AI Regulations Tracker
Every AI and algorithmic decision-making regulation XIRA tracks, organized by state. Updated as new laws are signed.
All regulations by state
Filter by category, status, and state search to find what matters now.
Category
Status
Arkansas(3 tracked)
- Arkansas AI-Generated Child Exploitation (HB 1877)
Criminal prohibition on creating, possessing, or distributing AI-generated imagery indistinguishable from real minors...
ARAI-SpecificHigh riskIn EffectCriminal penaltiesEffective - Arkansas Nonconsensual Synthetic Intimate Content (HB 1529)
Criminal penalties for distributing synthetic intimate content without consent, including AI-generated deepfakes. Eff...
ARAI-SpecificMedium riskIn EffectCriminal penaltiesEffective - Arkansas Generative AI Content Ownership Act (HB 1876, Act 927)
First-of-its-kind AI content ownership law. Establishes default rules: prompt/data providers own resulting content if...
ARAI-SpecificMedium riskIn EffectSee penalty termsEffective
California(21 tracked)
- CCPA/CPRA Automated Decision-Making Technology Regulations
Regulations are effective January 1, 2026. ADMT consumer opt-out and access rights compliance is required by April 1,...
CAPrivacy ADMHigh riskIn Effect$2,500/consumerEffective - California Transparency in Frontier AI Act (SB 53)
Requires developers of frontier AI models trained above the statutory compute threshold (10^26 FLOPs) to publish safe...
CAAI-SpecificHigh riskIn Effect$1,000,000/violationEffective - California AI-Generated Child Sexual Abuse Material (AB 1831)
Expands child pornography laws to include content digitally altered or generated by AI. Criminal prohibition.
CAAI-SpecificHigh riskIn EffectCriminal penaltiesEffective - California AI Transparency Act (SB 942)
Requires provenance and detection measures for certain generative AI content. As amended by AB 853 (signed October 13...
CAAI-SpecificHigh riskEffective August 2, 2026$5,000/dayEffective - California Companion Chatbots Act (SB 243)
Applies to AI chatbots capable of meeting a user's social needs. Requirements include AI disclosure, break reminders...
CAAI-SpecificHigh riskIn Effect$1,000/violation PRAEffective - California Deepfake Pornography Expansion (AB 621)
Expands civil remedies for non-consensual deepfake pornography. Broadens definitions, adds liability for deepfake por...
CAAI-SpecificHigh riskIn Effect$250,000 penalties PRAEffective - California Algorithmic Pricing Act (AB 325)
Prohibits use of common pricing algorithms as part of anticompetitive agreements. Covers any methodology including so...
CAAI-SpecificHigh riskIn Effect$1,000,000 penalties PRAEffective - California AI Training Data Transparency Act (AB 2013)
Requires developers of generative AI systems or services available to Californians to publish high-level documentatio...
CAAI-SpecificMedium riskIn EffectNo standalone penalties PRAEffective - California Healthcare AI Deceptive Terms Act (AB 489)
AB 3030 (2024) requires healthcare providers to disclose generative AI use to patients and in records. AB 489 (2025)...
CAAI-SpecificMedium riskIn EffectCriminal penaltiesEffective - California Digital Replicas of Deceased Performers Act (AB 1836)
Restricts commercial uses of realistic AI-generated replicas of deceased performers' voices or likenesses in audiovis...
CAAI-SpecificMedium riskIn Effect$10,000 penalties PRAEffective - California Non-Consensual Deepfake Pornography (SB 926)
Criminalizes creation and distribution of realistic deepfake intimate images without consent, if the creator or distr...
CAAI-SpecificMedium riskIn EffectCriminal penalties PRAEffective - California Healthcare Provider Generative AI Disclosure (AB 3030)
Requires healthcare providers to disclose when generative AI is used in patient interactions and to document that use...
CAAI-SpecificMedium riskIn EffectSee penalty termsEffective - California AI Defenses in Litigation (AB 316)
Prohibits defendants in civil actions from asserting that AI acted autonomously as a defense for harm caused through...
