Hawaii Artificial Intelligence Disclosure and Safety Act (SB 3001)

Jurisdiction:
Hawaii
enforcing
Effective:
Jul 14, 2026
Full enforcement:
Jan 1, 2028
Authority:
Hawaii Office of Consumer Protection, Department of Commerce and Consumer Affairs
Official text

Obligations Covered

Transparency & Disclosure Risk Assessment Human Oversight Incident Reporting

Timeline

MilestoneDateNotes
Approved by the GovernorJul 14, 2026Act 248, Session Laws of Hawaii 2026
EffectiveJul 14, 2026Sec. 7 — takes effect upon approval
First annual report to the Department of HealthJan 1, 2028Subsec. (e)

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

AI Companion Artificiality Disclosure #

Obligation:
Transparency
enforcing
Effective:
Jul 14, 2026
Risk tier:
limited-risk
Scope:
Operators — persons who develop and make an AI companion available to the public; a mobile application store or search engine that merely provides access is not by itself an operator (§ (i)). An AI companion is a system using artificial intelligence, generative AI, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship by retaining information on prior interactions and user preferences, asking unprompted emotion-based questions beyond a direct response, and sustaining ongoing dialogue on matters personal to the user (§ (i)). The minor cadence in § (b) applies where the operator has actual knowledge or reasonable certainty that the user is under eighteen
high-impact
The codified section number is not on the face of the act — Sec. 3 adds "a new section to part I" of ch. 481B "to be appropriately designated", so provisions are cited by the subsection letters (a) to (i) that do appear in the enacted text until the revisor publishes the number. Hawaii is the only 2026 state companion-AI statute already in force; Washington, California, Oregon and Nebraska all run from 2027. The minor cadence is the strictest in the cohort: at least once per hour, and the reminder must also tell the user to take a break from the chat, where Washington and Nebraska stop at a three-hour general interval. A persistent visible disclaimer under § (b)(1) is an accepted alternative to the whole session-start-plus-hourly cadence, which no other state in the cohort allows. The general disclosure in § (a) keeps a reasonable-person trigger, unlike Washington's unconditional duty.

Requirements

RequirementDetails
General artificiality notificationWhere a reasonable person interacting with the AI companion would be led to believe the person is interacting with a human, issue a clear and conspicuous notification indicating that the AI companion is artificial intelligence and not human (§ (a))
Minor disclosureWhere the operator has actual knowledge or reasonable certainty that a user is a minor, clearly and conspicuously disclose that the user is interacting with artificial intelligence (§ (b))
Persistent disclaimer alternativeThe minor disclosure may be satisfied by a persistent visible disclaimer (§ (b)(1))
Session-start and hourly cadenceOtherwise the disclosure must appear both at the beginning of each session and at least once per hour in a continuous AI companion interaction, and the hourly reminder must tell the user to take a break from the chat and that the conversation is artificially generated and not with a human (§ (b)(2)(A)-(B))

Penalties

ViolationFine
Unfair or deceptive act or practiceAny violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount
EnforcementEnforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority
Private right of actionNone. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))
Model developer shieldThe section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))
Cumulative dutiesThe duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))

Suicide, Self-Harm and Crisis Intervention Protocol #

Obligation:
Risk Assessment
enforcing
Effective:
Jul 14, 2026
Risk tier:
limited-risk
Scope:
All operators of AI companions, with no minor-status or knowledge trigger — § (c) applies to every covered operator regardless of the user's age. Crisis intervention means communication intended to provide immediate support or assistance in response to a user seeking help for, referencing, or expressing self-harm, suicidal ideation, or suicide (§ (i)); serious bodily injury takes its meaning from Haw. Rev. Stat. § 707-700
high-impactcross-domain
Two duties here have almost no analogue in the cohort. § (c)(2) requires evidence-based methods for measuring suicidal ideation and the risk of self-harm — a methodological standard rather than a "reasonable measures" standard, which only Oregon and Colorado otherwise impose. § (c)(5) reaches outward: reasonable measures must prevent outputs encouraging the user to cause serious bodily injury to another person, and no other state statute in this cohort covers harm to third parties at all. § (c)(3) also bars the companion from representing that it is designed to provide professional mental or behavioral health care, which pulls the section into scope-of-practice territory alongside consumer protection.

Requirements

RequirementDetails
Crisis response protocolAdopt a protocol for the AI companion to respond to user prompts regarding suicidal ideation or self-harm that includes making reasonable efforts to provide a response referring the user to crisis intervention service providers, such as a suicide hotline, crisis text line, or other appropriate crisis services (§ (c)(1))
Evidence-based measurementUse evidence-based methods for measuring suicidal ideation and the risk of self-harm (§ (c)(2))
No professional care claimsDo not cause or program the AI companion to make any representation or statement indicating that it is designed to provide professional mental or behavioral health care (§ (c)(3))
No human-claiming during crisisInstitute reasonable measures to prevent the AI companion from making any representation or statement that would lead a reasonable person to believe they are interacting with a human where the user is seeking or receiving crisis intervention services for self-harm or suicide (§ (c)(4))
No outputs encouraging harm to othersInstitute reasonable measures to prevent the AI companion from generating outputs that encourage the user to cause serious bodily injury to another person (§ (c)(5))

