Iowa Conversational AI Services Act (SF 2417)

Jurisdiction:
Iowa
enacted
Effective:
Jul 1, 2026
Full enforcement:
Jul 1, 2027
Authority:
Iowa Attorney General
Official text

Obligations Covered

Transparency & Disclosure Risk Assessment Data Governance

Timeline

MilestoneDateNotes
Passed SenateFeb 24, 202648-0
Passed HouseApr 15, 202695-0, substituted for HF 2507
Signed by GovernorMay 2, 20262026 Iowa Acts ch. 1068
EffectiveJul 1, 2026Standard Iowa effective date; no urgency clause. New Iowa Code ch. 554J enters the statute book, but no operator duty is yet applicable
ApplicabilityJul 1, 2027Sec. 7: "This Act applies July 1, 2027." The date every duty in §§ 554J.2-554J.5 begins to bite

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Conversational AI Artificiality Disclosure #

Obligation:
Transparency
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators — persons who develop and make a conversational AI service available to the public (§ 554J.1(4)); a conversational AI service is publicly accessible software whose primary purpose is simulating human conversation and interaction through text, audio, or visual communication, excluding R&D tools, features inside a program with a different primary purpose, narrow-and-discrete-topic systems, customer-service and commerce assistants sold to businesses, speaker/voice-assistant interfaces, and systems used solely for internal business purposes (§ 554J.1(2)); app stores and search engines are not operators merely for providing access (§ 554J.1(4))
high-impactupcoming
Two disclosure regimes sit side by side. The general one in § 554J.3 fires only on a reasonable-individual mistaken-for-human test, so a service that visibly presents as a bot may owe nothing. The minor-account-holder one in § 554J.2(1) has no such trigger: if the operator knows or is reasonably certain the account holder is under 18, the disclaimer is owed unconditionally. Both routes accept a persistent visible disclaimer, which is the cheap compliance path and is likely what most operators will build.

Requirements

RequirementDetails
Minor disclaimer, persistent optionClearly and conspicuously disclose to a minor account holder that they are interacting with artificial intelligence, by way of a persistent visible disclaimer (§ 554J.2(1)(a))
Minor disclaimer, interval optionAlternatively, provide both a disclaimer at the beginning of each interaction between the service and the minor account holder and a disclaimer at least once every three hours of continuous interaction (§ 554J.2(1)(b))
General consumer disclosureWhere a reasonable individual interacting with the service would believe they are interacting with a human, clearly and conspicuously disclose that the service is artificial intelligence, using either a persistent visible disclaimer or a disclaimer appearing after every three hours of continuous interaction (§ 554J.3)

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))

Anti-Anthropomorphism and Emotional Dependency Measures #

Obligation:
Transparency
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services (§ 554J.1(4)); the duty sits in § 554J.2, headed "minors — requirements", and two of its four enumerated examples are framed around a minor account holder, but the operative test is what a reasonable individual would believe
high-impactupcoming
This is the provision with no California analogue. SB 243 regulates the disclosure; Iowa regulates the persona. Barring statements that "simulate emotional dependence" or "simulate a romantic interaction" reaches model behaviour rather than interface copy, which means the compliance artifact is a system prompt, a fine-tune, or an output classifier — not a banner. It is drafted as a reasonable-measures standard, so the question at enforcement will be what the operator did to prevent the output, not whether the output ever occurred.

Requirements

RequirementDetails
Reasonable measures against human-impersonation outputInstitute reasonable measures to prevent the service from generating statements that would lead a reasonable individual to believe they are interacting with a human (§ 554J.2(4))
Sentience and humanity claimsIncluded in the bar: explicit claims that the service is sentient or human (§ 554J.2(4)(a))
Simulated emotional dependenceIncluded in the bar: statements that simulate emotional dependence on a minor account holder (§ 554J.2(4)(b))
Romantic or sexual framingIncluded in the bar: statements that simulate a romantic interaction or a sexual innuendo (§ 554J.2(4)(c))
Adult-minor romantic role-playIncluded in the bar: role-playing an adult-minor romantic relationship (§ 554J.2(4)(d))

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))

Minor Engagement and Sexual Content Safeguards #

Obligation:
Risk Assessment
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services, as to minor users and minor account holders — a minor being an individual the operator knows is, or is reasonably certain is, under eighteen years of age (§ 554J.1(3)); "sexually explicit conduct" and "visual depiction" take their 18 U.S.C. § 2256 meanings (§§ 554J.1(5)-(6))
high-impactupcoming
The variable-reward bar in § 554J.2(2) is the first US AI statute to regulate an engagement mechanic rather than an output. It borrows the language of intermittent reinforcement — "points or similar rewards at unpredictable intervals" — and is gated on intent to encourage increased engagement, which makes internal growth documents the natural evidence. Note the drafting asymmetry: § 554J.2(2) reaches a "minor user" while § 554J.2(3) reaches a "minor account holder", so the reward bar plausibly applies without an account.