CAAI-SpecificMedium riskIn EffectSee penalty termsEffective - California Social Media Deepfake Reporting (SB 981)
Requires social media platforms to provide a mechanism for users to report sexually explicit digital identity theft i...
CAAI-SpecificMedium riskIn EffectSee penalty termsEffective - California Digital Replica Contract Protections (AB 2602)
Makes contract terms unenforceable when they allow digital replicas of a performer without the performer giving speci...
CAAI-SpecificMedium riskIn EffectSee penalty terms PRAEffective - California Insurance AI Disclosures (SB 1120)
Requires AI disclosure in insurance sector contexts. Sector-specific regulation for insurers using AI in underwriting...
CASector-SpecificMedium riskIn EffectSee penalty termsEffective - California AI Robocall Disclosure (AB 2905)
Requires robocalls to disclose when the recording uses a voice generated or significantly altered by generative AI.
CAAI-SpecificLow riskIn EffectSee penalty termsEffective - California Political Ad AI Disclaimer (AB 2355)
Requires disclaimers on AI-generated political advertisements created by political committees. Unlike AB 2839 (struck...
CAAI-SpecificLow riskIn EffectSee penalty termsEffective - California Government AI Accountability Act (SB 896)
Requires California state agencies to disclose use of generative AI in communications with individuals about governme...
CAAI-SpecificLow riskIn EffectSee penalty termsEffective - California AI Definition Act (AB 2885)
Standardizes the legal definition of artificial intelligence across all California law. Defines AI as an engineered o...
CAAI-SpecificLow riskIn EffectSee penalty termsEffective - CAAI-SpecificNone riskStruck DownNot enforceableEffective
Colorado(2 tracked)
- Colorado AI Act (SB 24-205)
Requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from algorithmi...
COAI-SpecificHigh riskEffective June 30, 2026$20,000/violationEffective - Colorado Privacy Act (CPA profiling and ADM)
Colorado profiling rules define three tiers: Solely Automated Processing, Human Reviewed Automated Processing, and Hu...
COPrivacy ADMHigh riskIn Effect$20,000/violationEffective
Connecticut(3 tracked)
- Connecticut Public Act 25-113 (SB 1295) CTDPA and profiling amendments
Major CTDPA overhaul signed June 25, 2025. Removes solely from automated decision scope: after July 1, 2026, covered...
CTPrivacy ADMHigh riskEffective July 1, 2026$5,000 penaltiesEffective - Connecticut Data Privacy Act (CTDPA profiling)
Connecticut consumers may opt out of profiling in furtherance of solely automated decisions that produce legal or sim...
CTPrivacy ADMMedium riskIn Effect$5,000 penaltiesEffective - Connecticut Government AI Procurement and Oversight (SB 1103)
First-in-nation state government AI procurement law. Requires state agencies to inventory AI systems, conduct impact...
CTAI-SpecificLow riskIn EffectNo standalone penaltiesEffective
Delaware(1 tracked)
- Delaware Personal Data Privacy Act - Profiling Provisions
Grants Delaware consumers the right to opt out of profiling for decisions with legal or significant effects. Opt-out...
DEPrivacy ADMMedium riskIn Effect$10,000/violationEffective
Illinois(8 tracked)
- Illinois Biometric Information Privacy Act (BIPA)
Requires informed written consent before collecting biometric data including facial geometry, fingerprints, and voice...
ILAI-SpecificHigh riskIn Effect$1,000 penalties PRAEffective - Illinois AI-Generated Child Sexual Abuse Material (HB 4623)
Clarifies that Illinois child pornography laws encompass AI-generated images of minors in sexual acts. AI-generated C...
ILAI-SpecificHigh riskIn EffectCriminal penaltiesEffective - Illinois Human Rights Act (HB 3773 AI amendment)
Makes discriminatory use of AI in employment a civil rights violation under the IHRA. Prohibits AI that has the effec...
ILAI-SpecificMedium riskIn EffectSee penalty termsEffective - Illinois Right of Publicity Act, Digital Replica Amendment (HB 4875)
Prohibits unauthorized AI-generated digital replicas of individual voices, images, and likenesses. Holds liable anyon...
