Data tool
Which AI rules apply to me?
Pick where you work or sell and what you use AI for. You get the AI rules that apply, what they ask you to do and from when, with a link to the official text.
Your checklist
Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.
96 rules in our list. Pick a place and a use to narrow it down.
In force now 70
- In force since February 2, 2025
Do not use AI to read emotions at work or school
AI systems that infer people’s emotions are banned in workplaces and in schools and universities, except for medical or safety reasons.
- Who
- Anyone who provides or uses such AI in the EU, including employers and schools.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(f)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since August 2, 2026
Tell people when they are talking to an AI
If you provide an AI system that talks directly with people, design it so they are told they are interacting with AI, unless that is obvious.
- Who
- Providers of AI systems used in the EU.
- Enforced by
- National authorities, or the EU AI Office for chatbots built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 50(1)
Official text AI Act, Article 50 (EU AI Act Service Desk) - In force since August 2, 2026
Mark AI-generated content so machines can detect it
Providers of AI that generates audio, images, video or text must mark the output in a machine-readable way as AI-made. Systems already on the market before August 2, 2026 have until December 2, 2026. Tools that only assist standard editing are exempt.
- Who
- Providers of generative AI systems in the EU, including general-purpose AI.
- Enforced by
- National authorities, or the EU AI Office for generative AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 50(2)
Official text AI Act implementation timeline (European Commission) - In force since August 2, 2026
Label deepfakes and AI-written news-style text
If you use AI to create or alter a deepfake image, audio or video, disclose that it is AI-made or manipulated; for obvious art, satire or fiction a light disclosure is enough. If you use AI to write or alter text published to inform the public on matters of public interest, disclose it, unless it went through human review or editorial control and someone holds editorial responsibility.
- Who
- Businesses and organisations that use AI to make such content in the EU; purely personal, non-professional use is exempt.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 50(4)
Official text AI Act, Article 50 (EU AI Act Service Desk) - In force since February 2, 2025
Help your staff understand the AI they use
Take steps to support the AI literacy of staff and others who operate or use AI for you, suited to their knowledge and to how the AI is used. Since July 27, 2026 you no longer have to guarantee a particular skill level.
- Who
- Providers and deployers of AI systems in the EU, which includes any business using AI at work.
- Enforced by
- National authorities; the AI Act sets no EU-wide fine for this duty, so penalties come from national law.
- Law
- AI Act, Article 4, as replaced by Regulation (EU) 2026/1744
Official text AI Omnibus enters into force (European Commission) - In force since February 2, 2025
Do not build AI that manipulates or exploits people
AI that uses subliminal, manipulative or deceptive techniques, or exploits people’s age, disability or social or economic situation, to distort their decisions in a way that causes or is likely to cause significant harm is banned.
- Who
- Anyone who provides or uses such AI in the EU.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(a) and (b)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not use AI social scores to treat people unfairly
AI that scores people over time on their social behaviour or personal traits is banned when the score leads to unjustified or disproportionate harm, or to harm in a context unrelated to where the data came from. Ordinary performance reviews are usually not social scoring.
- Who
- Anyone who provides or uses such AI in the EU, including private companies.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(c)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not scrape faces from the web to build face recognition
AI that creates or expands facial recognition databases by untargeted scraping of face images from the internet or CCTV footage is banned.
- Who
- Anyone who provides or uses such AI in the EU.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(e)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not use AI to predict crime from profiling alone
AI that assesses or predicts the risk that a person will commit a crime based solely on profiling, or on their personality traits, is banned. AI that supports a human assessment already based on objective, verifiable facts is allowed.
- Who
- Anyone who provides or uses such AI in the EU, including private companies.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(d)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not use biometrics to guess race, religion or union ties
AI that sorts individual people by biometric data, such as face or voice, to infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation is banned.
- Who
- Anyone who provides or uses such AI in the EU, including employers.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(g)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since August 2, 2026
Tell people when you use emotion or biometric AI on them
If you use AI that recognises emotions or sorts people into categories from biometric data, inform the people exposed to it and handle their data under the GDPR. Emotion recognition at work or school is banned anyway, except for medical or safety reasons.
- Who
- Businesses and organisations that use such systems in the EU.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 50(3)
Official text AI Act, Article 50 (EU AI Act Service Desk) - In force since August 2, 2025
Document your AI model and publish a training-data summary
If you put a general-purpose AI model on the EU market, keep technical documentation and give developers who build on it the information they need. Follow EU copyright law, including publishers’ opt-outs from text and data mining, and publish a summary of the training content. Models on the market before August 2, 2025 have until August 2, 2027.
- Who
- Providers of general-purpose AI models offered in the EU, wherever they are based; providers outside the EU need an EU representative. Open-source models skip the documentation duties unless they pose systemic risk, but must still follow copyright law and publish the summary.
- Enforced by
- European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
- Law
- AI Act, Articles 53, 54 and 111(3); text and data mining opt-outs under the Copyright Directive (EU) 2019/790, Article 4(3)
Official text AI Act overview (European Commission) - In force since August 2, 2025
Test and report risks of the most powerful AI models
A general-purpose model is presumed to have systemic risk if it was trained with more than 10²⁵ operations, and the Commission can also designate one. If yours has it, notify the Commission, evaluate and adversarially test the model, and assess and reduce its risks. Report serious incidents to the AI Office and keep strong cybersecurity.
- Who
- Providers of general-purpose AI models with systemic risk offered in the EU.
- Enforced by
- European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
- Law
- AI Act, Articles 51, 52 and 55
Official text AI Act overview (European Commission) - In force since May 25, 2018
Do not let AI alone make big decisions about people
People have the right not to be subject to decisions made solely by automated processing, including profiling, with legal or similarly significant effects, such as automatically rejecting a job application. Such decisions are allowed only when needed for a contract, authorised by law or with explicit consent, and then people get human intervention, a way to contest and meaningful information about the logic.
- Who
- Any organisation processing personal data in the EU, or of people in the EU, including employers and schools.
- Enforced by
- National data protection authorities; fines up to €20 million or 4% of worldwide turnover, whichever is higher.
- Law
- GDPR (Regulation (EU) 2016/679), Article 22, with Articles 13 to 15
Official text GDPR, Regulation (EU) 2016/679 (EUR-Lex) - In force since August 2, 2026
Explain decisions made with high-risk AI when asked
Some AI counts as high-risk, such as AI for hiring, managing staff, education, credit or essential services. If a decision based on it seriously affects someone, they can ask you to explain the AI’s role and the main reasons for the decision, and you must answer clearly. The AI Act’s other duties for this AI start on December 2, 2027.
- Who
- Businesses and organisations in the EU that use such AI to decide about people. It applies where other EU law, such as the GDPR, does not already give this right.
- Enforced by
- National authorities; the AI Act sets no EU-wide fine for this right, so penalties come from national law (in Germany, up to €50,000).
- Law
- AI Act, Article 86, with Annex III
Official text AI Act, Article 86 (EU AI Act Service Desk) - In force since February 17, 2024
Explain how your platform’s recommendations work
If your online platform recommends content, explain in your terms, in plain language, the main factors your recommender systems use and how users can change them. Very large platforms and search engines must also offer at least one feed option not based on profiling.
