Data tool
Which AI rules apply to me?
Pick where you work or sell and what you use AI for. You get the AI rules that apply, what they ask you to do and from when, with a link to the official text.
Your checklist
Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.
28 rules match your choices.Includes United States (all states) rules, which apply in every US state.
- No federal law overrides state AI laws. A December 2025 executive order tells federal agencies to challenge some of them, but state laws still apply until a court or Congress says otherwise. Official text
In force now 17
- In force since May 19, 2026
Remove reported intimate deepfakes within 48 hours
Give people a clear, plain-language way to report intimate images of themselves posted without consent, including AI-made fakes. Remove a valid reported image within 48 hours, and make reasonable efforts to remove known identical copies.
- Who
- Public websites, apps and online services that mainly host content from users, with no size threshold. Broadband providers and email are excluded.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per violation. Removals made in good faith are protected.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 3
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since May 19, 2025
Never post AI-made intimate images of real people
It is a federal crime to knowingly publish online an intimate image of an identifiable real person without their consent, including realistic fakes made with AI.
- Who
- Anyone, people and businesses alike.
- Enforced by
- Department of Justice; fines and up to two years in prison, or three years if the person shown is a minor.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 2, 47 U.S.C. 223(h)
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since October 21, 2024
Do not post or buy fake reviews, including AI-written ones
Do not write, create, sell or buy reviews or testimonials that falsely suggest the reviewer exists, used the product or had the experience described. The FTC says this covers AI-generated fake reviews.
- Who
- Businesses selling to US consumers.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per knowing violation.
- Law
- FTC Rule on the Use of Consumer Reviews and Testimonials, 16 CFR part 465
Official text 16 CFR part 465 (eCFR) - In force since February 8, 2024
Get consent before calling people with an AI voice
Calls that use AI-generated or cloned voices count as artificial-voice calls under the federal robocall law, so they need the called person’s prior express consent, unless it is an emergency or an exemption applies. The message must also identify the caller.
- Who
- Anyone placing calls to people in the US.
- Enforced by
- Federal Communications Commission, state attorneys general and private lawsuits; $500 per call, or up to $1,500 if willful.
- Law
- FCC Declaratory Ruling FCC 24-17, applying the Telephone Consumer Protection Act, 47 U.S.C. 227(b)
Official text FCC Declaratory Ruling 24-17 (Federal Communications Commission) - In force since April 22, 2026
Get parents’ separate consent to train AI on kids’ data
If your site, app or service is aimed at children under 13, or you know you collect their data, get a parent’s separate, verifiable consent before disclosing a child’s personal information to third parties. The FTC says disclosing it to train or develop AI needs this consent.
- Who
- Operators of websites, apps and online services, including education technology, aimed at children under 13 or knowingly collecting their data.
- Enforced by
- Federal Trade Commission and state attorneys general; civil penalties of up to $53,088 per violation.
- Law
- Children’s Online Privacy Protection Rule, 16 CFR 312.5(a)(2), as amended in 2025
Official text COPPA Rule amendments (Federal Trade Commission) - In force since August 2, 2026
Embed hidden AI labels and offer a free checking tool
If you make a generative AI system that people in California can use, add hidden provenance data to the images, video and audio it creates or alters, where technically feasible. Also offer a free disclosure verification tool, your own or a compliant third-party one. Since September 30, 2026 this applies however many users you have; AI built mainly as assistive technology is exempt until 2029.
- Who
- Makers of generative AI systems publicly available in California.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation. Falsely claiming the assistive-technology exemption costs $50,000 per violation.
- Law
- California AI Transparency Act, Business and Professions Code sections 22757 to 22757.6 (SB 942, Chapter 291, Statutes of 2024; amended by AB 853, Chapter 674, Statutes of 2025, and SB 1000, Chapter 861, Statutes of 2026)
Official text SB 1000 (California Legislature) - In force since January 1, 2026
Companion chatbots must disclose AI and handle crises
Tell users the chatbot is AI, not human, if they could be misled; keep and publish a suicide and self-harm protocol that refers users to crisis services; and warn that companion chatbots may not suit some minors. Until December 31, 2026, also remind known minors every three hours that it is AI and to take a break, and block sexual content for them. Yearly reports start July 1, 2027.