ILAI-SpecificMedium riskIn EffectSee penalty terms PRAEffective - Illinois HB 1806 / WOPRA - AI in Mental Health Therapy
Restricts AI use in mental health therapy contexts under Illinois WOPRA and related professional standards. Targets A...
ILAI-SpecificMedium riskIn EffectSee penalty termsEffective - Illinois Digital Forgeries Act (HB 2123)
Extends nonconsensual intimate image protections to AI-generated deepfakes. Provides civil remedies including statuto...
ILAI-SpecificMedium riskIn EffectSee penalty terms PRAEffective - Illinois AI Video Interview Act (820 ILCS 42)
Requires employers using AI to analyze video interviews to notify candidates, explain how AI is used, and obtain cons...
ILAI-SpecificMedium riskIn EffectNo standalone penaltiesEffective - Illinois Digital Voice and Likeness Protection Act (HB 4762)
Protects individual digital voice and likeness in contracts. Contract provisions for digital replica use are unenforc...
ILAI-SpecificMedium riskIn EffectSee penalty terms PRAEffective
Indiana(2 tracked)
- Indiana Consumer Data Protection Act - Profiling Provisions
Grants Indiana consumers the right to opt out of profiling for decisions with legal or significant effects. Applies t...
INPrivacy ADMMedium riskIn Effect$7,500/violationEffective - Indiana Election Deepfake Disclosure (HB 1133)
Requires disclosure when AI-generated synthetic media is used in political campaign communications in Indiana.
INAI-SpecificLow riskIn EffectSee penalty termsEffective
Iowa(2 tracked)
- Iowa AI-Generated Child Exploitation (SF 2243)
Treats AI-generated depictions of child exploitation equivalently to real CSAM under Iowa criminal code.
IAAI-SpecificHigh riskIn EffectCriminal penaltiesEffective - Iowa Nonconsensual Synthetic Intimate Content (HF 2240)
Criminal penalties for distributing nonconsensual synthetic intimate content including AI-generated deepfakes.
IAAI-SpecificMedium riskIn EffectCriminal penaltiesEffective
Kentucky(1 tracked)
- Kentucky Consumer Data Protection Act - Profiling Provisions
Grants Kentucky consumers the right to opt out of profiling for decisions producing legal or significant effects. Vir...
KYPrivacy ADMMedium riskIn Effect$7,500 penaltiesEffective
Maryland(5 tracked)
- Maryland Online Data Privacy Act (MODPA), ADM and profiling provisions
Statute effective October 1, 2025, but enforcement does not begin until April 1, 2026. The law does not apply to proc...
MDPrivacy ADMHigh riskIn Effect$10,000 penaltiesEffective - Maryland Healthcare AI Utilization Review (HB 820)
Requires AI tools used in healthcare coverage decisions to base determinations on individual patient data, not group...
MDSector-SpecificMedium riskIn EffectCriminal penaltiesEffective - Maryland Nonconsensual Pornography Deepfake Expansion (SB 360)
Expands Maryland's revenge porn statute to cover AI-generated and computer-generated sexual imagery. Strengthens civi...
MDAI-SpecificMedium riskIn Effect$5,000 penalties PRAEffective - Maryland HB 1202 (Facial Recognition in Hiring)
Prohibits creating facial templates of job applicants during interviews without signed consent. The waiver must inclu...
MDAI-SpecificLow riskIn EffectNo standalone penaltiesEffective - Maryland AI Governance Act of 2024 (SB 818)
Requires Maryland state agencies to inventory AI systems, conduct impact assessments, and follow DoIT policies for AI...
MDAI-SpecificLow riskIn EffectSee penalty termsEffective
Minnesota(2 tracked)
- Minnesota Consumer Data Privacy Act - ADM and profiling provisions
Minnesota is the first state privacy law to require controllers to create and maintain a data inventory. The right to...
MNPrivacy ADMHigh riskIn Effect$7,500 penaltiesEffective - Minnesota Election and NCII Deepfake Law (HF 1370)
Criminalizes election deepfakes within 90 days before elections (no disclosure exception, one of the strictest in the...
