, and the vendors selling clinical-adjacent AI into private practices are constrained by what their customers may lawfully deploy. That is what makes this an AI-deployment rule rather than a professional-licensing rule. The liability allocation is the sharpest edge: the provider retains clinical judgement and therapeutic oversight "but not for vendor-controlled system design, algorithms, or outputs" (§§ 40.1-5.5-2(6), 40.1-5.5-3(c)(2)) — the statute carves the provider's responsibility around the vendor's black box without saying who carries the residue.
The consent definition does the work. § 40.1-5.5-2(3) rules out the three cheapest consent mechanics in software: acceptance of broad terms of use that bury the AI description among unrelated material, dark-pattern interactions (hovering, muting, pausing, closing content), and deceptive actions. Consent must be affirmative, written or electronic, purpose-specific, and revocable — which means the product needs a per-purpose consent record and a revocation path, not a checkbox. § 40.1-5.5-3(c) then makes consent a condition precedent: AI use is permitted "only to the extent that such use meets the requirements of subsection (a)".
The chapter links two duties for healthcare providers and facilities using AI to document in-person or telehealth visits: notify patients of that documentation use and review the resulting documentation for accuracy after the visit. The phrase "for that sole purpose" describes the documentation use; this chapter does not establish duties for diagnosis or triage. Section 23-108-3 requires review, without specifying an attestation step. The linked duties are modelled as one provision.
Resolution No. 0001/2025 creates two tracks: voluntary registration for entities seeking the Law's Article 19 safeguards, and mandatory registration for operators deploying consequential-decision AI in six listed sectors. General-purpose model, API, platform, and cloud providers are not required to register solely because they supply those services; developers register only if they also operate a covered deployment. Existing covered systems received a 12-month grace period from the Resolution's effective date.
Penalties qualification: Specific penalty amounts are not stated in the Resolution. ANIA ordinarily proceeds through education, at least 60 days to remediate, formal notice, and a compliance order before referral; emergency action is reserved for a clear and imminent risk of serious harm (Resolution Art. 28).
Law Article 17 makes the ANIA risk-framework requirements mandatory only for systems handling data classified as confidential, reserved, or personal. Resolution Articles 10 and 15 additionally require an algorithmic impact assessment for systems subject to mandatory registration because of a covered consequential-decision deployment.
Penalties qualification: Subject to ANIA's general enforcement powers. Specific penalty amounts not confirmed in available sources.
Creates de facto compliance obligations for any AI vendor selling LLMs to the US federal government. Agencies must require vendor documentation including model cards, data cards, acceptable use policies, and risk disclosures. Agencies must reject non-compliant models. Not branded as AI regulation, but effectively mandates transparency for a significant market segment.
Establishes two Unbiased AI Principles — truth-seeking and ideological neutrality — that federal LLM procurements must comply with. Agencies must adopt procedures to enforce compliance and hold vendors accountable. Effectively creates a content-level compliance standard for the federal market.
Establishes a voluntary framework under which frontier developers may engage the government to have models designated "covered frontier models" and provide up to 30 days of pre-release access for evaluation before other trusted partners. The framework itself does not yet exist — Treasury, NSA, and CISA must design it within 60 days. Section 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement, so participation is opt-in. Worth watching: a voluntary pre-release evaluation regime can harden into a de facto procurement or trusted-vendor expectation.
Does not create compliance obligations for AI companies. Instead, directs DOJ to form a task force to challenge state AI laws on preemption, interstate commerce, and First Amendment grounds. Directly threatens enforceability of state laws tracked in this reference (Colorado SB 24-205, Illinois HB 3773, California ADS regs, NYC LL144, and others). Section 8(b) carveouts bar the legislative recommendation from proposing preemption of state laws on child safety, AI compute and data-center infrastructure (other than generally applicable permitting reforms), and state government procurement and use of AI.