- Who
- Online platforms serving people in the EU, except micro and small companies; the extra option applies to services with more than 45 million monthly users in the EU.
- Enforced by
- National Digital Services Coordinators, or the European Commission for very large platforms; fines up to 6% of worldwide turnover.
- Law
- Digital Services Act (Regulation (EU) 2022/2065), Articles 27 and 38
Official text Digital Services Act (European Commission) - In force since August 2, 2026
Explain high-risk AI decisions, or Germany can fine you
Germany backs the EU right to an explanation with its own fine. If a decision based on high-risk AI, for example in hiring, staff management, education or credit, seriously affects someone and they ask, explain the AI’s role and the main reasons. Failing to do so can cost up to €50,000. The EU has moved most other high-risk duties to December 2, 2027.
- Who
- Businesses and other private organisations using high-risk AI in Germany, such as employers, private schools and lenders. Public bodies cannot be fined.
- Enforced by
- Federal Network Agency (Bundesnetzagentur) in most cases, BaFin for finance and state authorities for the media; fines up to €50,000.
- Law
- KI-MIG (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz), sections 15(2), 15(3) and 17, with AI Act Article 86
Official text KI-MIG (Gesetze im Internet) - In force since June 18, 2021
Tell the works council early about planned AI
If your workplace has a works council (Betriebsrat), inform it in good time, with the documents it needs, when you plan work processes that use AI. Discuss the effects on staff early enough that its suggestions can still change the plan.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- Labour courts; fines up to €10,000 for information that is missing, wrong, incomplete or late (section 121). Obstructing the works council is a crime (section 119).
- Law
- Works Constitution Act (Betriebsverfassungsgesetz), section 90(1) no. 3 and (2), as amended in 2021
Official text Works Constitution Act, section 90 (Gesetze im Internet) - In force since June 18, 2021
Let the works council bring in an AI expert
When your works council has to assess the introduction or use of AI, the law treats calling in an outside expert as necessary, so you cannot refuse on the ground that one is not needed. You still agree on the details, and you can agree on a standing AI expert.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- Labour courts. Obstructing the works council is a crime (section 119).
- Law
- Works Constitution Act, section 80(3), as amended in 2021
Official text Works Constitution Act, section 80 (Gesetze im Internet) - In force since June 18, 2021
Get works council consent for AI-made selection rules
General rules for choosing whom to hire, transfer, regrade or dismiss need your works council’s consent, also when AI is used to draw them up. In businesses with more than 500 employees, the works council can demand such rules. If you cannot agree, a conciliation board decides.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- A conciliation board (Einigungsstelle) settles disputes, and labour courts enforce.
- Law
- Works Constitution Act, section 95(1), (2) and (2a), as amended in 2021
Official text Works Constitution Act, section 95 (Gesetze im Internet) - In force since January 19, 1972
Agree with the works council before AI that tracks staff
You need your works council’s agreement before you introduce or use technical systems designed to monitor how employees behave or perform, which includes AI tools that log or analyse staff activity. If you cannot agree, a conciliation board decides.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- A conciliation board settles disputes, and labour courts can stop a system introduced without agreement. Obstructing the works council is a crime (section 119).
- Law
- Works Constitution Act, section 87(1) no. 6 and (2)
Official text Works Constitution Act, section 87 (Gesetze im Internet) - In force since November 7, 2020
Label automated bot posts on social networks
If you run a social media account that looks like a person but posts automatically through software, clearly mark each automated post as sent by a program. Social networks must also take care that such posts are labelled.
- Who
- Anyone offering content on social networks in Germany, such as businesses, publishers and campaigns, and the networks themselves.
- Enforced by
- State media authorities (Landesmedienanstalten); fines up to €500,000 for unlabelled bot posts.
- Law
- Interstate Media Treaty (Medienstaatsvertrag), sections 18(3) and 93(4)
Official text Interstate Media Treaty (REVOSax, Saxony’s official law portal) - In force since November 7, 2020
Explain how your algorithm picks and ranks content
If you run a search engine, social network, news aggregator or similar service, publish in plain language the main criteria for selecting and ranking content and how your algorithms work, easy to find and always available.
- Who
- Services that gather and present others’ content (media intermediaries) and reach at least 1 million users a month in Germany. Services focused on goods and services are exempt.
- Enforced by
- State media authorities; fines up to €500,000.
- Law
- Interstate Media Treaty, sections 91 and 93(1)
Official text Interstate Media Treaty (REVOSax, Saxony’s official law portal) - In force since June 11, 2023
Label AI faces or bodies in paid posts “Images virtuelles”
If you are paid to promote something online and your post includes an AI-made image of a face or body, add the words “Images virtuelles”, clear and easy to read on every format. Retouched faces or bodies need “Images retouchées” instead.
- Who
- Commercial influencers: people or companies paid to promote goods, services or causes online to a French audience, including those based abroad.
- Enforced by
- Criminal courts; up to one year in prison and a €4,500 fine.
- Law
- Law no. 2023-451 of June 9, 2023 on commercial influence, article 5, as amended in 2024
Official text Law no. 2023-451 (Légifrance) - In force since May 23, 2024
Get consent or clearly label AI fakes of real people
Do not publish or share AI-made images, video or audio that reproduce a real person’s image or words without their consent, unless it is obvious, or clearly stated, that the content was made by AI.
- Who
- Anyone in France, including businesses, publishers and influencers.
- Enforced by
- Criminal courts; up to one year in prison and €15,000, or two years and €45,000 if shared online.
- Law
- Criminal Code (Code pénal), article 226-8, as amended by Law no. 2024-449 of May 21, 2024 (SREN)
Official text Criminal Code, articles 226-8 and 226-8-1 (Légifrance) - In force since May 23, 2024
Never share sexual deepfakes of a person without consent
Sharing AI-made sexual images, video or audio that reproduce a real person’s image or voice without their consent is a crime, even if it is labelled as fake.
- Who
- Anyone in France.
- Enforced by
- Criminal courts; up to two years in prison and €60,000, or three years and €75,000 if shared online.
- Law
- Criminal Code, article 226-8-1, added by Law no. 2024-449 of May 21, 2024 (SREN)
Official text Criminal Code, articles 226-8 and 226-8-1 (Légifrance) - In force since January 1, 2018
Consult the works council before rolling out AI at work
Inform and consult your works council (CSE) before introducing new technologies such as AI tools, and on changes that affect staff numbers, organisation or working conditions.
- Who
- Employers in France with at least 50 employees and a works council (comité social et économique).
- Enforced by
- Obstructing the works council is a crime, with a fine of up to €7,500 (article L2317-1).
- Law
- Labour Code (Code du travail), article L2312-8
Official text Labour Code, article L2312-8 (Code du travail numérique) - In force since January 1, 2018
Tell the works council before AI hiring or tracking tools
Inform your works council before you use recruitment-assistance methods or automated staff-management systems, and before changing them. Inform and consult it before deciding to deploy any tool that can monitor employees’ activity.
- Who
- Employers in France with at least 50 employees and a works council.
- Enforced by
- Obstructing the works council is a crime, with a fine of up to €7,500 (article L2317-1).
- Law
- Labour Code, article L2312-38
Official text Labour Code, article L2312-38 (Code du travail numérique) - In force since May 1, 2008
Tell job candidates before using AI to assess them
Before using any recruitment method or technique on candidates, including AI tools, tell them which ones you will use. Methods must be relevant to the job, results stay confidential, and no data may be collected through a tool they were not told about.