Penalties

ViolationFine
Unfair or deceptive act or practiceAny violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount
EnforcementEnforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority
Private right of actionNone. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))
Model developer shieldThe section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))
Cumulative dutiesThe duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))

Minor Engagement, Sexual Content and Parental Controls #

Obligation:
Human Oversight
enforcing
Effective:
Jul 14, 2026
Risk tier:
limited-risk
Scope:
Operators that know or have reasonable certainty that a user is a minor — any person under eighteen years of age (§ (d), § (i)). Sexually explicit conduct takes its meaning from 18 U.S.C. § 2256; sexually objectify means to make sexual comments directed at the user's body or appearance (§ (i))
high-impactcross-domain
The trigger is actual knowledge or reasonable certainty, not an age-estimation duty — the legislature's findings in Sec. 2 expressly say regulation should "proactively avoid the mandatory collection of data by technology companies such as identity documentation for age verification purposes", so Hawaii deliberately declines the Colorado-style duty to estimate age. § (d)(1) targets variable-ratio reward schedules by name (points or similar rewards at unpredictable intervals intended to encourage increased engagement), which is a narrower and more mechanism-specific engagement ban than Washington's eight-technique list. § (d)(4) is the cohort's parental-tools duty: screen-time and account-settings controls must be available to the user and to parents and guardians alike.

Requirements

RequirementDetails
No unpredictable-interval rewardsDo not provide the user with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the AI companion (§ (d)(1))
No disengagement-discouraging outputsDo not allow the AI companion to generate outputs that discourage disengagement with the AI companion (§ (d)(2))
Sexual content preventionInstitute reasonable measures to prevent the AI companion from producing visual material of sexually explicit conduct, generating direct statements that the user should engage in sexually explicit conduct, or generating statements that sexually objectify the user (§ (d)(3)(A)-(C))
Screen-time and account toolsMake tools available for users and their parents and guardians to manage the user's screen time and account settings (§ (d)(4))

Penalties

ViolationFine
Unfair or deceptive act or practiceAny violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount
EnforcementEnforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority
Private right of actionNone. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))
Model developer shieldThe section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))
Cumulative dutiesThe duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))

Annual Behavioral Health Reporting #

Obligation:
Incident Reporting
pending
Effective:
Jan 1, 2028
Risk tier:
limited-risk
Scope:
All operators of AI companions, with no minor-status or knowledge trigger. The report goes to the behavioral health administration of the Department of Health and must contain only the three listed items, with no identifiers or personal information about users (§ (e))
cross-domain
This is a filing to a health regulator, not a consumer-protection disclosure — Washington and Oregon make the crisis-referral count a public self-disclosure with no recipient agency, while Hawaii routes it to the behavioral health administration of the Department of Health, which is where the state's own suicide-prevention programming sits. The data-minimisation proviso is a hard cap rather than a floor: the report "shall include only the information listed in this subsection" and no user identifiers or personal information, so an operator cannot pad the filing with supporting detail. The duty is the one part of the act not in force on approval; it begins with the first report on 2028-01-01, covering the preceding calendar year.

Requirements

RequirementDetails
Annual reportBeginning January 1, 2028, submit an annual report to the behavioral health administration of the Department of Health (§ (e))
Referral countReport the number of times the operator has issued a crisis intervention services provider referral in the preceding calendar year (§ (e)(1))
Detection and response protocolsReport the protocols put in place to detect, remove, and respond to user prompts regarding suicidal ideation or self-harm (§ (e)(2))
Prohibition protocolsReport the protocols put in place to prohibit an AI companion response promoting suicidal ideation or actions or self-harm (§ (e)(3))
Data minimisationThe report must include only the information listed in the subsection and must not include any identifiers or personal information about users (§ (e))

Penalties

ViolationFine
Unfair or deceptive act or practiceAny violation of the section is an unfair or deceptive act or practice in the conduct of trade or commerce within the meaning of Haw. Rev. Stat. § 480-2 (§ (f)). The act itself sets no penalty amount
EnforcementEnforced by the Office of Consumer Protection under the state's unfair and deceptive acts and practices authority
Private right of actionNone. Nothing in the section may be interpreted as creating a private right of action to enforce it, or as supporting a private right of action under any other law (§ (f))
Model developer shieldThe section creates no liability for the developer of an artificial intelligence model for a violation by an AI system developed by a third party to provide an AI companion (§ (g))
Cumulative dutiesThe duties, remedies and obligations imposed are cumulative to those imposed under other law and do not relieve an operator of any other duty (§ (h))
Cite this regulation

Permalink: https://everyailaw.com/regulation/hawaii-sb3001/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Hawaii Artificial Intelligence Disclosure and Safety Act (SB 3001)”, EveryAILaw.com, Aug 3, 2026. https://everyailaw.com/regulation/hawaii-sb3001/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.