Directs the Secretary of Commerce to evaluate existing state AI laws within 90 days and identify those that conflict with federal objectives. A companion BEAD Policy Notice (§ 5(a)) makes states with those laws ineligible for BEAD non-deployment funds — not BEAD funding as a whole — and § 5(b) extends the same leverage to agency discretionary grants. Section 7 directs the FTC to issue a policy statement on how the FTC Act preempts state laws mandating alterations to truthful AI outputs, and § 6 directs the FCC to open a proceeding on a preemptive federal reporting and disclosure standard. No direct obligations for AI developers — but the evaluation results will shape which state laws survive federal challenge.
The therapeutic-communication definition is what pulls general-purpose AI products in: "offering clinical support, including reassurance or empathy in response to emotional or psychological distress" (§ 7115(a)(4)(C)) describes the default behavior of consumer companion chatbots, not just purpose-built therapy apps. And because § 7115(b) attaches to advertising and offering, not only delivering, marketing an AI product for mental health support to Vermonters is itself the violation. Enforcement runs through the Consumer Protection Act, which brings both AG civil penalties and a private right of action (§ 7115(c)(1)) — a materially stronger remedy stack than Rhode Island's EOHHS-investigation model for the equivalent rule.
This is the standing human-oversight loop, the same structure as Rhode Island ch. 40.1-5.5: AI can sit in the workflow only while a professional continuously reviews and approves what reaches the patient. Vermont's version is conditioned twice over — the tool must be HIPAA-compliant, and the professional must review and approve "any mental health services" — which constrains what vendors can sell into practices (a product with no review-and-approve surface cannot be lawfully deployed). The licensure hooks give it teeth on the professional side: prohibited AI use is per se unprofessional conduct for every § 129a licensee and for physicians under § 1354, whether committed inside or outside Vermont.
Washington's general disclosure is unconditional — unlike California SB 243 and Oregon ch. 85, it does not turn on whether a reasonable person would be misled, so every covered chatbot discloses at the start of the interaction and every three hours regardless of how obviously artificial it is. Sec. 3(3) adds a model-behaviour duty rather than a copy duty: the system must be constrained from claiming to be human when asked, which is an alignment requirement in statute. The educational-tools carve-out in Sec. 2(1)(b)(iv) has no California or Oregon analogue.
The "directed to minors" trigger means an operator cannot avoid this section by declining to determine user age — audience design alone brings the product in. The eight enumerated manipulative techniques in Sec. 4(1)(c) are the most detailed engagement-design ban of the three 2026 companion statutes, reaching in-app monetisation framed as relationship maintenance (Sec. 4(1)(c)(viii)) and outputs promoting isolation from family (Sec. 4(1)(c)(v)). Minors get a one-hour reminder cadence against the three-hour general rule.
Structured as a gate on deployment: no protocol, no chatbot. Washington is the only one of the three 2026 companion statutes to name eating disorders explicitly within the detection duty (Sec. 5(2)(a)), which pulls disordered-eating content into a self-harm safety pipeline that most moderation stacks treat separately. Unlike Oregon, no specific hotline is mandated — "a suicide hotline or crisis text line" is sufficient.
cross-domain 47 provisions
Provisions that span multiple industries. A privacy rule that affects AI in hiring, lending, and insurance simultaneously.
The enacted amendments expressly cover algorithms, artificial intelligence, automation and online platforms. Section 19(3)(c1) addresses worker health and safety risks from their use; section 21A specifically addresses allocation of work and requires consideration of listed workload, metrics, monitoring and unlawful-discrimination risks. These amendments require proclamation. Their pending status does not mean existing WHS duties cease to apply to digital systems. The section 118 duty to assist an entry permit holder is separate from the risk duties summarized here. Its penalties are not penalties for breach of sections 19(3)(c1) or 21A.
The new power requires a PCBU to provide reasonable assistance with access and inspection of a digital work system relevant to a suspected WHS contravention. SafeWork distinguishes this from existing inspection rights. Commencement requires proclamation and cannot be earlier than one month after publication of the first guidelines; exercise also requires guidelines relevant to the particular power/workplace under Schedule 1[11]. The 2026-09-08 source review did not establish these events, so the provision is pending with no effective date assigned.