- Who
- All employers and recruiters in France, of any size.
- Enforced by
- These articles set no penalty of their own.
- Law
- Labour Code, articles L1221-8 and L1221-9
Official text Labour Code, article L1221-8 (Code du travail numérique) - In force since May 1, 2008
Tell staff before any AI tool collects data about them
No information about an individual employee may be collected by a device or tool they were not told about beforehand, including AI monitoring and analytics tools.
- Who
- All employers in France.
- Enforced by
- This article sets no penalty of its own.
- Law
- Labour Code, article L1222-4
Official text Labour Code, article L1222-4 (Code du travail numérique) - In force since June 1, 2019
Explain your automated decision rules when asked
A decision with legal or similarly significant effects on someone may rest solely on automated processing only in the GDPR’s contract and explicit-consent cases. Then, if the person asks, you must tell them the rules that define the processing and its main characteristics, except secrets protected by law.
- Who
- Any organisation in France that takes solely automated decisions about people. Public bodies have stricter duties.
- Enforced by
- The data protection authority (CNIL); fines up to €20 million or 4% of worldwide turnover, whichever is higher.
- Law
- Data Protection Act (Loi Informatique et Libertés, law no. 78-17), article 47
Official text Data Protection Act, article 47 (CNIL) - In force since November 16, 2013
Never make or share fake recordings to smear someone
It is a crime in Hungary to make, or make available to others, a false or altered audio or image recording of someone in order to damage their honour. This covers AI deepfakes and cloned voices.
- Who
- Anyone in Hungary; a case starts only if the victim asks for it.
- Enforced by
- Police, prosecutors and criminal courts; up to one year in prison for making such a recording, two years for making it available, or three years if it reaches a large audience or causes significant harm.
- Law
- Criminal Code (2012. évi C. törvény), sections 226/A and 226/B
Official text Criminal Code (Nemzeti Jogszabálytár) - In force since May 19, 2026
Remove reported intimate deepfakes within 48 hours
Give people a clear, plain-language way to report intimate images of themselves posted without consent, including AI-made fakes. Remove a valid reported image within 48 hours, and make reasonable efforts to remove known identical copies.
- Who
- Public websites, apps and online services that mainly host content from users, with no size threshold. Broadband providers and email are excluded.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per violation. Removals made in good faith are protected.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 3
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since May 19, 2025
Never post AI-made intimate images of real people
It is a federal crime to knowingly publish online an intimate image of an identifiable real person without their consent, including realistic fakes made with AI.
- Who
- Anyone, people and businesses alike.
- Enforced by
- Department of Justice; fines and up to two years in prison, or three years if the person shown is a minor.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 2, 47 U.S.C. 223(h)
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since October 21, 2024
Do not post or buy fake reviews, including AI-written ones
Do not write, create, sell or buy reviews or testimonials that falsely suggest the reviewer exists, used the product or had the experience described. The FTC says this covers AI-generated fake reviews.
- Who
- Businesses selling to US consumers.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per knowing violation.
- Law
- FTC Rule on the Use of Consumer Reviews and Testimonials, 16 CFR part 465
Official text 16 CFR part 465 (eCFR) - In force since February 8, 2024
Get consent before calling people with an AI voice
Calls that use AI-generated or cloned voices count as artificial-voice calls under the federal robocall law, so they need the called person’s prior express consent, unless it is an emergency or an exemption applies. The message must also identify the caller.
- Who
- Anyone placing calls to people in the US.
- Enforced by
- Federal Communications Commission, state attorneys general and private lawsuits; $500 per call, or up to $1,500 if willful.
- Law
- FCC Declaratory Ruling FCC 24-17, applying the Telephone Consumer Protection Act, 47 U.S.C. 227(b)
Official text FCC Declaratory Ruling 24-17 (Federal Communications Commission) - In force since April 22, 2026
Get parents’ separate consent to train AI on kids’ data
If your site, app or service is aimed at children under 13, or you know you collect their data, get a parent’s separate, verifiable consent before disclosing a child’s personal information to third parties. The FTC says disclosing it to train or develop AI needs this consent.
- Who
- Operators of websites, apps and online services, including education technology, aimed at children under 13 or knowingly collecting their data.
- Enforced by
- Federal Trade Commission and state attorneys general; civil penalties of up to $53,088 per violation.
- Law
- Children’s Online Privacy Protection Rule, 16 CFR 312.5(a)(2), as amended in 2025
Official text COPPA Rule amendments (Federal Trade Commission) - In force since August 2, 2026
Embed hidden AI labels and offer a free checking tool
If you make a generative AI system that people in California can use, add hidden provenance data to the images, video and audio it creates or alters, where technically feasible. Also offer a free disclosure verification tool, your own or a compliant third-party one. Since September 30, 2026 this applies however many users you have; AI built mainly as assistive technology is exempt until 2029.
- Who
- Makers of generative AI systems publicly available in California.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation. Falsely claiming the assistive-technology exemption costs $50,000 per violation.
- Law
- California AI Transparency Act, Business and Professions Code sections 22757 to 22757.6 (SB 942, Chapter 291, Statutes of 2024; amended by AB 853, Chapter 674, Statutes of 2025, and SB 1000, Chapter 861, Statutes of 2026)
Official text SB 1000 (California Legislature) - In force since January 1, 2026
Companion chatbots must disclose AI and handle crises
Tell users the chatbot is AI, not human, if they could be misled; keep and publish a suicide and self-harm protocol that refers users to crisis services; and warn that companion chatbots may not suit some minors. Until December 31, 2026, also remind known minors every three hours that it is AI and to take a break, and block sexual content for them. Yearly reports start July 1, 2027.
- Who
- Operators of companion chatbot platforms available in California.
- Enforced by
- People harmed can sue for the greater of their damages or $1,000 per violation.
- Law
- SB 243 (Chapter 677, Statutes of 2025), Business and Professions Code sections 22601 to 22606; amended by SB 1119 (Chapter 190, Statutes of 2026) from January 1, 2027
Official text SB 243 (California Legislature) - In force since July 1, 2019
Do not let a bot pretend to be human to sell or sway votes
If you use a bot online to push a sale or influence a vote in California, it must clearly disclose that it is a bot.
- Who
- Anyone using bots to talk with people in California online.
- Enforced by
- This section names no penalty or enforcer.
- Law
- Business and Professions Code sections 17940 to 17943 (SB 1001, Chapter 892, Statutes of 2018)
Official text Business and Professions Code 17941 (California Legislature) - In force since January 1, 2026
Publish frontier AI safety plans and report incidents
If you train frontier AI models, publish a transparency report when you deploy a new or substantially changed one. Report critical safety incidents to the state’s Office of Emergency Services within 15 days, or within 24 hours to the right authority if lives are at risk. Developers with over $500 million in yearly revenue must also publish and follow a frontier AI framework and run an anonymous internal reporting channel.
- Who
- Frontier developers: anyone who has trained a model using more than 10²⁶ operations. None may gag or punish staff who report catastrophic risks.
- Enforced by
- Attorney General; civil penalties of up to $1 million per violation, scaled to its severity.