Requirements

RequirementDetails
No variable-reward engagement mechanicsDo not provide a minor user with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the service (§ 554J.2(2))
Reasonable measures against sexual depictionsInstitute reasonable measures to prevent the service from producing visual depictions of sexually explicit material for minor account holders (§ 554J.2(3)(a))
Reasonable measures against solicitationInstitute reasonable measures to prevent the service from stating that a minor account holder should engage in sexually explicit conduct (§ 554J.2(3)(b))
Reasonable measures against objectificationInstitute reasonable measures to prevent the service from sexually objectifying a minor account holder (§ 554J.2(3)(c))

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))

Minor Privacy and Parental Control Tools #

Obligation:
Data Governance
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services with minor account holders; the guardian-facing duty is unconditional for account holders under thirteen years of age and risk-calibrated for older minors (§ 554J.2(5)(b)-(c))
upcoming
The statute requires the tools to exist but says nothing about what they must control, so the compliance floor is a settings surface rather than a defined set of parental permissions. The § 554J.2(5)(c) "as appropriate based on relevant risks" formulation is the only risk-proportionate duty in the chapter and is left entirely to the Attorney General's chapter 17A rulemaking to give content.

Requirements

RequirementDetails
Minor self-service controlsOffer tools for minor account holders to manage their own privacy and account settings (§ 554J.2(5)(a))
Guardian controls under 13Offer tools for the parent or guardian of a minor account holder under thirteen years of age to manage the minor's privacy and account settings (§ 554J.2(5)(b))
Risk-calibrated guardian controlsOffer tools for the parent or guardian of a minor account holder to manage the minor's privacy and account settings as appropriate based on relevant risks (§ 554J.2(5)(c))

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))

Suicide and Self-Harm Response Protocol #

Obligation:
Risk Assessment
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services; the duty runs to all users, not only minors (§ 554J.4)
high-impactupcomingcross-domain
Compare California SB 243 § 22602(b), which makes the protocol a precondition on operating at all and requires publication on the operator's website. Iowa requires only that the protocol be adopted: no gate, no publication, no annual reporting to a public-health body. The floor is lower, and there is no plaintiff-facing document — the Attorney General would have to ask for the protocol to see it.

Requirements

RequirementDetails
Adopt a protocolAdopt protocols for the conversational AI service for responding to user prompts regarding suicidal ideation or self-harm (§ 554J.4)
Crisis referralThe protocol must include making reasonable efforts to refer the user to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis service (§ 554J.4)

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))

Licensed Mental Health Service Representation Bar #

Obligation:
Transparency
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services; the reference point is professional psychology or behavioral health services that would require licensure under Iowa Code chapter 154B (psychologists) or 154D (behavioral science practitioners) (§ 554J.5)
cross-domainupcoming
The scienter standard is the highest in the chapter — "knowingly and intentionally cause or program" — so an emergent therapeutic persona the operator did not design is outside this section, though it may still be caught by the reasonable-measures duty in § 554J.2(4). The bar is on representation, not on function: a service may in fact behave therapeutically as long as it does not lead a reasonable individual to believe it is a licensed practice.

Requirements

RequirementDetails
No licensed-practice representationDo not knowingly and intentionally cause or program a conversational AI service to make a representation that would lead a reasonable individual to believe the service is designed to provide professional psychology or behavioral health services requiring licensure under Iowa Code chapter 154B or 154D (§ 554J.5)
Runtime statements coveredThe bar reaches a "representation or statement", so programmed in-conversation output implying licensed psychology or behavioral health practice is covered, not only marketing or product description (§ 554J.5)

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))
Model developer carve-outA developer of an AI model is not liable solely because a third party used the model to create or train a conversational AI service (§ 554J.6(5))
Cite this regulation

Permalink: https://everyailaw.com/regulation/iowa-sf2417/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Iowa Conversational AI Services Act (SF 2417)”, EveryAILaw.com, Aug 2, 2026. https://everyailaw.com/regulation/iowa-sf2417/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.