- Who
- Operators of companion chatbot platforms available in California.
- Enforced by
- People harmed can sue for the greater of their damages or $1,000 per violation.
- Law
- SB 243 (Chapter 677, Statutes of 2025), Business and Professions Code sections 22601 to 22606; amended by SB 1119 (Chapter 190, Statutes of 2026) from January 1, 2027
Official text SB 243 (California Legislature) - In force since July 1, 2019
Do not let a bot pretend to be human to sell or sway votes
If you use a bot online to push a sale or influence a vote in California, it must clearly disclose that it is a bot.
- Who
- Anyone using bots to talk with people in California online.
- Enforced by
- This section names no penalty or enforcer.
- Law
- Business and Professions Code sections 17940 to 17943 (SB 1001, Chapter 892, Statutes of 2018)
Official text Business and Professions Code 17941 (California Legislature) - In force since January 1, 2026
Publish frontier AI safety plans and report incidents
If you train frontier AI models, publish a transparency report when you deploy a new or substantially changed one. Report critical safety incidents to the state’s Office of Emergency Services within 15 days, or within 24 hours to the right authority if lives are at risk. Developers with over $500 million in yearly revenue must also publish and follow a frontier AI framework and run an anonymous internal reporting channel.
- Who
- Frontier developers: anyone who has trained a model using more than 10²⁶ operations. None may gag or punish staff who report catastrophic risks.
- Enforced by
- Attorney General; civil penalties of up to $1 million per violation, scaled to its severity.
- Law
- Transparency in Frontier Artificial Intelligence Act, SB 53 (Chapter 138, Statutes of 2025), Business and Professions Code sections 22757.10 to 22757.16 and Labor Code sections 1107 to 1107.2
Official text SB 53 (California Legislature) - In force since January 1, 2025
Spell out digital replica uses in performer contracts
A contract term can let a digital replica of a person’s voice or likeness replace work they would have done in person. Such a term is unenforceable if it lacks a reasonably specific description of the uses and the person had no lawyer or union negotiating for them.
- Who
- Anyone contracting with a person in California for personal or professional services, such as actors, voice artists and creators. It covers new performances fixed from January 1, 2025.
- Enforced by
- No regulator or fine; such a term cannot be enforced.
- Law
- AB 2602 (Chapter 259, Statutes of 2024), Labor Code section 927
Official text AB 2602 (California Legislature) - In force since January 1, 2026
Post a summary of the data used to train your AI
Before each public release of a generative AI system, or a substantial change to it, post documentation on your website about its training data. It must include a high-level summary of the datasets: their sources or owners, whether they include copyrighted or personal information, and whether they were bought or licensed.
- Who
- Developers of generative AI systems or services released since January 1, 2022 and publicly available to Californians, including anyone who substantially modifies one. AI used only for security, aircraft operation or national security is exempt.
- Enforced by
- The law names no penalty or enforcer. A federal court refused to block it in March 2026; xAI’s appeal is set for argument on November 18, 2026.
- Law
- AB 2013 (Chapter 817, Statutes of 2024), Civil Code sections 3110 and 3111, amended by AB 1170 (Chapter 67, Statutes of 2025)
Official text Civil Code section 3111 (California Legislature) - In force since January 1, 2026
Do not make or help spread sexual deepfakes
Do not create or share sexually explicit deepfakes of a real person when you know, or should know, that they did not consent or were a minor, and do not knowingly help others do it. A service mainly for making sexual deepfakes is presumed to know there was no consent. Companies that keep such a service running are presumed liable if they do not stop within 30 days of notice.
- Who
- Anyone, including people and businesses that run or serve deepfake services.