- Law
- Transparency in Frontier Artificial Intelligence Act, SB 53 (Chapter 138, Statutes of 2025), Business and Professions Code sections 22757.10 to 22757.16 and Labor Code sections 1107 to 1107.2
Official text SB 53 (California Legislature) - In force since January 1, 2025
Spell out digital replica uses in performer contracts
A contract term can let a digital replica of a person’s voice or likeness replace work they would have done in person. Such a term is unenforceable if it lacks a reasonably specific description of the uses and the person had no lawyer or union negotiating for them.
- Who
- Anyone contracting with a person in California for personal or professional services, such as actors, voice artists and creators. It covers new performances fixed from January 1, 2025.
- Enforced by
- No regulator or fine; such a term cannot be enforced.
- Law
- AB 2602 (Chapter 259, Statutes of 2024), Labor Code section 927
Official text AB 2602 (California Legislature) - In force since January 1, 2026
Post a summary of the data used to train your AI
Before each public release of a generative AI system, or a substantial change to it, post documentation on your website about its training data. It must include a high-level summary of the datasets: their sources or owners, whether they include copyrighted or personal information, and whether they were bought or licensed.
- Who
- Developers of generative AI systems or services released since January 1, 2022 and publicly available to Californians, including anyone who substantially modifies one. AI used only for security, aircraft operation or national security is exempt.
- Enforced by
- The law names no penalty or enforcer. A federal court refused to block it in March 2026; xAI’s appeal is set for argument on November 18, 2026.
- Law
- AB 2013 (Chapter 817, Statutes of 2024), Civil Code sections 3110 and 3111, amended by AB 1170 (Chapter 67, Statutes of 2025)
Official text Civil Code section 3111 (California Legislature) - In force since January 1, 2026
Do not make or help spread sexual deepfakes
Do not create or share sexually explicit deepfakes of a real person when you know, or should know, that they did not consent or were a minor, and do not knowingly help others do it. A service mainly for making sexual deepfakes is presumed to know there was no consent. Companies that keep such a service running are presumed liable if they do not stop within 30 days of notice.
- Who
- Anyone, including people and businesses that run or serve deepfake services.
- Enforced by
- The person shown can sue for profits, actual damages or $1,500 to $50,000 per work, up to $250,000 with malice, plus punitive damages and fees. Public prosecutors can seek $25,000 per violation, or $50,000 with malice.
- Law
- AB 621 (Chapter 673, Statutes of 2025), Civil Code section 1708.86
Official text AB 621 (California Legislature) - In force since January 1, 2025
Let users report sexual deepfakes and act within 30 days
Let California account holders report sexually explicit images or videos of themselves that were made or altered digitally without their consent. Confirm each report within 48 hours, update within 7 days, block the material while you check, and decide within 30 days, or 60 days if the delay is beyond your control. Remove it at once if the report holds up.
- Who
- Social media platforms with users in California; end-to-end encrypted messaging services and charities are excluded.
- Enforced by
- The law names no penalty or enforcer.
- Law
- SB 981 (Chapter 292, Statutes of 2024), Business and Professions Code sections 22670 and 22671
Official text SB 981 (California Legislature) - In force since January 1, 2025
Say when a robocall uses an artificial voice
Before an automatic dialing device plays a prerecorded message, a live, natural voice must state the nature of the call and the caller’s name, address and phone number. It must ask whether the person consents to hear the message, and say if the message uses an artificial voice, such as an AI-generated one.
- Who
- Anyone placing calls with automatic dialing-announcing devices to people in California.
- Enforced by
- California Public Utilities Commission; fines of up to $500 per violation, or disconnection of the line.
- Law
- AB 2905 (Chapter 316, Statutes of 2024), Public Utilities Code section 2874
Official text AB 2905 (California Legislature) - In force since January 1, 2025
Get estate consent for AI replicas of dead celebrities
Do not use a digital replica of a deceased personality’s voice or likeness in a film, video or sound recording without consent from whoever holds their rights. News, sports, criticism, satire, parody, documentaries, biographies and fleeting uses are excepted.
- Who
- Studios, labels, advertisers, AI companies and anyone else using such a replica in California.
- Enforced by
- No regulator; the rights holders can sue for $10,000 or their actual damages, whichever is greater.
- Law
- AB 1836 (Chapter 258, Statutes of 2024), Civil Code section 3344.1
Official text AB 1836 (California Legislature) - In force since October 1, 2025
Do not let AI tools discriminate; keep their data 4 years
Using an automated decision system that discriminates against job applicants or workers is unlawful, even when a vendor runs it for you. Keep the system’s data with your employment records for four years. Evidence of anti-bias testing can count for or against you.
- Who
- Employers covered by California’s Fair Employment and Housing Act, usually those with 5 or more employees, plus employment agencies and unions.
- Enforced by
- Civil Rights Department complaints and lawsuits under the Fair Employment and Housing Act; damages rather than a fixed fine.
- Law
- Civil Rights Council regulations, California Code of Regulations title 2, sections 11008.1, 11009(f) and 11013(c)
Official text Automated-decision systems regulations (California Civil Rights Department) - In force since January 1, 2026
Do a risk assessment before using AI to judge people
Do and document a privacy risk assessment, and review it at least every three years, before you use automated decision-making for significant decisions such as jobs, loans, housing, education or health care. The same applies to automated tools that infer workers’, students’ or applicants’ performance, health, behaviour or location from systematic observation, and to training such tools or face recognition on personal data. Uses that began before 2026 need one by December 31, 2027.
- Who
- Businesses covered by the California Consumer Privacy Act.
- Enforced by
- California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
- Law
- CCPA regulations, California Code of Regulations title 11, sections 7150, 7155 and 7157
Official text CCPA regulations (California Privacy Protection Agency) - In force since July 1, 2023
Let people opt out of profiling for big decisions
Let people opt out of profiling that feeds decisions with legal or similarly significant effects, such as on loans, housing, insurance, education or health care. If a human is meaningfully involved you may refuse, but you must then explain the decision, the data used and the logic in plain language. Assess the risks in writing before such profiling.
- Who
- Businesses serving Colorado residents that handle the data of more than 100,000 of them a year, or of 25,000 or more while earning money or discounts from selling personal data.
- Enforced by
- Attorney General and district attorneys.
- Law
- Colorado Privacy Act, C.R.S. 6-1-1306(1)(a) and 6-1-1309, with the Attorney General’s rules (4 CCR 904-3, rule 9.04)
Official text Colorado Privacy Act (Colorado Attorney General) - In force since October 1, 2026
Say whether AI played a part in mass layoffs
When you file a federal mass-layoff (WARN) notice, also tell the Connecticut Labor Department whether the layoffs are related to your use of AI or another technological change.
- Who
- Employers that must file a federal WARN notice, usually those with 100 or more workers.
- Enforced by
- Connecticut Labor Department, in the form the Labor Commissioner sets. The act sets no penalty.
- Law
- Public Act 26-15, section 26
- In force since October 1, 2026
An AI tool is no excuse for discrimination
If an automated tool helps make a job decision, its use is no defence against a discrimination complaint. Evidence of anti-bias testing can be taken into account.
- Who
- Employers in Connecticut.
- Enforced by
- Commission on Human Rights and Opportunities and the courts.