MNAI-SpecificMedium riskIn EffectCriminal penalties PRAEffective
Montana(2 tracked)
- Montana Consumer Data Privacy Act - Profiling Provisions
Grants Montana consumers the right to opt out of profiling for decisions with legal or significant effects. 2025 amen...
MTPrivacy ADMMedium riskIn EffectSee penalty termsEffective - Montana Right to Compute Act (SB 212)
Requires deployers of critical infrastructure facilities controlled by AI to develop a risk management policy based o...
MTAI-SpecificMedium riskIn EffectSee penalty termsEffective
Nebraska(1 tracked)
- Nebraska Data Privacy Act - ADM and profiling provisions
Nebraska requires consumer opt-out rights and risk assessments for qualifying profiling and automated decisions with...
NEPrivacy ADMMedium riskIn Effect$7,500/violationEffective
New Hampshire(1 tracked)
- New Hampshire Privacy Act - Profiling Provisions
Grants New Hampshire consumers the right to opt out of profiling for decisions with legal or significant effects.
NHPrivacy ADMMedium riskIn Effect$10,000/violationEffective
New Jersey(2 tracked)
- New Jersey Data Privacy Act (Profiling Provisions)
Uniquely covers nonprofits with no revenue threshold. Universal opt-out mechanism (UOOM) requirement effective July 1...
NJPrivacy ADMMedium riskIn Effect$10,000 penaltiesEffective - New Jersey Deepfake Penalties (S2544)
Establishes civil and criminal penalties for creating and distributing deepfakes, including AI-manipulated images and...
NJAI-SpecificMedium riskIn EffectCriminal penalties PRAEffective
New York(6 tracked)
- New York Responsible AI Safety and Education Act (RAISE Act, S6953B/A6453B)
Requires developers of frontier AI models operating in New York to implement safety protocols, conduct impact assessm...
NYAI-SpecificHigh riskEffective January 1, 2027$1,000,000 penaltiesEffective - New York AI Companion Models Law (A3008, Article 47)
Requires AI companion operators to disclose AI nature, provide reminders every 3 hours of use, and implement protocol...
NYAI-SpecificHigh riskIn Effect$15,000/dayEffective - New York Personalized Algorithmic Pricing Disclosure (S 3008, 2025)
Requires businesses to disclose when personalized pricing is set by an algorithm using personal data so consumers kno...
NYAI-SpecificMedium riskIn Effect$1,000/violationEffective - New York Deceased Performer Digital Replicas (SB 8391)
Amends the Right of Publicity law to protect digital replicas of deceased performers. Provides civil remedies for una...
NYAI-SpecificMedium riskIn EffectSee penalty terms PRAEffective - New York Digital Replica Contract Protections (S7676B)
Establishes protections for individuals regarding the use of digital replicas in professional contracts. Requires spe...
NYAI-SpecificMedium riskIn EffectSee penalty terms PRAEffective - New York Synthetic Performers Disclosure (SB 8420A)
Requires conspicuous disclosure in advertisements when AI-generated synthetic performers are used. A synthetic perfor...
NYAI-SpecificLow riskEnacted, effective June 9, 2026$1,000 penaltiesEffective
New York City(1 tracked)
- NYC Local Law 144 (Automated Employment Decision Tools)
Requires employers using automated employment decision tools in NYC to conduct annual independent bias audits and not...
NYCAI-SpecificHigh riskIn Effect$500/dayEffective
Oregon(3 tracked)
- Oregon Consumer Privacy Act - Profiling Provisions
Grants Oregon consumers the right to opt out of profiling for decisions with legal or significant effects. Opt-out li...
ORPrivacy ADMMedium riskIn Effect$7,500/violationEffective - Oregon Synthetic Intimate Imagery (HB 2299)
Criminal penalties for creating or distributing AI-generated nonconsensual intimate imagery in Oregon. Expands intima...
ORAI-SpecificMedium riskIn EffectCriminal penaltiesEffective - Oregon Election Deepfake Disclosure (SB 1571)
Requires disclosure statement on political communications containing synthetic media in Oregon elections.
ORAI-SpecificLow riskIn EffectSee penalty termsEffective
Rhode Island(1 tracked)
- Rhode Island Data Transparency and Privacy Protection Act - ADM provisions
Rhode Island's privacy framework includes consumer rights tied to profiling and automated decisions, including opt-ou...