- Enforced by
- The person shown can sue for profits, actual damages or $1,500 to $50,000 per work, up to $250,000 with malice, plus punitive damages and fees. Public prosecutors can seek $25,000 per violation, or $50,000 with malice.
- Law
- AB 621 (Chapter 673, Statutes of 2025), Civil Code section 1708.86
Official text AB 621 (California Legislature) - In force since January 1, 2025
Let users report sexual deepfakes and act within 30 days
Let California account holders report sexually explicit images or videos of themselves that were made or altered digitally without their consent. Confirm each report within 48 hours, update within 7 days, block the material while you check, and decide within 30 days, or 60 days if the delay is beyond your control. Remove it at once if the report holds up.
- Who
- Social media platforms with users in California; end-to-end encrypted messaging services and charities are excluded.
- Enforced by
- The law names no penalty or enforcer.
- Law
- SB 981 (Chapter 292, Statutes of 2024), Business and Professions Code sections 22670 and 22671
Official text SB 981 (California Legislature) - In force since January 1, 2025
Say when a robocall uses an artificial voice
Before an automatic dialing device plays a prerecorded message, a live, natural voice must state the nature of the call and the caller’s name, address and phone number. It must ask whether the person consents to hear the message, and say if the message uses an artificial voice, such as an AI-generated one.
- Who
- Anyone placing calls with automatic dialing-announcing devices to people in California.
- Enforced by
- California Public Utilities Commission; fines of up to $500 per violation, or disconnection of the line.
- Law
- AB 2905 (Chapter 316, Statutes of 2024), Public Utilities Code section 2874
Official text AB 2905 (California Legislature) - In force since January 1, 2025
Get estate consent for AI replicas of dead celebrities
Do not use a digital replica of a deceased personality’s voice or likeness in a film, video or sound recording without consent from whoever holds their rights. News, sports, criticism, satire, parody, documentaries, biographies and fleeting uses are excepted.
- Who
- Studios, labels, advertisers, AI companies and anyone else using such a replica in California.
- Enforced by
- No regulator; the rights holders can sue for $10,000 or their actual damages, whichever is greater.
- Law
- AB 1836 (Chapter 258, Statutes of 2024), Civil Code section 3344.1
Official text AB 1836 (California Legislature) - In force since October 1, 2025
Do not let AI tools discriminate; keep their data 4 years
Using an automated decision system that discriminates against job applicants or workers is unlawful, even when a vendor runs it for you. Keep the system’s data with your employment records for four years. Evidence of anti-bias testing can count for or against you.
- Who
- Employers covered by California’s Fair Employment and Housing Act, usually those with 5 or more employees, plus employment agencies and unions.
- Enforced by
- Civil Rights Department complaints and lawsuits under the Fair Employment and Housing Act; damages rather than a fixed fine.
- Law
- Civil Rights Council regulations, California Code of Regulations title 2, sections 11008.1, 11009(f) and 11013(c)
Official text Automated-decision systems regulations (California Civil Rights Department) - In force since January 1, 2026
Do a risk assessment before using AI to judge people
Do and document a privacy risk assessment, and review it at least every three years, before you use automated decision-making for significant decisions such as jobs, loans, housing, education or health care. The same applies to automated tools that infer workers’, students’ or applicants’ performance, health, behaviour or location from systematic observation, and to training such tools or face recognition on personal data. Uses that began before 2026 need one by December 31, 2027.
- Who
- Businesses covered by the California Consumer Privacy Act.
- Enforced by
- California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
- Law
- CCPA regulations, California Code of Regulations title 11, sections 7150, 7155 and 7157
Official text CCPA regulations (California Privacy Protection Agency)
Coming up 11
- Starts January 1, 2027
Say in layoff notices when AI caused the cuts
If a mass layoff, relocation or closure is caused wholly or substantially by AI or other automation, the 60-day notice must say so under the line “This notice is for a technology displacement”. It must give the number, job type and work location of those jobs, the tasks that will be automated and the kind of technology used.