- Law
- Public Act 26-15, sections 13 and 14 (amending C.G.S. 46a-60(b)(1) and 46a-81c)
- In force since October 1, 2026
Do not punish staff who warn about catastrophic AI risks
Do not adopt or enforce any policy or contract that lets you punish staff for reporting a specific and substantial danger from catastrophic AI risk, or for whistleblowing to authorities, and tell your risk staff their rights. Developers with over $500 million in yearly revenue need an anonymous internal reporting channel by January 1, 2027.
- Who
- Frontier AI developers doing business in Connecticut: those training models with more than 10²⁶ operations.
- Enforced by
- Attorney General; civil penalty of up to $1,000 per violation.
- Law
- Public Act 26-15, section 2
- In force since October 1, 2026
Spell out the terms before charging for an AI subscription
Before you start or renew an AI subscription, give the customer a written notice of the key terms, including usage limits and any right to cut features, and get their written acceptance.
- Who
- Anyone selling AI subscriptions to Connecticut residents.
- Enforced by
- Attorney General, as an unfair trade practice; customers cannot sue under this section.
- Law
- Public Act 26-15, section 1
- In force since October 1, 2026
Add provenance data to AI images, audio and video
Where commercially and technically reasonable, embed provenance data in images, audio and video your AI creates or materially alters, and make it hard to remove, for example with the C2PA standard.
- Who
- Makers of generative AI systems for images, audio or video that the public can use for personal purposes and that have more than one million users a month. Business-to-business tools, games, and pure upscaling or compression tools are excluded.
- Enforced by
- Attorney General, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-15, section 15
- In force since October 1, 2026
Label prices raised by algorithms using personal data
If an automated process uses a customer’s personal data to set a price shown online, and the price is not a discount, show the notice “THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA”. Retailers and delivery apps may not set personal prices from tracking data at all, except for cost differences, supply and demand, and open discount or loyalty schemes.
- Who
- Businesses selling to people in Connecticut, for the label; retailers and delivery apps, for the ban. Insurers, banks and other financial institutions are excluded.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-64, section 11
Official text Public Act 26-64 (Connecticut General Assembly) - In force since October 1, 2026
Remove intimate deepfakes in 48 hours, or face state fines
Set up a written process, explained in a plain-language notice on your platform, for victims or the Attorney General to report synthetic intimate images. Remove a valid report within 48 hours and make reasonable efforts to remove copies.
- Who
- Public websites and apps that mainly host content shared by users, as defined in the federal TAKE IT DOWN Act.
- Enforced by
- Attorney General, in court; civil penalties of up to $25,000 a day for each person harmed.
- Law
- Public Act 26-55, section 2
Official text Public Act 26-55 (Connecticut General Assembly) - In force since July 1, 2026
Let people challenge automated profiling decisions
Let people opt out of profiling used for automated decisions with legal or similarly significant effects. If you made such a decision, where feasible let them question the result, tell them the reason and let them review their data; for housing decisions, let them correct the data and get the decision re-evaluated. Do an impact assessment for such profiling.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Connecticut Data Privacy Act, C.G.S. 42-518 and 42-522, as amended by Public Act 25-113 (impact assessments for processing from August 1, 2026)
Official text Public Act 25-113 (Connecticut General Assembly) - In force since July 1, 2026
Say in your privacy notice if you train AI on personal data
Your privacy notice must state whether you collect, use or sell personal data to train large language models.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Connecticut Data Privacy Act, C.G.S. 42-520, as amended by Public Act 25-113
Official text Public Act 25-113 (Connecticut General Assembly) - In force since October 1, 2026
Post signs if you use face recognition on your premises
If you use face recognition on your premises against security threats, fraud or crime, match faces only against your own database. Post clearly legible signs at each public entrance saying it is in use, with a link or QR code to your face recognition policy, which must give the Attorney General’s contact details.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-64, section 16 (C.G.S. 42-524)
Official text Public Act 26-64 (Connecticut General Assembly) - In force since January 1, 2026
Do not let AI discriminate at work, and say you use it
Do not use AI in recruiting, hiring, promotion, training, discipline, firing or other job decisions in a way that leads to discrimination against protected groups, even if unintended. Do not use ZIP codes as a stand-in for them, and tell employees when you use AI for these decisions.
- Who
- Employers with at least one employee in Illinois on each working day of 20 or more weeks this year or last. Draft rules on the notice were withdrawn in June 2026, so its exact form is not yet set.
- Enforced by
- Illinois Department of Human Rights: a worker or applicant can file a charge within 2 years, and the case then goes to the Human Rights Commission or a court. Remedies include damages, hiring or reinstatement, back pay and legal fees.
- Law
- Illinois Human Rights Act, 775 ILCS 5/2-102(L), added by Public Act 103-0804 (HB 3773)
Official text Labor Day Report 2026, page 17 (Illinois Attorney General) - In force since January 1, 2020
Get consent before AI analyses video job interviews
Before AI analyses an applicant’s recorded video interview, tell them AI may be used and get their consent. If you rely only on AI to decide who gets an in-person interview, report the race and ethnicity of the people interviewed and hired to the state every year.
- Who
- Employers that use AI to analyse video interviews for jobs based in Illinois.
- Enforced by
- The Department of Commerce and Economic Opportunity collects the yearly reports; the official summaries name no fine.
- Law
- Artificial Intelligence Video Interview Act, 820 ILCS 42 (HB 2557 of 2019; yearly reports added by HB 53 of 2021, from January 1, 2022)
Official text Governor’s bill actions, August 9, 2019 (State of Illinois) - In force since January 1, 2025
Get consent before using a person’s AI digital replica
Do not create or distribute a digital replica, an AI-made version of a person’s voice, image or likeness that could pass as authentic, without their consent. Illinois’s right-of-publicity law now covers such replicas.
- Who
- Anyone creating or distributing such replicas in Illinois.
- Enforced by
- No regulator; the person can sue under the Right of Publicity Act.
- Law
- Right of Publicity Act (765 ILCS 1075), as amended by HB 4875 of 2024
Official text AI Task Force report, December 2024 (Illinois Department of Innovation and Technology) - In force since August 9, 2024
Describe AI replica uses clearly in performer contracts
A contract clause that allows a digital replica of a person’s voice or likeness is invalid if it does not clearly describe the intended uses and the person had no lawyer or union representing them.
- Who
- Anyone contracting with performers or other individuals in Illinois for their voice or likeness.
- Enforced by
- No regulator or fine; such a clause cannot be enforced.
- Law
- Digital Voice and Likeness Protection Act (HB 4762 of 2024)
Official text AI Task Force report, December 2024 (Illinois Department of Innovation and Technology) - In force since November 5, 2025
Add crisis help and “not human” notices to AI companions
If your chatbot acts as an ongoing AI companion, it must detect signs of suicidal thoughts or self-harm and refer users to crisis services such as the 988 line. It must also tell users clearly that they are not talking to a human, at the start of a conversation and at least every three hours while it continues.
- Who
- Businesses that offer AI companions to people in New York for personal use: AI that remembers past chats, asks unprompted emotional questions and keeps up personal conversations. Customer-service, productivity and research tools are excluded.
- Enforced by
- Attorney General; civil penalties of up to $15,000 a day, paid into a suicide prevention fund.