From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to contain the APP 1.8 information only when the entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect an individual's rights or interests; and personal information about that individual is used in the program for that decision or related thing. This is an APP-entity duty with statutory conditions, not a rule for every AI provider or every use of personal information.
APP 3 regulates an APP entity's collection of solicited personal information, and APP 6 restricts an APP entity's use or disclosure of personal information for a secondary purpose unless an exception applies. OAIC guidance applies those existing rules to covered AI collection, generation, inference, inputs, uses, and disclosures. It describes proportionality and data minimisation under APP 3 and recommends minimising personal information used or disclosed for an APP 6 secondary purpose. These are not duties on every AI system or new APP clauses commencing in December 2026.
The disclosure runs to training inputs rather than outputs, which makes it the counterpart to the provenance duties in the California AI Transparency Act: one documents what went into the model, the other marks what comes out. It bites on every substantial modification — a new version, release, update, retraining, or fine-tune that materially changes functionality or performance — so it is a recurring release-gate obligation, not a one-time filing. There is no penalty provision and no named enforcer in the chapter.
The provenance chain's other end: the rest of the chapter marks content as synthetic, while this section marks content as camera-captured. It reaches hardware manufacturers rather than AI developers, so it lands on companies that may not otherwise track AI regulation — and default-on embedding (subdivision (a)(2)) is a firmware-level design decision with a long lead time.
The duty is structured as a gate: without the protocol, the operator must prevent the chatbot from engaging with users. The operator must publish details of the protocol, not necessarily the full internal document (§ 22602(b)(2)).
Article 4 requires explicit labels for generative and deep-synthesis services within the specified Deep Synthesis Provisions Article 17(1) scenarios. Article 9 permits delivery without an explicit label on user request if the provider allocates labeling duties and use responsibilities in the user agreement and retains recipient information and related logs for at least six months. Article 10 extends the anti-tampering prohibition to **any organization or individual**, including providers of label-removal tools or services.
The compliance dimension the Deep Synthesis Provisions do not have: duties that bind actors who never generated the content. Article 6 makes every covered network-information-content dissemination-service provider a verifier with a three-tier response, and Article 7 adds an app-store listing check.
Article 8 addresses transparency and identification of AI-generated content through context- and risk-tailored measures adopted by Parties; it does not directly impose a universal content label on providers. Article 15(2) says each Party "shall seek to ensure" contextual human-vs-AI notification. Signature or approval alone does not establish that the treaty is in force or that a particular private actor has a direct duty.
Article 16 directs Parties to adopt graduated, context-sensitive risk measures and assess whether uses they consider incompatible with human rights, democracy or the rule of law warrant a moratorium, ban or other measure. Its operation depends on treaty entry into force and Party implementation.
Article 14 remedies are qualified by each Party's international obligations and domestic legal system. Article 15(1) applies procedural safeguards where an AI system significantly affects enjoyment of human rights; Article 15(2) separately asks Parties to seek context-appropriate interaction notice. The treaty text does not create an unqualified private appeal right.
Article 10 calls for Party measures respecting equality, including gender equality and nondiscrimination under applicable law, and measures aimed at overcoming inequalities. Article 16 addresses related risks and impacts; Article 17 requires nondiscriminatory implementation of the Convention. These are Party-level duties qualified by applicable international and domestic law.
These definitions govern profiling within the CPA's controller, personal-data, and statutory-consumer scope. The significant-effects definition includes employment opportunities, but “Consumer” excludes a person acting in a commercial or employment context, a job applicant, and a beneficiary of someone acting in an employment context; C.R.S. § 6-1-1304(2)(k) separately exempts data maintained for employment records purposes. Rule 7.09 creates a distinct employee biometric-identifier consent regime and does not expand Part 9 profiling duties to ordinary employment records. Rule 9.04(B)-(C) applies the three processing definitions to profiling opt-out requests within the CPA’s covered scope.