RIPrivacy ADMHigh riskIn Effect$10,000 penalties PRAEffective
Tennessee(2 tracked)
- Tennessee ELVIS Act (Ensuring Likeness, Voice, and Image Security)
First enacted US legislation specifically designed to protect musicians from unauthorized AI voice synthesis. Covers...
TNAI-SpecificHigh riskIn EffectCriminal penalties PRAEffective - Tennessee Information Protection Act - Profiling Provisions
Grants Tennessee consumers the right to opt out of profiling for decisions with legal or significant effects. First s...
TNPrivacy ADMMedium riskIn Effect$7,500/violationEffective
Texas(6 tracked)
- Texas TRAIGA Biometric and AI Training Amendments (HB 149, 89th Legislature)
Amends the Texas Capture or Use of Biometric Identifier Act (CUBI) and related Business and Commerce Code provisions...
TXAI-SpecificHigh riskIn Effect$10,000/dayEffective - Texas Nonconsensual Intimate Deepfakes (SB 441)
Criminalizes creating and distributing nonconsensual intimate deepfakes. Creates civil liability for victims. Platfor...
TXAI-SpecificMedium riskIn Effect$4,000 penalties PRAEffective - Texas TRAIGA (Responsible Artificial Intelligence Governance Act, HB 149)
Intent-based liability only: prohibits intentional AI discrimination, behavioral manipulation, and CSAM generation, w...
TXAI-SpecificMedium riskIn Effect$10,000/dayEffective - Texas Data Privacy and Security Act, Profiling Provisions (HB 4)
Texas comprehensive privacy law with profiling provisions. Requires data protection assessments for profiling that pr...
TXPrivacy ADMMedium riskIn Effect$7,500/violationEffective - Texas SB 1188 - Healthcare AI Practitioner Disclosure
Requires healthcare providers using AI-enabled clinical support features in electronic health record workflows to dis...
TXAI-SpecificMedium riskIn EffectSee penalty termsEffective - Texas Government AI Ethics and Oversight (SB 1964)
Requires Texas state agencies and local governments to inventory AI systems, adopt an AI code of ethics aligned with...
TXAI-SpecificLow riskIn EffectNo standalone penaltiesEffective
Utah(5 tracked)
- Utah AI Mental Health Chatbot Regulation (HB 452)
Regulates AI-powered mental health chatbots. Requires clear disclosure that the service is not a human clinician, lim...
UTAI-SpecificMedium riskIn Effect$2,500/violationEffective - Utah Artificial Intelligence Policy Act (SB 149)
SB 332 extended the act's sunset from May 7, 2025 to July 1, 2027. SB 226 NARROWED disclosure requirements (not added...
UTAI-SpecificMedium riskIn Effect$2,500/violationEffective - Utah AI Policy Act Amendments (SB 226 / SB 332)
SB 226 narrowed UAIPA disclosure: general consumer contexts require disclosure only on a clear and unambiguous reques...
UTAI-SpecificMedium riskIn Effect$2,500/violationEffective - Utah Unauthorized AI Impersonation (SB 271)
Expands Utah's abuse of personal identity law to cover AI-generated deepfakes and digital replicas used for commercia...
UTAI-SpecificMedium riskIn EffectSee penalty terms PRAEffective - Utah Consumer Privacy Act, Profiling Provisions (SB 227)
Utah's comprehensive privacy law. It is the least restrictive state privacy law regarding profiling and ADM among com...
UTPrivacy ADMLow riskIn Effect$7,500/violationEffective
Virginia(2 tracked)
- Virginia Consumer Data Protection Act (VCDPA, Profiling Provisions)
Grants Virginia consumers the right to opt out of profiling in furtherance of decisions that produce legal or signifi...
VAPrivacy ADMMedium riskIn Effect$7,500/violationEffective - Virginia Nonconsensual Pornography (Deepfake Coverage)
Virginia's nonconsensual pornography statute criminalizes dissemination of intimate images created by any means whats...