- Law
- General Business Law, article 47 (sections 1700 to 1704), added by Chapter 58 of 2025, Part U
Official text General Business Law, article 47 (New York State Senate) - In force since July 8, 2025
Label prices set by an algorithm using personal data
If an algorithm uses a customer’s personal data to set the price you offer them, show this notice clearly next to the price: “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA”.
- Who
- Businesses offering personalised algorithmic prices to New York consumers. Insurers, financial institutions under the federal Gramm-Leach-Bliley Act, and lower prices for existing subscriptions are excluded.
- Enforced by
- Attorney General, enforcing since November 10, 2025: a cease-and-desist letter first, then court fines of up to $1,000 per violation. A federal court upheld the law in October 2025, and an appeal is pending.
- Law
- Algorithmic Pricing Disclosure Act, General Business Law section 349-a (Chapter 58 of 2025, Part X)
Official text General Business Law section 349-a (New York State Senate) - In force since June 9, 2026
Disclose AI-generated performers in your ads
If you make an ad and know it includes a synthetic performer, a realistic human made with AI or other software who is not a real, recognisable person, say so clearly in the ad.
- Who
- Anyone who produces or creates commercial ads. Audio-only ads, ads for films, TV shows and video games, and AI used only to translate a real performer’s speech are excluded; outlets that only publish ads are exempt.
- Enforced by
- $1,000 for a first violation and $5,000 for each later one; the law does not name the enforcer.
- Law
- General Business Law section 396-b, as amended by Chapter 617 of 2025
Official text General Business Law section 396-b (New York State Senate) - In force since December 11, 2025
Get consent before using a dead performer’s AI replica
Before you use a digital replica, a realistic computer-made voice or likeness, of a deceased performer in an audiovisual work, a sound recording or a live musical performance, get consent from whoever holds their publicity rights, usually the heirs. A disclaimer is no longer enough.
- Who
- Anyone using a replica of a performer who lived in New York when they died, on or after May 29, 2021, such as studios, labels, advertisers and AI companies.
- Enforced by
- No regulator; the rights holders can sue for $2,000 or their damages, whichever is greater, plus the profits made from the use.
- Law
- Civil Rights Law section 50-f, as amended by Chapter 616 of 2025
Official text Civil Rights Law section 50-f (New York State Senate) - In force since January 1, 2025
Spell out digital replica terms in performer contracts
A contract clause can let you use a digital replica of a person’s voice or likeness instead of work they would have done in person. Such a clause is void if it does not describe the intended uses reasonably specifically, unless the person had a lawyer or a union contract covering such replicas.
- Who
- Any business contracting with a person for personal or professional services in New York, such as actors, voice artists and creators. It applies to contracts made or changed from January 1, 2025.
- Enforced by
- No regulator or fine; such a clause cannot be enforced.
- Law
- General Obligations Law section 5-302
Official text General Obligations Law section 5-302 (New York State Senate) - In force since July 5, 2023
Audit AI hiring tools for bias and tell candidates
Before you use an automated tool to screen job candidates or employees for promotion, have an independent bias audit done within the past year and post a summary of the results on your website. Tell candidates and employees who live in New York City at least 10 business days before use, including what the tool will assess and how to ask for an alternative process or accommodation.
- Who
- Employers and employment agencies using such tools for jobs in New York City.
- Enforced by
- Department of Consumer and Worker Protection; up to $500 for a first violation and $500 to $1,500 for each later one. Each day of non-compliant use counts as a separate violation.
- Law
- Local Law 144 of 2021 (Administrative Code 20-870 to 20-874)
Official text Automated employment decision tools (NYC Department of Consumer and Worker Protection)
Coming up 26
- Starts December 2, 2026
Do not offer or use AI that makes sexual deepfakes
AI systems that create or alter realistic sexual or intimate images, video or audio of an identifiable person without their explicit consent, or child sexual abuse material, are banned. Providers are covered when this is the intended purpose or a foreseeable result their safeguards do not reliably prevent; users are covered when they use AI for this.
- Who
- Anyone who provides or uses such AI systems in the EU.
- Enforced by
- National authorities, or the EU AI Office for AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(ba) and (bb) and 5(1a) to (1b), inserted by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Official text AI Act implementation timeline (European Commission) - Starts December 2, 2026
Platforms: keep humans in charge of algorithmic management
Gig-work platforms must explain their automated monitoring and decision systems to the people working through them, keep them under human oversight, and not use them to process data such as emotional state, private conversations or union activity. Only a human may decide to restrict, suspend or close a worker’s account. EU countries must put this into national law by December 2, 2026.
- Who
- Digital labour platforms, such as ride-hailing or delivery apps, organising work in the EU. The data and human-review rules also protect self-employed platform workers.
- Enforced by
- Under each country’s national law; data protection authorities can fine breaches of the data rules at GDPR levels.
- Law
- Platform Work Directive (EU) 2024/2831, Articles 7 to 15 (deadline for national laws)
Official text Platform Work Directive (EU) 2024/2831 (EUR-Lex) - Starts January 1, 2027
Say in layoff notices when AI caused the cuts
If a mass layoff, relocation or closure is caused wholly or substantially by AI or other automation, the 60-day notice must say so under the line “This notice is for a technology displacement”. It must give the number, job type and work location of those jobs, the tasks that will be automated and the kind of technology used.
- Who
- Employers with a California site that has employed 75 or more people in the past year.
- Enforced by
- Existing Cal/WARN remedies, as SB 951 adds no new penalty: workers not given notice are owed back pay and benefits for up to 60 days, and a missing notice to officials can cost up to $500 a day. Workers, unions and local governments can sue.
- Law
- SB 951 (Chapter 860, Statutes of 2026), Labor Code section 1401
Official text SB 951 (California Legislature) - Starts January 1, 2027
No surveillance tools in workplace bathrooms
Employers may not use surveillance tools to monitor workers in workplace bathrooms, except under a court order, and workers may leave such tools behind when they go in. Simple badges or alarms without audio, video or built-in AI are allowed.
- Who
- All California employers, public and private.
- Enforced by
- Labor Commissioner and public prosecutors; up to $500 per violation.
- Law
- AB 1331 (Chapter 851, Statutes of 2026), Labor Code sections 1560 to 1565
Official text AB 1331 (California Legislature) - Starts January 1, 2027
Do not use AI to read workers’ emotions or neural data
Employers may not use AI-powered workplace surveillance tools to recognise, infer or predict workers’ emotional state, or to collect neural data, meaning measurements of the nervous system. Tools used to keep people safe are not banned.
- Who
- All California employers, public and private.
- Enforced by
- Labor Commissioner, public prosecutors or the worker; up to $500 per violation.
- Law
- AB 1883 (Chapter 853, Statutes of 2026), Labor Code sections 1580 to 1583
Official text AB 1883 (California Legislature) - Starts January 1, 2027
Big platforms must show whether content is AI-made
Detect provenance data in content on your platform, clearly show whether it says the content was made or substantially altered by AI or captured by a camera or recorder, and let users inspect that data. Where technically feasible, do not knowingly strip it.
- Who
- Public-facing social media, file-sharing, mass-messaging and stand-alone search services with more than 2 million unique monthly users over the past 12 months. Broadband and telecom services are excluded.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation.