Rule 9.06 applies to covered controllers before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in C.R.S. § 6-1-1309(2)(a). Rules 9.02 and 9.03 list employment opportunities among significant-effect decision domains, but the statute's Consumer definition excludes an employment context, a job applicant, and an employment-context beneficiary, and § 6-1-1304(2)(k) exempts employment records. Rule 7.09 separately regulates employee biometric identifiers.
Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says "but not including a law enforcement agency." The exclusion applies to the required crisis-service referral. The text does not resolve every possible separate welfare-check or escalation practice, and a claim of uniqueness would require a separate comparative source review. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.
Not a disclosure rule but a liability rule, and it is the sharpest incentive in the Act: using an automated employment-related decision technology is expressly not a defense to a discrimination complaint, while evidence of anti-bias testing may be considered in the employer's favour. That asymmetry converts bias testing from a good practice into the only available mitigation, which is why it belongs under bias-prevention rather than with the disclosure provisions.
This is the provision that converts the § 42-522(c) impact assessment from a paperwork exercise into a retained, producible record. Three design choices matter together: the Attorney General may compel any assessment relevant to an investigation and evaluate it for compliance across §§ 42-515 to 42-525; the assessments are confidential and exempt from the Freedom of Information Act, so a competitor cannot obtain them by request; and disclosure to the Attorney General waives neither attorney-client privilege nor work product protection. The privilege carve-out is the load-bearing piece — without it, counsel would advise against writing anything candid in an assessment, which is precisely how comparable assessment regimes hollow out.
Filed under `risk-assessment` rather than `data-governance` because the ongoing compliance process the section creates is the § 42-529b(b) impact assessment — six enumerated elements, review on any material change to the profiling operations, and documentation kept for the longer of three years after the operations cease or as long as the service is offered. The consent gate in § 42-529a(b)(3)(B) is a condition on a single processing activity rather than a sustained process, and § 42-529a(a) ties the two together by giving a controller that complies with § 42-529b a rebuttable presumption of reasonable care in any Attorney General enforcement action — the assessment is the safe harbor, so it is where the compliance weight sits. Two scope moves are easy to miss. The consent gate was broadened from profiling in furtherance of any **fully** automated decision to **any** automated decision, so a human reviewer in the loop no longer takes a minor's profiling outside it — the same widening the act made to the adult opt-out in § 42-518. And the assessment trigger in § 42-529b(b) is any profiling at all by a service offered to minors, not only legal-effect profiling; only the first of the six elements is qualified by legal or similarly significant effects. Separately, § 42-529d(d)(4) permits processing a minor's personal data for legal-effect profiling solely to detect or correct bias, on five conditions including deletion once the processing is complete, pseudonymization and other industry-standard security measures, strict documented access controls, and no third-party transmission or access — a construction rule creating a safe harbor rather than an obligation, so it is recorded here rather than as its own provision.
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02. The Commission published Article 50 scope guidelines on July 20, 2026. The final Code of Practice on Transparency of AI-generated Content was published on June 10, 2026; the Commission concluded its adequacy assessment on July 8. The code is voluntary and supports implementation of Article 50(2), (4) and (5). It does not replace the Act or the guidelines, and adherence is not conclusive evidence of compliance. These implementation materials do not postpone the statutory application date or remove the Article 111(4) transitional condition.
A permission, not a mandate — Article 4a(2) states expressly that it creates no obligation to conduct bias detection. It supplies an express AI Act route to processing special-category personal data for covered bias work, with six cumulative safeguards for anyone who uses it; other potential data-protection-law bases require their own analysis. Replaces the former Article 10(5), which was limited to high-risk training data.
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
Two duties here have almost no analogue in the cohort. § (c)(2) requires evidence-based methods for measuring suicidal ideation and the risk of self-harm — a methodological standard rather than a "reasonable measures" standard, which only Oregon and Colorado otherwise impose. § (c)(5) reaches outward: reasonable measures must prevent outputs encouraging the user to cause serious bodily injury to another person, and no other state statute in this cohort covers harm to third parties at all. § (c)(3) also bars the companion from representing that it is designed to provide professional mental or behavioral health care, which pulls the section into scope-of-practice territory alongside consumer protection.