- Who
- Employers with a California site that has employed 75 or more people in the past year.
- Enforced by
- Existing Cal/WARN remedies, as SB 951 adds no new penalty: workers not given notice are owed back pay and benefits for up to 60 days, and a missing notice to officials can cost up to $500 a day. Workers, unions and local governments can sue.
- Law
- SB 951 (Chapter 860, Statutes of 2026), Labor Code section 1401
Official text SB 951 (California Legislature) - Starts January 1, 2027
No surveillance tools in workplace bathrooms
Employers may not use surveillance tools to monitor workers in workplace bathrooms, except under a court order, and workers may leave such tools behind when they go in. Simple badges or alarms without audio, video or built-in AI are allowed.
- Who
- All California employers, public and private.
- Enforced by
- Labor Commissioner and public prosecutors; up to $500 per violation.
- Law
- AB 1331 (Chapter 851, Statutes of 2026), Labor Code sections 1560 to 1565
Official text AB 1331 (California Legislature) - Starts January 1, 2027
Do not use AI to read workers’ emotions or neural data
Employers may not use AI-powered workplace surveillance tools to recognise, infer or predict workers’ emotional state, or to collect neural data, meaning measurements of the nervous system. Tools used to keep people safe are not banned.
- Who
- All California employers, public and private.
- Enforced by
- Labor Commissioner, public prosecutors or the worker; up to $500 per violation.
- Law
- AB 1883 (Chapter 853, Statutes of 2026), Labor Code sections 1580 to 1583
Official text AB 1883 (California Legislature) - Starts January 1, 2027
Big platforms must show whether content is AI-made
Detect provenance data in content on your platform, clearly show whether it says the content was made or substantially altered by AI or captured by a camera or recorder, and let users inspect that data. Where technically feasible, do not knowingly strip it.
- Who
- Public-facing social media, file-sharing, mass-messaging and stand-alone search services with more than 2 million unique monthly users over the past 12 months. Broadband and telecom services are excluded.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation.
- Law
- Business and Professions Code section 22757.3.1, added by AB 853 (Chapter 674, Statutes of 2025) and amended by AB 2713 (Chapter 856, Statutes of 2026)
Official text AB 2713 (California Legislature) - Starts January 1, 2027
Do not knowingly host AI models that skip hidden labels
If your site or app offers generative AI model weights or source code for download, do not knowingly make available a system that does not add the hidden provenance data California requires.
- Who
- Generative AI hosting platforms, paid or free, that offer downloads to people in California.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation.
- Law
- Business and Professions Code section 22757.3.2 (AB 853, Chapter 674, Statutes of 2025)
Official text AB 853 (California Legislature) - Starts January 1, 2027
Assess, limit and audit companion chatbots for children
From January 1, 2027, check users’ ages or give everyone the child protections. From July 1, 2027, if children may use your companion chatbot, assess child risks before each release, publish a child safety policy and run a crisis protocol. Set parent-controlled limits such as one-hour sessions, block romance, sexual content and purchase pressure, and do not sell children’s data. Independent audits are due from 2029.
- Who
- Anyone who makes a companion chatbot available in California; most duties apply only if children under 18 may use it. Colleges offering it only for education, and employers offering it only to staff, are excluded.
- Enforced by
- Public prosecutors; up to $5,000 per affected child for each negligent violation and $15,000 for each intentional one. Harmed children or their parents can sue for damages.
- Law
- Adam’s Law, SB 1119 (Chapter 190, Statutes of 2026), Business and Professions Code sections 21810 to 21818
Official text SB 1119 (California Legislature) - Starts January 1, 2027
Do not make or sell toys with companion chatbots
Until January 1, 2031, do not make, sell, exchange or offer to retailers any toy that includes a companion chatbot. A toy here means a product made for play by children under 16.
- Who
- Toy makers, sellers and distributors in California.
- Enforced by
- People harmed can sue for their actual damages or $1,000 per violation, whichever is greater, plus a court order and legal fees.