- Law
- Business and Professions Code section 22757.3.1, added by AB 853 (Chapter 674, Statutes of 2025) and amended by AB 2713 (Chapter 856, Statutes of 2026)
Official text AB 2713 (California Legislature) - Starts January 1, 2027
Do not knowingly host AI models that skip hidden labels
If your site or app offers generative AI model weights or source code for download, do not knowingly make available a system that does not add the hidden provenance data California requires.
- Who
- Generative AI hosting platforms, paid or free, that offer downloads to people in California.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation.
- Law
- Business and Professions Code section 22757.3.2 (AB 853, Chapter 674, Statutes of 2025)
Official text AB 853 (California Legislature) - Starts January 1, 2027
Assess, limit and audit companion chatbots for children
From January 1, 2027, check users’ ages or give everyone the child protections. From July 1, 2027, if children may use your companion chatbot, assess child risks before each release, publish a child safety policy and run a crisis protocol. Set parent-controlled limits such as one-hour sessions, block romance, sexual content and purchase pressure, and do not sell children’s data. Independent audits are due from 2029.
- Who
- Anyone who makes a companion chatbot available in California; most duties apply only if children under 18 may use it. Colleges offering it only for education, and employers offering it only to staff, are excluded.
- Enforced by
- Public prosecutors; up to $5,000 per affected child for each negligent violation and $15,000 for each intentional one. Harmed children or their parents can sue for damages.
- Law
- Adam’s Law, SB 1119 (Chapter 190, Statutes of 2026), Business and Professions Code sections 21810 to 21818
Official text SB 1119 (California Legislature) - Starts January 1, 2027
Do not make or sell toys with companion chatbots
Until January 1, 2031, do not make, sell, exchange or offer to retailers any toy that includes a companion chatbot. A toy here means a product made for play by children under 16.
- Who
- Toy makers, sellers and distributors in California.
- Enforced by
- People harmed can sue for their actual damages or $1,000 per violation, whichever is greater, plus a court order and legal fees.
- Law
- SB 867 (Chapter 189, Statutes of 2026), Business and Professions Code section 22604.5
Official text SB 867 (California Legislature) - Starts January 1, 2027
Do not train AI on students’ data from your school app
If your website, service or app is designed or marketed for preschool, school or college use, do not use the student information it creates or gathers, including persistent identifiers, to train generative AI or develop any AI system. The rules for colleges start on July 1, 2027.
- Who
- Operators of education websites, services and apps that know they are used for school purposes in California, and companies working for them.
- Enforced by
- Students or parents who suffer damages can sue, also as a class, for their actual damages or $500 per violation, whichever is greater, after giving the operator 60 days’ written notice to fix it.
- Law
- AB 1159 (Chapter 182, Statutes of 2026), Business and Professions Code sections 22584, 22586 and 22587 and following
Official text AB 1159 (California Legislature) - Starts January 1, 2027
Get consent before using a person’s AI voice or likeness
Do not use a digital replica of a living person’s voice or likeness on products, in ads or to sell things without their prior consent. The law now says plainly that California’s right of publicity covers digital replicas, and using one to impersonate someone counts as false impersonation under criminal law.
- Who
- Anyone using a person’s voice or likeness commercially in California.
- Enforced by
- No regulator; the person can sue for $750 or their actual damages, whichever is greater, plus profits, punitive damages and fees.
- Law
- SB 1111 (Chapter 862, Statutes of 2026), Civil Code section 3344(f) and Penal Code section 540
Official text SB 1111 (California Legislature) - Starts January 1, 2027
Give notice and an opt-out before automated decisions
If software makes significant decisions about people without real human involvement, such as hiring, pay, promotion, firing or school admissions, give a notice before use, offer an opt-out, and explain the logic and result on request. In most cases an appeal to a human who can overturn the decision can replace the opt-out.
- Who
- Businesses covered by the California Consumer Privacy Act, such as those with over $26,625,000 in yearly revenue or that buy, sell or share data on 100,000 or more consumers.
- Enforced by
- California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
- Law
- CCPA regulations, California Code of Regulations title 11, sections 7200 and 7220 to 7222
Official text CCPA regulations (California Privacy Protection Agency) - Starts January 1, 2027
Explain automated decisions and offer a human review
Before technology that processes personal data materially influences a decision about someone’s job, education, housing, financial or lending services, insurance, health care or essential government services, tell them clearly; a prominent notice where they apply is enough. After a bad outcome, explain its role within 30 days and, on request, let them correct their data and get a human review where commercially reasonable.
- Who
- Businesses in Colorado that use such technology in decisions about people in Colorado, including workers and job applicants. Developers that sell it must give users documentation and update notices; both keep records for 3 years.
- Enforced by
- Attorney General only, as a deceptive trade practice. Until January 1, 2030, a 60-day chance to fix after a warning, except for knowing or repeated violations. No new right to sue, but discrimination claims still apply.
- Law
- SB 26-189, which replaced the 2024 Colorado AI Act
Official text SB 26-189 (Colorado General Assembly) - Starts January 1, 2027
Tell users your chatbot is AI and handle crises
Tell users clearly that your chatbot is AI at the start of each day’s first chat, at least every three hours or with a notice that stays visible, and whenever they ask. Have a suicide and self-harm protocol that refers users to crisis services, and never present its answers as coming from a licensed professional such as a doctor, lawyer or therapist. Yearly reports to the Attorney General start July 1, 2027.
- Who
- Operators of public chatbots in Colorado that mainly simulate human conversation. Customer-service, shopping, productivity, developer, school and narrow-topic tools, voice assistants and game bots are excluded.
- Enforced by
- Attorney General, as a deceptive trade practice under Colorado’s AI law; no new right to sue.
- Law
- HB 26-1263 (signed May 29, 2026), section 2
Official text HB 26-1263 (Colorado General Assembly) - Starts January 1, 2027
Estimate ages and protect minors on your chatbot
Use reasonable methods to estimate users’ ages, and do not ignore clear signs that a user is a minor. For minors, keep a regular AI notice, give no surprise rewards to drive engagement, block sexual content, stop the bot claiming to be human or sentient or role-playing romance, and give minors and parents privacy and account tools.
- Who
- Operators of public chatbots in Colorado that mainly simulate human conversation. Customer-service, shopping, productivity, developer, school and narrow-topic tools, voice assistants and game bots are excluded.
- Enforced by
- Attorney General, as a deceptive trade practice under Colorado’s AI law; no new right to sue.
- Law
- HB 26-1263 (signed May 29, 2026), section 2
Official text HB 26-1263 (Colorado General Assembly) - Starts January 1, 2027
AI companions must say they are not human and handle crises
An AI companion needs a published protocol that detects talk of suicide, self-harm or violence and refers users to help such as the 988 line, and it must not claim to be human. If it could be mistaken for a person, show a clear AI notice: always visible, or at the start of each day’s first chat and then hourly for minors and every three hours for adults.
- Who
- Operators of AI companion chatbots used in Connecticut.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-15, sections 4 to 6
- Starts January 1, 2027
Protect minors who use your AI companion
If you know or have reason to believe a user is under 18, use measures that meet industry standards to keep your AI companion safe for them. It must not encourage self-harm, suicide, violence, disordered eating or drug use, discourage seeking help, engage in romantic or sexual talk, or use manipulative engagement tactics. Give minors and parents tools to manage screen time and account settings.