The trigger is actual knowledge or reasonable certainty, not an age-estimation duty — the legislature's findings in Sec. 2 expressly say regulation should "proactively avoid the mandatory collection of data by technology companies such as identity documentation for age verification purposes", so Hawaii deliberately declines the Colorado-style duty to estimate age. § (d)(1) targets variable-ratio reward schedules by name (points or similar rewards at unpredictable intervals intended to encourage increased engagement), which is a narrower and more mechanism-specific engagement ban than Washington's eight-technique list. § (d)(4) is the cohort's parental-tools duty: screen-time and account-settings controls must be available to the user and to parents and guardians alike.
This is a filing to a health regulator, not a consumer-protection disclosure — Washington and Oregon make the crisis-referral count a public self-disclosure with no recipient agency, while Hawaii routes it to the behavioral health administration of the Department of Health, which is where the state's own suicide-prevention programming sits. The data-minimisation proviso is a hard cap rather than a floor: the report "shall include only the information listed in this subsection" and no user identifiers or personal information, so an operator cannot pad the filing with supporting detail. The duty is the one part of the act not in force on approval; it begins with the first report on 2028-01-01, covering the preceding calendar year.
Structured as an adoption duty with a reasonable-efforts floor, not California SB 243's engagement gate: Idaho does not bar the service from operating without a protocol, does not require the protocol to be published, and imposes no annual reporting. The practical consequence is that the crisis protocol is only visible to the Attorney General on investigation.
AI processing can fall within this general data-protection law when section 3 applies. Personal/domestic processing and qualifying publicly available data are excluded by section 3(c); other exemptions are in section 17. The core consent, accuracy, security and breach-notification duties summarized here are in the eighteen-month phase, not already enforcing merely because the Board-related phase began.
Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.
The scienter standard is the highest in the chapter — "knowingly and intentionally cause or program" — so an emergent therapeutic persona the operator did not design is outside this section, though it may still be caught by the reasonable-measures duty in § 554J.2(4). The bar is on representation, not on function: a service may in fact behave therapeutically as long as it does not lead a reasonable individual to believe it is a licensed practice.
Article 7 treats healthcare AI as support in prevention, diagnosis, care, and therapeutic choice while reserving the clinical decision to medical professionals. It separately gives the interested person a right to be informed of AI use and requires healthcare AI systems and their data to be reliable, periodically verified, and updated.
Penalties qualification: This entry does not assign a provision-specific penalty to the Article 7 requirements. Applicable oversight and sanctions depend on the competent authority and the relevant national and EU framework.
Institutional context (not a private requirement): Article 10 inserts Article 12-bis into Decree-Law 179/2012. It assigns AGENAS the design, implementation, operation, and ownership of a national healthcare AI platform. The platform supplies non-binding suggestions to healthcare professionals and doctors and access support to users. These are statutory functions of AGENAS and the platform, not requirements imposed on the private deployers described in the Article 7 provision above.
Article 11 requires employers and principals to inform workers of workplace AI use in the cases and modalities of Article 1-bis of Legislative Decree 152/1997. That incorporated provision covers fully automated decision or monitoring systems producing indications relevant to specified employment decisions and conditions. Article 4(4) separately ties under-14 access to AI technologies and consequent personal-data processing to parental-responsibility consent.
Penalties qualification: This entry does not assign a provision-specific penalty to Article 11. Applicable consequences depend on the incorporated employment-law duties and the competent national and EU enforcement frameworks.
Article 8 establishes a health-research pathway for specified public, nonprofit, IRCCS, and participating private health-sector actors. For those actors and purposes, secondary use under paragraph 2 is limited to personal data lacking direct identifiers, preserves the information duty, and carries an exception where identity is unavoidable or necessary to protect health. Processing under paragraphs 1 and 2 must be communicated to the Garante and may begin after 30 days if the Garante has not blocked it.