- Law
- SB 867 (Chapter 189, Statutes of 2026), Business and Professions Code section 22604.5
Official text SB 867 (California Legislature) - Starts January 1, 2027
Do not train AI on students’ data from your school app
If your website, service or app is designed or marketed for preschool, school or college use, do not use the student information it creates or gathers, including persistent identifiers, to train generative AI or develop any AI system. The rules for colleges start on July 1, 2027.
- Who
- Operators of education websites, services and apps that know they are used for school purposes in California, and companies working for them.
- Enforced by
- Students or parents who suffer damages can sue, also as a class, for their actual damages or $500 per violation, whichever is greater, after giving the operator 60 days’ written notice to fix it.
- Law
- AB 1159 (Chapter 182, Statutes of 2026), Business and Professions Code sections 22584, 22586 and 22587 and following
Official text AB 1159 (California Legislature) - Starts January 1, 2027
Get consent before using a person’s AI voice or likeness
Do not use a digital replica of a living person’s voice or likeness on products, in ads or to sell things without their prior consent. The law now says plainly that California’s right of publicity covers digital replicas, and using one to impersonate someone counts as false impersonation under criminal law.
- Who
- Anyone using a person’s voice or likeness commercially in California.
- Enforced by
- No regulator; the person can sue for $750 or their actual damages, whichever is greater, plus profits, punitive damages and fees.
- Law
- SB 1111 (Chapter 862, Statutes of 2026), Civil Code section 3344(f) and Penal Code section 540
Official text SB 1111 (California Legislature) - Starts January 1, 2027
Give notice and an opt-out before automated decisions
If software makes significant decisions about people without real human involvement, such as hiring, pay, promotion, firing or school admissions, give a notice before use, offer an opt-out, and explain the logic and result on request. In most cases an appeal to a human who can overturn the decision can replace the opt-out.
- Who
- Businesses covered by the California Consumer Privacy Act, such as those with over $26,625,000 in yearly revenue or that buy, sell or share data on 100,000 or more consumers.
- Enforced by
- California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
- Law
- CCPA regulations, California Code of Regulations title 11, sections 7200 and 7220 to 7222
Official text CCPA regulations (California Privacy Protection Agency) - Starts July 1, 2027
Do not discipline or fire workers by software alone
Do not rely solely on an automated decision system to discipline or fire. If you rely mainly on one, a human must corroborate the result, and the worker gets a written notice when told of the decision. Such systems also may not be used to infer protected traits, and workers can ask for their own data.
- Who
- Employers in California, including public employers such as cities and counties. It protects employees, not job applicants.
- Enforced by
- Labor Commissioner and public prosecutors; $500 per violation.
- Law
- SB 947, the No Robo Bosses Act of 2026 (Chapter 859, Statutes of 2026), Labor Code sections 1520 to 1526.7
Next deadlines
The next rules to start, everywhere we track.
- European UnionDo not offer or use AI that makes sexual deepfakes
- European UnionPlatforms: keep humans in charge of algorithmic management
- CaliforniaSay in layoff notices when AI caused the cuts
- CaliforniaNo surveillance tools in workplace bathrooms
- CaliforniaDo not use AI to read workers’ emotions or neural data
- CaliforniaBig platforms must show whether content is AI-made
What this checker covers
We aim to list every rule that fits the scope below, and we say openly what is not in it yet.
Covered
- Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
- Rules already in force, and rules that are law with a set start date.
- Duties for businesses, employers, platforms and AI makers in the places listed above.
- For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
- A few general laws that are the main rule for an AI use in a country, marked “General law”.
Not covered yet
- Rules for a single sector, such as health care, insurance, banking, elections or law firms.
- Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
- Bills that have not passed, official guidance and voluntary codes.
- Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
- Other US states, and countries not listed above, including the United Kingdom.
- National laws of EU countries other than Germany, France and Hungary.
How we check these rules
We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.
Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.
One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.
For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.
This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.