VAAI-SpecificMedium riskIn Effect$2,500 penalties PRAEffective
Washington(7 tracked)
- Washington SB 5395 (AI in Health Insurance Prior Authorization)
Enacted as Chapter 157, Laws of 2026; Governor signed March 23, 2026; effective June 11, 2026. AI tools may be used t...
WAAI-SpecificHigh riskEffective June 11, 2026See penalty termsEffective - Washington My Health My Data Act
Broad health data privacy law covering health data collected outside HIPAA, including data from health-related AI too...
WAPrivacy ADMHigh riskIn Effect$7,500/violation PRAEffective - Washington AI Chatbot Safety for Minors (HB 2225)
First-in-nation law requiring AI chatbot operators to disclose AI nature at regular intervals (every 3 hours for adul...
WAAI-SpecificMedium riskEnacted, effective January 1, 2027See penalty terms PRAEffective - Washington AI Content Disclosure Act (HB 1170)
AI content provenance and watermarking requirements for providers with 1 million or more monthly Washington users. Re...
WAAI-SpecificMedium riskEffective January 1, 2028See penalty termsEffective - Washington Fabricated Intimate Images (2024)
Criminalizes creation and distribution of AI-generated intimate images without consent. Provides civil remedies for v...
WAAI-SpecificMedium riskIn EffectCriminal penalties PRAEffective - Washington Election Deepfake Disclosure (SB 6280)
Requires clear and conspicuous disclosure when AI-generated or AI-manipulated media is used in political advertising...
WAAI-SpecificMedium riskIn EffectSee penalty termsEffective - Washington Forged Digital Likenesses (HB 2459)
Extends Washington's existing forgery and identity theft statutes to cover AI-generated digital likenesses used for f...
WAAI-SpecificMedium riskIn EffectCriminal penaltiesEffective
Federal(10 tracked)
- EEOC Guidance on AI in Employment Selection
NON-BINDING TECHNICAL ASSISTANCE applying existing Title VII law to AI use cases. Not voted on or approved by the ful...
EEOCFederalHigh riskIn EffectSee penalty termsEffective - FTC Enforcement Policy on AI and Algorithmic Fairness
COMPOSITE ENFORCEMENT POSTURE, not a single regulation. The FTC applies existing laws (FTC Act Section 5, COPPA, ECOA...
FTCFederalHigh riskIn Effect$50,120/violationEffective - TAKE IT DOWN Act (S. 146)
Requires covered online platforms to remove reported nonconsensual intimate imagery, including AI-generated deepfakes...
FederalFederalHigh riskIn Effect$53,088/violationEffective - DOJ AI Litigation Task Force
Coordinates federal civil litigation strategy on AI-related matters across the Department of Justice. Executive order...
DOJFederalMedium riskIn EffectSee penalty termsEffective - FDA AI/ML Medical Device Framework
FDA requires pre-market review (510(k), De Novo, PMA) for AI/ML-based software that meets the definition of a medical...
FDAFederal guidanceMedium riskIn EffectSee penalty termsEffective - HUD AI Guidance in Housing
Fair Housing Act disparate impact standard applies to AI-driven tenant screening, lending algorithms, and property va...
HUDFederal guidanceMedium riskIn EffectSee penalty terms PRAEffective - NIST AI Risk Management Framework (AI RMF 1.0)
NIST AI RMF is a voluntary framework used as a practical benchmark by regulators and lawmakers. NIST released AI RMF...
NISTFrameworkMedium riskIn EffectSee penalty termsEffective - SEC AI Guidance in Financial Services
SEC enforces existing fiduciary duties and disclosure requirements as applied to AI. Pursuing AI washing enforcement...
SECFederal guidanceMedium riskIn EffectSee penalty termsEffective - Executive Order 14110 on AI (Revoked)
Established federal policy priorities for AI safety, security, and rights protections across agencies. Directed agenc...
Executive BranchFederalLow riskIn EffectSee penalty termsEffective - DOL AI in Workplace Guidance
Non-binding principles for AI in the workplace covering transparency, human oversight, informed consent, data protect...
DOLFederal guidanceLow riskIn EffectSee penalty termsEffective
Find which regulations apply to you.
Start your free scanFree. No account required.
Get monthly regulatory updates