Penalties qualification: Article 8(6) preserves the Garante's inspection, prohibition, and sanctioning powers. This entry does not assign a fixed penalty ceiling or infringement category to Article 8 conduct.
Institutional context (not a private requirement): Article 8(4) permits AGENAS, after consulting the Garante and considering international standards and the state of the art, to establish and update guidelines for anonymization procedures and synthetic data. The provision grants an institutional power; it does not itself impose a universal anonymization standard on every researcher.
Maine put this rule in Title 10 (commerce and trade), not in a licensing chapter, which is what gives it reach beyond Maine licensees: § 1500-EE(2) binds any "person" who offers therapy to the Maine public through Internet-based AI, and § 1500-EE(3) converts a violation into an Unfair Trade Practices Act violation enforced by the Attorney General. The statute never calls itself an AI law in its operative duty — it is drafted as a licensure and trade-practices rule — yet the therapeutic-communication definition at § 1500-EE(1)(C)(3), "offering emotional support, reassurance or empathy in response to psychological or emotional distress", describes ordinary consumer companion-chatbot behavior, not only purpose-built therapy products. Advertising and offering are covered alongside providing, so marketing an AI mental-health product into Maine is itself the violation. The IRB carve-out mirrors Rhode Island's and Vermont's, which is now the settled shape of this exemption across the three states.
This is the requirement neither Vermont nor Rhode Island has: Maine permits AI supplementary support "only when the client's therapeutic session is recorded or transcribed" (§ 2113(3)). That is an affirmative surveillance precondition, not a restriction on surveillance — a practice that wants an AI scribe or progress-tracking tool must first put the session on the record. Paired with it is a consent definition (§ 2113(1)(C)) that is unusually strict even against Rhode Island's: consent must be a clear, explicit, affirmative act communicating express, informed, voluntary, specific, unambiguous written agreement, revocable by the client, and it expressly is not acceptance of a general or broad terms-of-use agreement, not hovering over, muting, pausing, or closing electronic content, and not anything obtained through deceptive actions. The disclosure at § 2113(3)(A)(3) reaches further than either sibling statute: the client must be told in writing how session data will be stored, retained, **used for training**, and deleted on termination of services — a written commitment about training-data use, made per client. And § 2113(5) bars the licensee from denying or refusing treatment because the client withheld consent, so declining AI is genuinely costless for the client and fully blocking for the licensee. Any client waiver of the section is void as contrary to public policy (§ 2113(11)), which forecloses the intake-paperwork workaround.
The statute reaches AI only indirectly. Art. 2 Fraction XIX defines "tratamiento" to include operations carried out by automated procedures, so processing personal data with AI is covered, and the Art. 14-17 privacy-notice duties apply. The consolidated text (Última Reforma DOF 14-11-2025) contains no occurrence of "inteligencia artificial" or "algoritmo", and Art. 15 does not require disclosure of algorithmic logic, significance, or consequences. No secondary regulation is bound here to establish any additional duty; such a duty remains unconfirmed.
The statute provides a right to object, not a duty of oversight. Art. 26(II) lets a data subject oppose processing where their data undergoes automated processing that produces unwanted legal effects or significantly affects their interests, rights, or freedoms, and is intended to evaluate personal aspects — professional performance, economic situation, health, sexual preferences, reliability, or behaviour — without human intervention. The text imposes no human-in-the-loop requirement, no impact assessment, and no safeguards specific to agentic systems; those duties are not confirmed by the retained source, and no implementing regulation establishing them is bound here.
Nebraska states the crisis duty in a single sentence and, unlike Washington, does not gate deployment on having the protocol, name eating disorders, or require any public disclosure of referral counts — the duty is to adopt a protocol and make reasonable efforts to refer. The "includes, but is not limited to" framing leaves the floor open, which means the Attorney General, not the statute, will set the practical content of an adequate protocol.
The duty is a gate on access, not a best-efforts standard: without the protocol the operator may not allow Oregon users access at all. Two features go beyond California SB 243 — the protocol must use evidence-based detection methods rather than merely respond after the fact, and § 1(3)(b)(B) requires clinical best practices for escalated intervention when a user keeps expressing intent after the first referral.