- Who
- Operators of AI companions used in Connecticut; customer-service, game, voice-assistant and narrow-task bots are excluded.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-15, section 6
- Starts January 1, 2027
Report frontier AI incidents and get yearly safety audits
Large frontier AI developers must publish a safety framework, file disclosure statements with the state emergency management agency and send it regular summaries of catastrophic-risk assessments. Report critical safety incidents to that agency and the Attorney General within 72 hours, or 24 hours if lives are at risk. Yearly independent audits start on January 1, 2028.
- Who
- Developers of the largest frontier AI models. Staff who raise safety concerns get confidential reporting channels and whistleblower protection.
- Enforced by
- Civil penalties of up to $1 million for a first violation and $3 million for each later one.
- Law
- Artificial Intelligence Safety Measures Act (SB 315, signed July 6, 2026)
Official text Governor’s announcement of SB 315 (State of Illinois) - Starts January 1, 2027
Report frontier AI incidents within 72 hours
If you develop frontier AI models, trained with more than 10²⁶ operations, publish a transparency report when you release a new model and report critical safety incidents to the state within 72 hours. Developers with over $500 million in yearly revenue must also write, follow and publish a frontier AI safety framework and file disclosures with a new office at the Department of Financial Services.
- Who
- Frontier AI developers whose models are developed, deployed or operated at least partly in New York. Accredited universities doing academic research are exempt.
- Enforced by
- Attorney General; up to $1 million for a first violation and $3 million for each later one. No private lawsuits.
- Law
- RAISE Act, General Business Law article 44-B, as replaced by Chapter 96 of 2026
Official text S8828, RAISE Act amendments (New York State Senate) - Starts July 1, 2027
Do not discipline or fire workers by software alone
Do not rely solely on an automated decision system to discipline or fire. If you rely mainly on one, a human must corroborate the result, and the worker gets a written notice when told of the decision. Such systems also may not be used to infer protected traits, and workers can ask for their own data.
- Who
- Employers in California, including public employers such as cities and counties. It protects employees, not job applicants.
- Enforced by
- Labor Commissioner and public prosecutors; $500 per violation.
- Law
- SB 947, the No Robo Bosses Act of 2026 (Chapter 859, Statutes of 2026), Labor Code sections 1520 to 1526.7
- Starts October 1, 2027
Tell people when an AI tool helps decide about their job
If an automated tool is a substantial factor in a job decision, give the person a written notice before the decision. Tell people in plain language when they are interacting with such a tool.
- Who
- Businesses in Connecticut, such as employers, recruiters and staffing firms, that use automated tools in job decisions about Connecticut staff or applicants. Developers of tools sold for job decisions must give users the information they need.
- Enforced by
- Attorney General only, as an unfair trade practice. For violations up to December 31, 2027, the Attorney General may first give 60 days to fix them. No private lawsuits.
- Law
- Public Act 26-15, sections 7 to 12
- Starts December 2, 2027
AI for hiring and managing staff becomes “high-risk”
Employers using AI to recruit, manage or evaluate workers must follow its instructions, have trained people oversee it and keep its logs for at least six months. They must inform workers and their representatives before using it, and tell candidates and staff when it is used in decisions about them. AI types already on the market before then are covered only after a significant design change.
- Who
- Employers and other organisations that use such AI in the EU.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 26 and Annex III (date moved by the 2026 Digital Omnibus)
Official text AI Act overview (European Commission) - Starts December 2, 2027
Certify HR AI as high-risk before you sell it
If you sell AI for recruiting, promotion, firing, task allocation or monitoring workers, it must meet the high-risk requirements: risk management, data quality, documentation, logging, human oversight and accuracy. It must also pass a conformity assessment, carry the CE mark and be registered in the EU database.
- Who
- Providers placing such AI on the EU market, including companies that sell it under their own name or substantially change it.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Articles 6(2), 8 to 17, 43 and 47 to 49, and Annex III point 4 (date moved by Regulation (EU) 2026/1744)
Official text AI Act overview (European Commission) - Starts December 2, 2027
Treat AI for admissions, grading and exams as high-risk
This covers AI that admits or places students, grades their work, decides what level of education they can reach, or watches for cheating in tests. If you use it, follow the maker’s instructions, have trained staff oversee it, keep its logs for at least six months and tell students it is used. Public bodies, and private bodies providing a public service, must first assess its impact on people’s rights.
- Who
- Schools, universities, training providers and exam bodies using such AI in the EU; the makers must pass a conformity assessment before selling it. AI on the market before then is covered only after a significant design change, except that AI for public authorities must comply by August 2, 2030.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Annex III point 3 and Articles 26, 27 and 111(2) (dates set by Regulation (EU) 2026/1744)
Official text AI Act, Annex III (EU AI Act Service Desk) - Starts December 2, 2027
Treat face recognition and emotion AI as high-risk
This covers AI that identifies people remotely from their face or other biometrics, sorts them by sensitive or protected traits, or recognises emotions, where such uses are not banned. If you use it, follow the maker’s instructions, have trained staff oversee it, keep its logs and tell the people exposed to it. Simple ID checks that only confirm a person is who they claim to be are excluded.
- Who
- Businesses and organisations using such AI in the EU, such as shops, venues and security firms; the makers must pass a conformity assessment before selling it. AI on the market before then is covered only after a significant design change.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Annex III point 1 and Article 26 (date set by Regulation (EU) 2026/1744)
Official text AI Act, Annex III (EU AI Act Service Desk) - Starts December 2, 2027
Treat AI credit scoring and insurance pricing as high-risk
If you use AI to judge people’s creditworthiness or set their credit score, or to assess risk and set prices for life or health insurance, first assess its impact on people’s rights. Then follow the maker’s instructions, have trained staff oversee it, keep its logs for at least six months and tell people it is used in decisions about them. AI used only to detect fraud is excluded.
- Who
- Banks, lenders, insurers and other businesses using such AI in the EU; the makers must pass a conformity assessment before selling it. AI on the market before then is covered only after a significant design change.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Annex III point 5(b) and (c) and Articles 26 and 27 (date set by Regulation (EU) 2026/1744)
Official text AI Act, Annex III (EU AI Act Service Desk)
Next deadlines
The next rules to start, everywhere we track.
- European UnionDo not offer or use AI that makes sexual deepfakes
- European UnionPlatforms: keep humans in charge of algorithmic management
- CaliforniaSay in layoff notices when AI caused the cuts
- CaliforniaNo surveillance tools in workplace bathrooms
- CaliforniaDo not use AI to read workers’ emotions or neural data
- CaliforniaBig platforms must show whether content is AI-made
What this checker covers
We aim to list every rule that fits the scope below, and we say openly what is not in it yet.
Covered
- Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
- Rules already in force, and rules that are law with a set start date.
- Duties for businesses, employers, platforms and AI makers in the places listed above.
- For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
- A few general laws that are the main rule for an AI use in a country, marked “General law”.
Not covered yet
- Rules for a single sector, such as health care, insurance, banking, elections or law firms.
- Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
- Bills that have not passed, official guidance and voluntary codes.
- Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
- Other US states, and countries not listed above, including the United Kingdom.
- National laws of EU countries other than Germany, France and Hungary.
How we check these rules
We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.
Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.
One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.
For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.
This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.