The duty falls on private-sector actors, not only on licensees: § 40.1-5.5-3(b) reaches any "individual, corporation, or entity" that offers therapy to the Rhode Island public "including through the use of internet-based artificial intelligence", so an out-of-state AI therapy product marketed into Rhode Island is directly in scope, and the vendors selling clinical-adjacent AI into private practices are constrained by what their customers may lawfully deploy. That is what makes this an AI-deployment rule rather than a professional-licensing rule. The liability allocation is the sharpest edge: the provider retains clinical judgement and therapeutic oversight "but not for vendor-controlled system design, algorithms, or outputs" (§§ 40.1-5.5-2(6), 40.1-5.5-3(c)(2)) — the statute carves the provider's responsibility around the vendor's black box without saying who carries the residue.
Creates de facto compliance obligations for any AI vendor selling LLMs to the US federal government. Agencies must require vendor documentation including model cards, data cards, acceptable use policies, and risk disclosures. Agencies must reject non-compliant models. Not branded as AI regulation, but effectively mandates transparency for a significant market segment.
Vendors must disclose training data provenance, limitations, and risk mitigations as a condition of federal procurement. While framed as ensuring "unbiased AI," the practical effect is a data governance disclosure requirement for the federal AI supply chain.
Establishes two Unbiased AI Principles — truth-seeking and ideological neutrality — that federal LLM procurements must comply with. Agencies must adopt procedures to enforce compliance and hold vendors accountable. Effectively creates a content-level compliance standard for the federal market.
The White House launched the clearinghouse as GOLD EAGLE on 2026-07-14. Open-source software partners and critical-infrastructure companies built the coordinated system, which had already begun receiving and prioritizing vulnerabilities from across sectors, coordinating scanning verification, and distributing prioritized threat and remediation information. Participation remains voluntary and creates no reporting mandate.
Does not create compliance obligations for AI companies. Instead, directs DOJ to form a task force to challenge state AI laws on preemption, interstate commerce, and First Amendment grounds. Directly threatens enforceability of state laws tracked in this reference (Colorado SB 24-205, Illinois HB 3773, California ADS regs, NYC LL144, and others). Section 8(b) carveouts bar the legislative recommendation from proposing preemption of state laws on child safety, AI compute and data-center infrastructure (other than generally applicable permitting reforms), and state government procurement and use of AI.
Directs the Secretary of Commerce to evaluate existing state AI laws within 90 days and identify those that conflict with federal objectives. A companion BEAD Policy Notice (§ 5(a)) makes states with those laws ineligible for BEAD non-deployment funds — not BEAD funding as a whole — and § 5(b) extends the same leverage to agency discretionary grants. Section 7 directs the FTC to issue a policy statement on how the FTC Act preempts state laws mandating alterations to truthful AI outputs, and § 6 directs the FCC to open a proceeding on a preemptive federal reporting and disclosure standard. No direct obligations for AI developers — but the evaluation results will shape which state laws survive federal challenge.
The therapeutic-communication definition is what pulls general-purpose AI products in: "offering clinical support, including reassurance or empathy in response to emotional or psychological distress" (§ 7115(a)(4)(C)) describes the default behavior of consumer companion chatbots, not just purpose-built therapy apps. And because § 7115(b) attaches to advertising and offering, not only delivering, marketing an AI product for mental health support to Vermonters is itself the violation. Enforcement runs through the Consumer Protection Act, which brings both AG civil penalties and a private right of action (§ 7115(c)(1)) — a materially stronger remedy stack than Rhode Island's EOHHS-investigation model for the equivalent rule.
Structured as a gate on deployment: no protocol, no chatbot. Washington is the only one of the three 2026 companion statutes to name eating disorders explicitly within the detection duty (Sec. 5(2)(a)), which pulls disordered-eating content into a self-harm safety pipeline that most moderation stacks treat separately. Unlike Oregon, no specific hotline is mandated — "a suicide hotline or crisis text line" is sufficient.